whatsapp-macos

Warn

Audited by Socket on Apr 3, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capabilities fit the stated WhatsApp-control purpose, and the tool scope is relatively narrow, but the install trust is weakened by an unverifiable package-name/command mismatch and lack of clear publisher provenance for `whatsapp-mcp-macos`. The skill also enables autonomous real-world messaging from the user's account, which raises risk even with confirm-before-send guidance.

Confidence: 84%Severity: 63%
SecurityMEDIUM
Sources/WhatsAppMCP/main.swift

No clear supply-chain/memory-obfuscation or network-based malicious behavior is present in this fragment. However, the code is an Accessibility-driven WhatsApp automation agent that (1) reads private message contents and (2) can send arbitrary messages provided via MCP inputs, while also manipulating the user clipboard and logging sensitive queries/descriptions to stderr. The main risk is abuse of the MCP interface (unauthorized callers) for privacy invasion and message spoofing, not direct exfiltration/C2 in this file.

Confidence: 72%Severity: 70%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:26 PM
Package URL
pkg:socket/skills-sh/m13v%2Fwhatsapp-mcp-macos%2Fwhatsapp-macos%2F@a752495747e14db604001ca7965eb11b1eaa5815