Security-hardened, read-only WhatsApp MCP server for Claude Desktop
The server defines 9 read-only tools with proper schemas and descriptions. All tools have input schemas with typed parameters and descriptions. Tool names follow verb_noun conventions (search_contacts, list_messages, get_chat, etc.). Descriptions are present and explain purpose, though most are brief (50-100 chars). The primary limitation: no output schemas are documented anywhere in the provided source code. Parameter descriptions are adequate but lack detailed constraints, enums, or validation rules. Error handling is not visible in the tool definitions. The security posture is strong (read-only, token auth, Unix socket, whitelist) but this is infrastructure, not reflected in tool definition quality per the rubric.
Download media (images, videos, documents) from a WhatsApp message. This tool downloads media files from messages in whitelisted groups only. The download request is authenticated and goes through the Go bridge via a secure Unix domain socket.
Get WhatsApp chat metadata by JID.
Get all chats involving a contact.
Get WhatsApp chat by phone number.
Get most recent message with a contact.
Get context around a specific message.
No output schemas documented for any tool. LLMs cannot predict response structure, forcing them to guess at field names and types. This violates pattern:tool and pattern:response-shaper.
Parameter descriptions lack concrete constraints. E.g., 'limit' (integer, default 20) has no min/max bounds stated. 'sort_by' accepts 'last_active' or 'name' but no enum constraint visible in schema. Agents may pass invalid values.
No error handling guidance visible in tool definitions. If a JID is invalid, contact not found, or message_id does not exist, LLMs have no recovery path documented.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 64 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 43 | - | v1 |
Get WhatsApp chats matching criteria.
Get WhatsApp messages matching criteria with optional context.
Search WhatsApp contacts by name or phone number.
Tool 'get_direct_chat_by_contact' uses parameter 'sender_phone_number' which is vague, does it mean the phone number of the contact, or a message sender? Naming should clarify: 'contact_phone_number' would be clearer.
Parameter descriptions sometimes lack format hints. E.g., 'chat_jid' (JID format unknown), 'message_id' (format unknown), ISO datetime format stated for 'after'/'before' but not confirmed for consistency.
Pagination parameters (limit, page) present on multiple tools but no documentation of total count or next_cursor in response. Agents cannot determine if more results exist beyond the requested page.