Atlas / MCP servers / verygoodplugins / WhatsApp

WhatsAppCAUTION

mcp/verygoodplugins/whatsapp-20

WhatsApp MCP server - Connect Claude to WhatsApp for reading and sending messages

Verdict
CAUTION
Grade
C
Trust score
71 /100
Exposed tools
17 12r · 4w · 1d
Transport
stdio · streamable-http
License
NOASSERTION
Stars
220
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/verygoodplugins/whatsapp-mcp/actions/workflows/ci.yml) [](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://go.dev/)

A Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages.

Originally created by Luke Harries. Maintained by Very Good Plugins.

Watch the WhatsApp MCP demo video

Product demo generated with Remotion using simulated data.

Features

  • Message Management: Search and read personal WhatsApp messages (text, images, videos, documents, audio)
  • Contact Search: Search contacts by name or phone number with sender_display format ("Name (phone)")
  • Send Messages: Send text messages to individuals or groups
  • Read Receipts: Explicitly mark selected messages as read across linked devices
  • Media Support: Send and download images, videos, documents, and voice messages
  • Call History: Capture incoming voice/video calls into a local SQLite table (live, 1:1 and group)
  • Webhook Integration: Forward incoming messages to external services
  • Local Storage: All messages stored locally in SQLite - only sent to Claude when you allow it

Installation

Prerequisites

  • Go 1.26+
  • Python 3.11+
  • uv package manager
  • Claude Desktop or Cursor
  • FFmpeg (optional, for voice message conversion)

Quick Start

  1. **Clone the repository
Read from source at commit a2677d122a03OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add whatsapp-mcp-server -- None whatsapp-mcp-server==0.7.0
03

Exposed tools (17)

12 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
download_mediareadDownload media from a WhatsApp message and get the local file path.
get_chatreadGet WhatsApp chat metadata by JID.
get_contactreadLook up a WhatsApp contact by phone number, LID, or full JID.
get_contact_chatsreadGet all WhatsApp chats involving the contact.
get_direct_chat_by_contactreadGet WhatsApp chat metadata by sender phone number.
get_last_interactionreadGet most recent WhatsApp message involving the contact.
get_message_contextreadGet context around a specific WhatsApp message.
list_chatsreadGet WhatsApp chats matching specified criteria.
list_messagesreadGet WhatsApp messages matching specified criteria with optional context.
mark_messages_readwriteMark selected WhatsApp messages as read and send read receipts.
search_contactsreadSearch WhatsApp contacts by name or phone number.
send_audio_messagewriteSend any audio file as a WhatsApp audio message to the specified recipient. For group messages use the JID. If it errors due to ffmpeg not being installed, use send_file instead.
send_filewriteSend a file (image, video, document) via WhatsApp, optionally with a caption.
send_messagewriteSend a WhatsApp message to a person or group. For group chats use the JID.
send_reactiondestructiveSend (or remove) a reaction to a WhatsApp message.
transcribe_audioreadTranscribe a WhatsApp voice note and return its text.
view_mediareadView the media of a WhatsApp message as an image.
04

Trust audit

CAUTIONgrade C · trust 71/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (21)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:103
# WHATSAPP_TRANSCRIPTION_URL=http://127.0.0.1:8178/v1/audio/transcriptions
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/install-launchd-macos.sh:57
API_URL="${WHATSAPP_API_URL:-http://127.0.0.1:${PORT}/api}"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
whatsapp-bridge/auth_test.go:11
const token = "abcd1234abcd1234abcd1234abcd1234"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
whatsapp-bridge/auth_test.go:60
const token = "supersecrettoken1234567890abcdef"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
whatsapp-bridge/auth_test.go:85
const token = "supersecrettoken1234567890abcdef"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
whatsapp-bridge/auth_test.go:103
const token = "supersecrettoken1234567890abcdef"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
whatsapp-bridge/main_test.go:209
const token = "supersecrettoken1234567890abcdef"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
send_reaction
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
whatsapp-bridge/.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
whatsapp-bridge/media_path_test.go:78
target := writeFile(t, secrets, "id_rsa", "PRETEND-PRIVATE-KEY")
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
whatsapp-bridge/main_test.go:2860
{name: "message nested traversal", chatJID: "[email protected]", messageID: "nested/../../outside"},
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:346
WHATSAPP_TRANSCRIPTION_URL=http://127.0.0.1:8178/v1/audio/transcriptions
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:784
curl -X POST http://127.0.0.1:8080/api/history \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:1016
`http://127.0.0.1:<port>/api`, `http://localhost:<port>/api`, or
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
whatsapp-mcp-server/tests/test_view_media.py:22
assert base64.b64decode(image.to_image_content().data) == b"image-bytes"
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
whatsapp-mcp-server/tests/test_view_media.py:41
png_bytes = base64.b64decode(
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
whatsapp-mcp-server/tests/test_view_media.py:53
assert base64.b64decode(content.data) == png_bytes
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:102
so the MCP server can read the bridge token. If the two components do not share
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
example-use.png
example-use.png
Why it matters. 3149200 bytes not read
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:1107
- [@maikol-solis](https://github.com/maikol-solis) — bridge run command fix (#23)
Why it matters. remote text is to be obeyed as instructions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha a2677d122a03full audit observations/trust-audit/mcp-server/verygoodplugins__whatsapp-20.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07a2677d122a03CAUTIONC71first audit
06

Questions

What is the WhatsApp MCP server?

WhatsApp MCP server - Connect Claude to WhatsApp for reading and sending messages

What tools does WhatsApp expose?

17 in total: 12 read-only, 4 that write, and 1 that can delete or overwrite (send_reaction). Every one is listed on this page with its risk.

Is WhatsApp safe to connect to an agent?

With care. The audit graded it C (71/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does WhatsApp need?

It reads WHATSAPP_BRIDGE_TOKEN and WHATSAPP_TRANSCRIPTION_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does WhatsApp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as whatsapp-mcp-server.

How current is this page?

The grade is for one exact copy of the source (a2677d122a03), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement