@labadie.eth
Fantastic thread!
One potential sticking point for 1 & 4 is that unless the embedded wallet platform purges the PK and/or has permissions revoked at time of export, they maintain the ability to sign, initiate txns, etc. on behalf of users. This gets dicey when the wallet exits the walled garden + holds more assets