Robin Saige we check the tools AI agents call

WhatsApp

io.github.mcp-dir/whatsapp-mcp

Connect a personal/Business WhatsApp account via QR pairing (multi-device, like WhatsApp Web). Send

— the operator's own registry description reported

Publisher io.github.mcp-dir · first seen 2026-08-22 · endpoint https://api.mcp.ai/p_whatsapp

allow
verdict
gateway
cluster
ok_tools
answers
47
tools served

Dependency rating derived

allow
allow — gateway · action ● · V n/a
allow — because answers ●, 47 tools legible (band B) ●, no confirmed drift in 3 probes ●; not yet checked: truth (0 runs)

Cluster gateway · distinctiveness 0.627 (unusual). Every figure is a percentile or class within the 15,472-server censussee the whole spectrum.

Does it answer? Q1 · observed
answersalive_tools
latency650 ms
vs populationslow
protocolcurrent
authopen
Can it be used? Q4 · observed
tools47
vs populationhigh
capabilities1
harnessB
Did it hold when checked? Q3–Q4 · derived
identityfarm_member
servers on its host1115
verifiabilityunassessed
duplicate inventoryno
drift events0
answers trueno primary

🔏 Signed receipt rr_3e37f5620de5742cf58e6c09 · ed25519 · key rs-rcpt-2026-08 — this rating is tamper-evident; an agent gets the full signature from check_server and can verify it against the published key.

Q1Does it answer?gateway — 3 probes ●evidence ↓
Q2What is it?action ● evidence ↓
Q3Can it be checked?V n/a for this kind ◐evidence ↓
Q4Did it hold?harness B · truth not yet run · no drift ●evidence ↓
Q5What company does it keep?gateway · 1115 on its host (context, not verdict) ◐evidence ↓

● observed · ◐ derived · ○ reported — the verdict synthesizes Q1–Q4; Q5 is context. Methodology →

History observed

Every probe we made, oldest → newest (3 shown, 2026-08-23 → 2026-09-06). Green answered · amber answered-but-walled · red no useful answer. A gap in our cadence is a gap in coverage, not evidence about the server.

changelog (1 events)
datetypewhat changed
2026-08-23outcomefirst probe: ok_tools

What kind of tools these are derived

Verification only means something relative to a tool's NATURE — an email-sender has no "true answer", a generator has no answer key. Classification evidence: classified from tool names/descriptions/annotations WE OBSERVED. What checking applies to each kind (the full methodology →):

naturetoolsmeaning what checking applies
action22changes the worldno true answer exists; we check the CONTRACT (destructive/read-only/idempotent declarations, error legibility) and never fire real actions
retrieval-public16serves public factstruth-checkable against a public source — the V-ladder applies in full
unclassified6not classifiable from its textTier-1 only until its tools describe themselves
orchestration3routes other toolsidentity + fronted-service disclosure checks (gateway vs costume)

Tools last seen observed

authenticate connect marketplace report_bug show_version toolkit_info whatsapp_chat_archive whatsapp_chat_metadata whatsapp_chat_mute whatsapp_chat_pin whatsapp_chat_unarchive whatsapp_chat_unmute whatsapp_chat_unpin whatsapp_chats whatsapp_config_get whatsapp_config_set whatsapp_contacts_get whatsapp_contacts_list whatsapp_group_manage_create whatsapp_group_manage_invite_link whatsapp_group_manage_join whatsapp_group_manage_leave whatsapp_group_manage_requests whatsapp_group_manage_update whatsapp_group_members whatsapp_group_participants_add whatsapp_group_participants_demote whatsapp_group_participants_promote whatsapp_group_participants_remove whatsapp_groups whatsapp_history_backfill whatsapp_history_coverage whatsapp_list_accounts whatsapp_message_delete whatsapp_message_edit whatsapp_message_forward whatsapp_messages whatsapp_messages_write whatsapp_poll_create whatsapp_poll_vote whatsapp_react whatsapp_search whatsapp_send_media whatsapp_send_text whatsapp_sync whatsapp_webhook_get whatsapp_webhook_set

Harness readiness observed

Can an agent's harness pick this tool and call it correctly? Graded on the three things an agent reads — name, description, typed parameters. Band B — usable, with rough edges.

legibility checktools passingok
name is clear & specific47/47
has a description47/47
description is substantive47/47
parameters are typed47/47
parameters are described5/475/47

47 of 47 tools graded · 47 with a captured input schema. RS-008, Tier-1 — no domain knowledge, applies to any tool. “Alive” is not the same as “usable”.

Truth checks observed

Not in the Tier-2 trade lane, or not yet checked. Tier-2 re-derives a server's answers against published primary sources — see truth checks.

Protocol conformance observed

2025-06-18
protocol version
session model
0.9.342
server version mcp-ai

Capabilities: tools

Drift observed

No confirmed drift on record. Baseline set 2026-09-06; changes appear here after human review.

raw probe records
probed (UTC) outcomehttpmsprotocol
2026-09-06T06:16:40Zok_tools2006502025-06-18
2026-08-30T06:16:28Zok_tools2004102025-06-18
2026-08-23T06:13:57Zok_tools2001432025-06-18

Watch or embed this verdict

verdict badge

Operators: put the live verdict in your README — it updates with every census, links back here, and is a dated observation, never a warranty:

[![Robin Saige verdict](https://robinsaige.com/badge/io.github.mcp-dir/whatsapp-mcp.svg)](https://robinsaige.com/s/io.github.mcp-dir/whatsapp-mcp)

Depend on it? Subscribe to its change feed — outcome changes and confirmed drift, no account needed. Building on it? The full dossier as JSON — verdict, rating, truth checks, history — stable enough to gate CI on.

← overview

Operator of this server? Everything we hold about it is on this page — free, no account, for anyone. Wrong attribution, stale probe, misclassification? Dispute this record →