WhatsApp Claude PluginBLOCK
Claude Code WhatsApp channel plugin — run AI directly from WhatsApp, voice transcription, remote tool approval, access control. No API keys, no Docker, just a linked device.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Drive your Claude Code session from WhatsApp — your personal number, no bots, no API keys.
The plugin connects to WhatsApp as a linked device (the same protocol as WhatsApp Web, via Baileys) and exposes it to Claude Code as an MCP channel. Incoming messages reach your session in real time; Claude replies from your own number, so recipients see a normal chat. Everything runs locally on your machine — messages travel directly between WhatsApp and your session, with no third-party servers in between. Once paired, it keeps working while your phone is off; only the Claude Code session needs to stay open, and reconnects never require re-pairing.
[](https://claude.com/plugins) [](https://claude.com/plugins) [](https://modelcontextprotocol.io) [](https://opensource.org/licenses/Apache-2.0)
Published on the Anthropic Official Plugin Marketplace — the first community-built WhatsApp channel plugin reviewed and published by Anthropic.
Installation
claude plugin marketplace add Rich627/whatsapp-claude-plugin claude plugin install whatsapp-channel@whatsapp-claude-plugin claude --dangerously-load-development-channels plugin:whatsapp-channel@whatsapp-claude-plugin
The --dangerously-load-development-channels flag matters: it registers the plugin as a channel, so an inbound Whats
e6a11b436e52OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add claude-channel-whatsapp --env GROQ_API_KEY=${GROQ_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env WHATSAPP_GROQ_API_KEY=${WHATSAPP_GROQ_API_KEY} --env WHATSAPP_OPENAI_API_KEY=${WHATSAPP_OPENAI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"claude-channel-whatsapp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GROQ_API_KEY": "${GROQ_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"WHATSAPP_GROQ_API_KEY": "${WHATSAPP_GROQ_API_KEY}",
"WHATSAPP_OPENAI_API_KEY": "${WHATSAPP_OPENAI_API_KEY}"
}
}
}
}Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
catch_up | read | Recover conversation context. Pass |
download_attachment | read | Download a media attachment from a WhatsApp message to the local inbox. Use when the inbound <channel> meta shows attachment_file_id. Returns the local file path ready to Read. |
edit_message | write | Edit a message this account previously sent. Only works on the account |
group_roster | read | List an allowlisted group |
list_groups | read | List every WhatsApp group this account is currently a member of, with each group |
react | write | Add an emoji reaction to a WhatsApp message. Any emoji is supported. |
reply | read | Reply on WhatsApp. Pass chat_id from the inbound message. Optionally pass reply_to (message_id) for quoting, mentions (to @-tag people) and files (absolute paths) to attach images or documents. |
status | read | Get WhatsApp connection status. Returns whether connected, the pairing code (if pending), and the connected JID. Call this on session start to check setup state and show the pairing code to the user. |
whatsapp_unavailable | read | WhatsApp is not available in this session. ${conflictReason} No other WhatsApp tool exists here. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
3. Read existing `.env` if present; update/add the `WHATSAPP_PHONE_NUMBER=` line,
inCrontab = execFileSync("crontab", ["-l"], { encoding: "utf8" }).includes(`installed at ${WATCHDOG_SCRIPT} (${executable ? "executable" : "NOT executable — chmod +x it"}, ${inCrontab ? "referenced in crontab" : "not in crontab — add a */2 entry per the script header"})`,describe("cronMatches with crontab spellings", () => {stubDir = mkdtempSync(join(tmpdir(), "crontab-stub-"));
const stub = join(stubDir, "crontab");
"../../../..",
[.not.toContain("");expect(oneLine("👨👩👧 Family")).toBe("👨👩👧 Family");expect(displayWidth("")).toBe(0);@inquirer/prompts, @modelcontextprotocol/sdk
system use found in code, not declared in the description
Gates applied: no_behavioural_pass.
e6a11b436e52full audit observations/trust-audit/mcp-server/rich627__whatsapp-claude-plugin.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e6a11b436e52 | BLOCK | D | 69 | first audit |
Questions
What is the WhatsApp Claude Plugin MCP server?
Claude Code WhatsApp channel plugin — run AI directly from WhatsApp, voice transcription, remote tool approval, access control. No API keys, no Docker, just a linked device.
What tools does WhatsApp Claude Plugin expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is WhatsApp Claude Plugin safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does WhatsApp Claude Plugin need?
It reads GROQ_API_KEY, OPENAI_API_KEY, WHATSAPP_GROQ_API_KEY and WHATSAPP_OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does WhatsApp Claude Plugin run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-channel-whatsapp at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (e6a11b436e52), read on 2026-10-08. The repository is watched and re-audited when it changes.