Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add razvangirgiz/wazap --skill wazap-setupgit clone --depth 1 https://github.com/razvangirgiz/wazapWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/razvangirgiz/wazap/wazap-setup)<a href="https://agentmods.dev/skills/razvangirgiz/wazap/wazap-setup"><img src="https://agentmods.dev/badge/skills/razvangirgiz/wazap/wazap-setup/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/razvangirgiz/wazap/wazap-setup"><img src="https://agentmods.dev/badge/skills/razvangirgiz/wazap/wazap-setup.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00076 | $0.01359 |
| Opus 5 | $0.00038 | $0.00679 |
| Sonnet 5 | $0.00015 | $0.00272 |
| Haiku 4.5 | $0.00008 | $0.00136 |
Grade A, and why
wazap-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 89 lines — stays where its author put it; the contents beside it link to each section on GitHub.
wazap setup
wazap links the user's own WhatsApp account as a "linked device" and exposes it as MCP tools. The phone must stay online; the link needs the user's hands once.
Diagnose first
Run npx wazap-mcp status and branch on its output. It never contacts WhatsApp, so it is safe at any point.
status says |
Do |
|---|---|
wazap: command not found / npx fails |
Node 20+ is required. node --version; install from nodejs.org if older. |
linked: no |
Go to Link. |
linked: yes, server: running |
The server is up. If tools still fail, call get_status and follow its fix. |
linked: yes, server: not running |
Go to Connect a client. |
Below those lines is a checks: section. Every ✗ carries the command that
fixes it; run that command rather than improvising.
checks: line |
What it means |
|---|---|
✗ node |
The Node version is below 20. Nothing else will work until it is upgraded. |
✗ data dir |
Missing, not a directory, mode other than 0700, or not writable. The line names the chmod to run. |
– lock: stale |
A previous server died without cleaning up. Harmless; the next start reclaims it. |
✓ lock: held |
A server is running. Do not run logout or status --live; ask through the client with get_status. |
✗ credentials |
Unreadable. Call link_account, or npx wazap-mcp logout then npx wazap-mcp login. |
writes: off |
Write tools are not registered. Enabling them is Allow writes. A Bearer write token does not turn writes on; a read token never sees write tools. |
– update |
A newer wazap exists, or the check could not reach npm. Never blocking. |
npx wazap-mcp status --live reaches WhatsApp for real and reports whether the
phone is reachable, how many chats synced and how old the last message is. It
refuses while a server holds the lock, because one process owns the session.
--json gives the same report as one object.
Link
Inside an MCP client that already has the whatsapp tools, call link_account
with the user's number in international format. No terminal is involved. It
returns an 8-character code, and get_status reports linking with that code
until the phone accepts it. Tell the user: WhatsApp → Settings → Linked devices
→ Link a device → Link with phone number instead, then type the code. Poll
get_status every 10 seconds until it says connected, for up to 3 minutes.
Codes expire, so call link_account again for a fresh one if the status falls
back to not_linked.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +1 lines d669b8c802b9
- 9d ago First seen · 88 lines · 76 tokens per session scan A 76c7ed839641
wazap-setup is a skill published in the GitHub repository razvangirgiz/wazap (0 stars, last pushed yesterday), licensed MIT. It adds 76 tokens to every session and 1,359 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…