AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itprivacy

WhatsApp MCP: why it is not safe to use

WhatsApp MCP passed most checks, but it can access and store private chat history and send messages or files without a built-in confirmation step.

What we found

Our review did not find hidden instructions, hardcoded secrets, obfuscated code, or undisclosed remote code execution. The README also openly describes the skill's behavior and notes MCP prompt injection risk.

The main concerns were about access and action scope. This skill legitimately connects to a personal WhatsApp account, can reach highly sensitive private message archives, and stores WhatsApp history locally in SQLite. That means installation should come with clear user understanding of what data becomes available to the tool and where it is retained.

We also found that tool calls can send WhatsApp messages and files immediately, with no built-in confirmation step. In addition, its audio conversion flow uses `ffmpeg -y`, which can overwrite a generated `.ogg` file without prompting.

What to do instead

Use this skill only if you specifically need WhatsApp access and are comfortable with local retention of chat history. Prefer setups that add human confirmation before sending messages or files, and review local storage handling before installation. If you do not need message archive access, choose a narrower integration with less access to personal communications.

Want the same outcome, safely? Use our checked skill instead.

Source: https://github.com/lharries/whatsapp-mcp

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.