skill-candidates/wacli/SKILL.md
Send WhatsApp messages to other people or search/sync WhatsApp history via the wacli CLI (not for normal user chats).
npx skillsauth add grtninja/skill-arbiter wacliInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use wacli only when the user explicitly asks you to message someone else on WhatsApp or when they ask to sync/search WhatsApp history.
Do NOT use wacli for normal user chats; OpenClaw routes WhatsApp conversations automatically.
If the user is chatting with you on WhatsApp, you should not reach for this tool unless they ask you to contact a third party.
Safety
Auth + sync
wacli auth (QR login + initial sync)wacli sync --follow (continuous sync)wacli doctorFind chats + messages
wacli chats list --limit 20 --query "name or number"wacli messages search "query" --limit 20 --chat <jid>wacli messages search "invoice" --after 2025-01-01 --before 2025-12-31History backfill
wacli history backfill --chat <jid> --requests 2 --count 50Send
wacli send text --to "+14155551212" --message "Hello! Are you free at 3pm?"wacli send text --to "[email protected]" --message "Running 5 min late."wacli send file --to "+14155551212" --file /path/agenda.pdf --caption "Agenda"Notes
~/.wacli (override with --store).--json for machine-readable output when parsing.<number>@s.whatsapp.net; groups look like <id>@g.us (use wacli chats list to find).tools
Run a defender-first security sweep on code, configs, prompts, model/tooling surfaces, or third-party contribution lanes. Use when a request involves safe bug, leak, zero-day-class, exploit, or hack hunting for protection, when contributing to outside repositories and you want a focused security pass, or when touching auth, secrets, permissions, network exposure, prompt/tool boundaries, data flow, or update/build surfaces. This skill is defensive only and must never be used for weaponization or unauthorized access.
development
Validate and repair VRM Sandbox startup acceptance with shim-first local model authority, frontend/backend bring-up, and avatar-runtime launch proof. Use when launch behavior, chat handoff, voice fallback, or runtime bridge acceptance must be verified end to end.
documentation
Align documented voice-command catalogs, endpoint action allowances, and live runtime handlers so operator-visible voice surfaces match what the stack can actually execute. Use when voice command docs, parser matrices, endpoint permissions, or runtime action routing drift apart.
development
Track SkillHub trend and topic drift, maintain a bounded rewrite watchlist, and surface emerging gaps worth turning into repo-owned skills. Use when the marketplace query set shows new families or when the current shortlist has gone stale.