Twelve tools put personal chats and outbound messages in one agent
WhatsApp MCP exposes 12 tools for contact search, chat listing, message retrieval, context lookup, text sending, file sending, voice messages, and media downloads. The Go bridge links a personal account through WhatsApp's multi-device interface and stores chat data in SQLite. A Python process then presents those operations to Claude Desktop or Cursor over MCP. That is a useful combination, but it puts private data and an action channel behind the same model.
The README names the risk directly: untrusted message content can carry prompt injection, the agent can read private material, and it can send data elsewhere. This is the familiar MCP security failure where outside content, sensitive access, and outbound actions meet. Tool approval helps, but the available action is still powerful. A retrieved message can influence the same agent that has access to send_message, send_file, and local downloaded media.
The working setup is two processes, two languages, and a phone
The documented route starts the Go bridge inside whatsapp-bridge, then launches the Python MCP server through uv from the client configuration. The first bridge run displays a QR code for phone authentication. The README says the session may need reauthentication after about 20 days. Claude Desktop and Cursor need absolute paths in their JSON configuration, while voice-message conversion adds FFmpeg when the input is not already Ogg Opus.
There is a documentation mismatch before you begin. The prerequisites say Python 3.6 or newer, but whatsapp-mcp-server/pyproject.toml requires Python 3.11 or newer. Windows is more involved because go-sqlite3 needs CGO and a C compiler. The README recommends MSYS2, enabling CGO_ENABLED=1, and adding its compiler directory to PATH. Linux still needs both the Go and Python processes kept alive.
What happened when we ran it
Our unprivileged Debian sandbox installed the Go bridge at commit 7d6a06d in 13 seconds. Go fetched 33 packages, and the build completed successfully in 76 seconds on 3 CPUs with 8 GB of RAM and no secrets. The repository was small: 14 files, roughly 2,479 lines of source, and a 3.3 MB checkout.
go test completed in 18 seconds and reported 0 passed and 0 failed out of 0 tests. That is a successful command, not evidence that QR login, message synchronization, SQLite writes, contact resolution, or media delivery works. Our scan found no tests directory, no CI workflow, and no Dockerfile. We did not authenticate a WhatsApp account or exercise the Python MCP process, so the run says only that the Go bridge installs and compiles.
Port 8080 can send messages without an authentication check
commit 7d6a06d starts the Go REST server with :8080, which listens across network interfaces rather than only on localhost. Its /api/send and /api/download handlers validate request fields but do not check a token or caller identity. A pending pull request proposes authenticated bridge access and safer media paths, but that code is not in the reviewed commit. Keep this bridge behind a local firewall, or patch it before linking any account.
Local SQLite storage does reduce routine dependence on a hosted message database. It does not mean messages stay away from the model. The README says content is sent to the language model when the agent accesses it through a tool. Session data lives in whatsapp.db, and indexed chats live in messages.db. Backups, filesystem permissions, MCP logs, downloaded media, and the model provider all become part of the privacy boundary.
A July 2025 main branch trails 158 open pull requests
The main branch's last push was July 13, 2025, at the same 7d6a06d commit our lab built. GitHub showed 6,372 stars and 251 combined open items on October 2, 2026: 93 issues and 158 pull requests. Contributors were still opening fixes in October 2026, including proposals for bridge authentication and updated pairing, but those changes had not reached main. Active contributors do not compensate for an upstream that is not merging them.
The issue queue shows what that lag costs. Issue 344 reports media downloads returning 403 even while text synchronization works. Issue 198 documents contact-name confusion after WhatsApp's move toward linked-device identifiers. Multiple open pull requests propose updates to the underlying whatsmeow client, contact mapping, and media handling. The only GitHub release, v0.0.1, was published in April 2025.
This repository is readable enough to fork, and our 76-second build gives a useful starting point. As a ready-to-connect personal assistant, it asks for too much trust: no tests, a stale main branch, unauthenticated network handlers, and direct access to private conversations. Use a spare account and narrow network boundary if you are studying the design. Do not treat the current main branch as a finished personal-messaging product.

