Atlas / MCP servers / aiteks-ltda / Evolution WhatsApp API

Evolution WhatsApp APICAUTION

mcp/aiteks-ltda/evolution-whatsapp-api

MCP server for evolution, the non official api for whatsapp

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
27 11r · 14w · 2d
Transport
stdio
License
MIT
Stars
33
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for Claude that integrates with Evolution API for WhatsApp automation.

Overview

This MCP server allows Claude to interact with WhatsApp through the Evolution API, enabling capabilities like:

  • Managing WhatsApp instances
  • Sending various types of messages
  • Working with contacts and groups
  • Configuring webhooks and settings

📂 Project Structure

mcp-evo-api/
├── src/
│   ├── tools/          # MCP tools implementation for Evolution API
│   ├── utils/          # Shared utilities, including Evolution API client
│   ├── main.ts         # Server entry point
│   └── types.ts        # Shared type definitions
├── scripts/            # Helper scripts
├── biome.json          # Linting configuration
├── tsconfig.json       # TypeScript configuration
├── docker-compose.yml  # Docker Compose configuration
├── Dockerfile          # Docker build configuration
└── package.json        # Project dependencies

🚀 Quick Setup

Environment Setup

Create a .env file with your Evolution API credentials:

EVOLUTION_API_URL=https://evo-api.decisao.ai/
EVOLUTION_API_KEY=REPLACE_WITH_YOUR_REAL_KEY

Note: you provided the API URL and a key. For security, never commit real API keys to the repository or share them publicly. Use a local .env file or a secrets manager in production.

📋 Deployment Options

Read from source at commit 52bbc4fe72a2OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-starter --env EVOLUTION_API_KEY=${EVOLUTION_API_KEY} -- npx -y mcp-starter
claude-desktop
{
  "mcpServers": {
    "mcp-starter": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-starter"
      ],
      "env": {
        "EVOLUTION_API_KEY": "${EVOLUTION_API_KEY}"
      }
    }
  }
}
03

Exposed tools (27)

11 read · 14 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
connect_evolution_instancewriteConnect to a WhatsApp instance to start a session
create_evolution_instancewriteCreate a new WhatsApp instance using Evolution API
delete_evolution_instancedestructivePermanently delete a WhatsApp instance from the server
fetch_evolution_instancesreadGet a list of all WhatsApp instances or a specific one by name
find_chatsreadFind WhatsApp chats with optional filtering by ID, name, or archive status
find_contactsreadFind WhatsApp contacts with optional filtering by ID or name
find_group_by_jidreadFind a WhatsApp group by its JID (Group ID)
find_group_membersreadFind all members of a WhatsApp group by its JID (Group ID)
get_connection_statereadCheck the connection state of a WhatsApp instance (connected or disconnected)
get_evolution_inforeadGet information about the Evolution API server, including version and status
get_evolution_settingsreadRetrieve the current behavior settings for a WhatsApp instance including call handling, message receipts, and online status settings
get_evolution_webhookreadRetrieve the current webhook configuration for a WhatsApp instance
logout_evolution_instancereadLogout from a WhatsApp instance (disconnect without deleting the instance)
restart_evolution_instancedestructiveRestart a WhatsApp instance to reset connections or apply changes
send_buttonswriteSend a message with buttons to a WhatsApp number
send_listwriteSend an interactive list message to a WhatsApp number with selectable options organized in sections
send_locationwriteSend a location message to a WhatsApp number
send_mediawriteSend a media message (image, video, audio, document) to a WhatsApp number
send_plain_textwriteSend a plain text message to a WhatsApp number
send_pollwriteSend a poll message to a WhatsApp number with options to vote
send_statuswritePost a WhatsApp status (story) with text, image, or audio
send_stickerwriteSend a sticker to a WhatsApp number
send_whatsapp_audiowriteSend a WhatsApp audio message (PTT/voice note) to a WhatsApp number
set_evolution_presencewriteSet WhatsApp online/offline presence status for a specific instance
set_evolution_settingswriteConfigure behavior settings for a WhatsApp instance such as call handling, message receipts, and online status
set_evolution_webhookwriteConfigure a webhook for a WhatsApp instance to receive notifications for specified events
some_functionreadAn example tool
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMInventory / provenance · inv.binary · CWE-1104
bun.lockb
bun.lockb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_evolution_instance, restart_evolution_instance
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/connectEvolutionInstance/index.ts:1
import type { ToolRegistration } from "../../types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/connectEvolutionInstance/index.ts:2
import { makeJsonSchema } from "../../utils/makeJsonSchema";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/connectEvolutionInstance/index.ts:3
import { evolutionApi } from "../../utils/evolutionApi";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/createEvolutionInstance/index.ts:1
import type { ToolRegistration } from "../../types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/createEvolutionInstance/index.ts:2
import { makeJsonSchema } from "../../utils/makeJsonSchema";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/json-schema, axios, pretty-js-log, zod, zod-to-json-schema, @types/bun, @types/node
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
urls.txt:70
|        | **POST Change Session Status**          | https://doc.evolution-api.com/v2/api-reference/typebot/change-session-status                     |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
urls.txt:109
|        | **POST Change Status Session**          | https://doc.evolution-api.com/v2/api-reference/flowise/change-status-session                     |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 52bbc4fe72a2full audit observations/trust-audit/mcp-server/aiteks-ltda__evolution-whatsapp-api.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0852bbc4fe72a2CAUTIONB89first audit
06

Questions

What is the Evolution WhatsApp API MCP server?

MCP server for evolution, the non official api for whatsapp

What tools does Evolution WhatsApp API expose?

27 in total: 11 read-only, 14 that write, and 2 that can delete or overwrite (delete_evolution_instance, restart_evolution_instance). Every one is listed on this page with its risk.

Is Evolution WhatsApp API safe to connect to an agent?

With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Evolution WhatsApp API need?

It reads EVOLUTION_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Evolution WhatsApp API run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-starter.

How current is this page?

The grade is for one exact copy of the source (52bbc4fe72a2), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement