Atlas / MCP servers / rich627 / WhatsApp Claude Plugin

WhatsApp Claude PluginBLOCK

mcp/rich627/whatsapp-claude-plugin

Claude Code WhatsApp channel plugin — run AI directly from WhatsApp, voice transcription, remote tool approval, access control. No API keys, no Docker, just a linked device.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
9 7r · 2w · 0d
Transport
stdio
License
Apache-2.0
Stars
102
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Drive your Claude Code session from WhatsApp — your personal number, no bots, no API keys.

The plugin connects to WhatsApp as a linked device (the same protocol as WhatsApp Web, via Baileys) and exposes it to Claude Code as an MCP channel. Incoming messages reach your session in real time; Claude replies from your own number, so recipients see a normal chat. Everything runs locally on your machine — messages travel directly between WhatsApp and your session, with no third-party servers in between. Once paired, it keeps working while your phone is off; only the Claude Code session needs to stay open, and reconnects never require re-pairing.

[](https://claude.com/plugins) [](https://claude.com/plugins) [](https://modelcontextprotocol.io) [](https://opensource.org/licenses/Apache-2.0)

Published on the Anthropic Official Plugin Marketplace — the first community-built WhatsApp channel plugin reviewed and published by Anthropic.

Installation

claude plugin marketplace add Rich627/whatsapp-claude-plugin
claude plugin install whatsapp-channel@whatsapp-claude-plugin
claude --dangerously-load-development-channels plugin:whatsapp-channel@whatsapp-claude-plugin

The --dangerously-load-development-channels flag matters: it registers the plugin as a channel, so an inbound Whats

Read from source at commit e6a11b436e52OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add claude-channel-whatsapp --env GROQ_API_KEY=${GROQ_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env WHATSAPP_GROQ_API_KEY=${WHATSAPP_GROQ_API_KEY} --env WHATSAPP_OPENAI_API_KEY=${WHATSAPP_OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "claude-channel-whatsapp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GROQ_API_KEY": "${GROQ_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "WHATSAPP_GROQ_API_KEY": "${WHATSAPP_GROQ_API_KEY}",
        "WHATSAPP_OPENAI_API_KEY": "${WHATSAPP_OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (9)

7 read · 2 write · 0 destructive.

ToolRiskDescription
catch_upreadRecover conversation context. Pass
download_attachmentreadDownload a media attachment from a WhatsApp message to the local inbox. Use when the inbound <channel> meta shows attachment_file_id. Returns the local file path ready to Read.
edit_messagewriteEdit a message this account previously sent. Only works on the account
group_rosterreadList an allowlisted group
list_groupsreadList every WhatsApp group this account is currently a member of, with each group
reactwriteAdd an emoji reaction to a WhatsApp message. Any emoji is supported.
replyreadReply on WhatsApp. Pass chat_id from the inbound message. Optionally pass reply_to (message_id) for quoting, mentions (to @-tag people) and files (absolute paths) to attach images or documents.
statusreadGet WhatsApp connection status. Returns whether connected, the pairing code (if pending), and the connected JID. Call this on session start to check setup state and show the pairing code to the user.
whatsapp_unavailablereadWhatsApp is not available in this session. ${conflictReason} No other WhatsApp tool exists here.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/configure/SKILL.md:88
3. Read existing `.env` if present; update/add the `WHATSAPP_PHONE_NUMBER=` line,
Why it matters. asks the agent to read credentials
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
scripts/doctor.ts:552
inCrontab = execFileSync("crontab", ["-l"], { encoding: "utf8" }).includes(
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
scripts/doctor.ts:561
`installed at ${WATCHDOG_SCRIPT} (${executable ? "executable" : "NOT executable — chmod +x it"}, ${inCrontab ? "referenced in crontab" : "not in crontab — add a */2 entry per the script header"})`,
LOWPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
lib/cron.test.ts:127
describe("cronMatches with crontab spellings", () => {
LOWPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
scripts/install-watchdog.test.ts:28
stubDir = mkdtempSync(join(tmpdir(), "crontab-stub-"));
LOWPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
scripts/install-watchdog.test.ts:29
const stub = join(stubDir, "crontab");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/update-notice.ts:290
"../../../..",
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:7
[![Anthropic Published](https://img.shields.io/badge/Anthropic-Official%20Published-ff6b35?logo=data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMjQiIGhlaWdodD0iMjQiIHZpZXdCb3g9IjAgMCAyNCAyNCIgZmlsbD0ibm9uZS
LOWObfuscation / stealth · obf.rtl_override · CWE-506, CWE-94
scripts/picker.test.ts:650
label: "a\x1b[31mb\rc\nde",
LOWObfuscation / stealth · obf.rtl_override · CWE-506, CWE-94
scripts/picker.test.ts:656
expect(text).not.toContain("");
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
lib/message-view.test.ts:990
expect(oneLine("👨👩👧 Family")).toBe("👨👩👧 Family");
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/picker.test.ts:536
expect(displayWidth("")).toBe(0);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@inquirer/prompts, @modelcontextprotocol/sdk
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e6a11b436e52full audit observations/trust-audit/mcp-server/rich627__whatsapp-claude-plugin.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e6a11b436e52BLOCKD69first audit
06

Questions

What is the WhatsApp Claude Plugin MCP server?

Claude Code WhatsApp channel plugin — run AI directly from WhatsApp, voice transcription, remote tool approval, access control. No API keys, no Docker, just a linked device.

What tools does WhatsApp Claude Plugin expose?

9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is WhatsApp Claude Plugin safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does WhatsApp Claude Plugin need?

It reads GROQ_API_KEY, OPENAI_API_KEY, WHATSAPP_GROQ_API_KEY and WHATSAPP_OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does WhatsApp Claude Plugin run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-channel-whatsapp at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (e6a11b436e52), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement