Model Context Protocol server for Evolution API WhatsApp integration, providing tools to create instances, send messages, manage groups, and control WhatsApp accounts
This server provides 30 WhatsApp API tools with basic schema definitions and descriptions. However, most tools have minimal, generic descriptions (under 100 chars) that lack actionable context for LLM decision-making. Parameter descriptions are sparse, many lack detail about expected formats, constraints, or dependencies. Schemas are present but minimalist: most parameters lack examples or detailed type information. Error handling is not visible in the provided code. The tool definitions appear inferred from file structure rather than explicit registration. Security concerns exist: no evidence of secret injection patterns, and tools operate directly on external APIs without visible validation or rate-limiting guards. This is a typical community server with functional but underdeveloped definitions.
Connect to a WhatsApp instance to start a session
Create a new WhatsApp instance using Evolution API
Permanently delete a WhatsApp instance from the server
Retrieves all WhatsApp groups for a given instance
Get a list of all WhatsApp instances or a specific one by name
Find WhatsApp chats with optional filtering by ID, name, or archive status
Tool 'some_function' has a generic, non-descriptive name that does not follow verb_noun convention. Name should clearly indicate what action it performs.
Most tool descriptions are 65 characters or fewer, below the production baseline of 194 chars average (p10=34, p90=392). Descriptions lack context about WHEN to use each tool vs similar ones, prerequisites, or recovery guidance.
Parameter 'instanceName' appears in nearly all tools but lacks detail about format, length constraints, or how to obtain a valid instance name. Should describe: 'Alphanumeric string (2-50 chars) identifying a WhatsApp instance created via create_evolution_instance.'
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 58 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 49 | - | v1 |
Find WhatsApp contacts with optional filtering by ID or name
Find a WhatsApp group by its JID (Group ID)
Find all members of a WhatsApp group by its JID (Group ID)
Check the connection state of a WhatsApp instance (connected or disconnected)
Get information about the Evolution API server, including version and status
Retrieve the current behavior settings for a WhatsApp instance including call handling, message receipts, and online status settings
Retrieve the current webhook configuration for a WhatsApp instance
Logout from a WhatsApp instance (disconnect without deleting the instance)
Restart a WhatsApp instance
Send a message with interactive buttons to a WhatsApp chat
Send a contact to a WhatsApp chat
Send a list message to a WhatsApp chat
Send a location to a WhatsApp chat
Send a media file (image, video, audio, document) to a WhatsApp chat
Send a plain text message to a WhatsApp chat
Send a poll to a WhatsApp chat
Send a reaction emoji to a WhatsApp message
Send a status message to WhatsApp
Send a sticker to a WhatsApp chat
Send an audio message to a WhatsApp chat
Set the presence status of a WhatsApp instance
Configure behavior settings for a WhatsApp instance
Set or update the webhook configuration for a WhatsApp instance
An example tool
No visible error handling or recovery guidance in tool definitions. When a user does not exist, a group is not found, or API authentication fails, LLMs receive no context about what to do next. Error responses should include 'Did you mean:' suggestions and next-step guidance.
Tools that send messages or delete instances (send_plain_text, send_media, delete_evolution_instance, etc.) modify external state but lack explicit confirmation/dry-run patterns. Agents may accidentally send duplicate messages or delete wrong instances on retry.
No validation visible for critical parameters like 'phoneNumber', 'mediaUrl', 'latitude'/'longitude', or 'emoji'. Tools should validate format/range server-side and return actionable error messages (e.g., 'Invalid phone number: must be E.164 format +[country code][number]').
Tools like 'fetch_evolution_instances' and 'find_chats' return lists but lack documented pagination, limits, or total count fields. No evidence of per-request page/offset/limit parameters or capping behavior. Large result sets could exhaust context window.
Output schemas are not visible in the provided code. Tool definitions list input schemas but do not document what fields and types are returned, preventing LLMs from planning downstream calls and extracting required data.
No evidence of secret injection pattern. If Evolution API keys or WhatsApp tokens are passed via environment variables, that's correct. If they are embedded in tool parameters or configs, they will leak into MCP logs and agent traces.
Presence enum values 'available' and 'unavailable' are documented, but many enums lack descriptions. E.g., mediaType enum ['image', 'video', 'audio', 'document'] should explain: 'Format of media to send. image: JPEG/PNG up to 16 MB, video: MP4 up to 100 MB, audio: MP3/OGG up to 100 MB, document: PDF/DOC up to 100 MB.'