Skip to content

Prompts

The final redacted result of every prompt must fit limits.mcpReadResponseMaxBytes. An oversized prompt is rejected whole through the same bounded protocol boundary used for resources.

MCP prompts are explicit user-selected workflow templates. Rendering a prompt performs no Discord, local-file, local-activity, planning, or write call. Eligible exact-ID fields support the policy-aware completion boundary above, while all arguments remain flat MCP strings that are strictly validated and converted into a one-line JSON input object so arbitrary text cannot escape into workflow instructions. route_discord_goal is available with every non-empty configured toolset. It treats one bounded objective as literal untrusted data, begins with standard discover_discord_tools, requires the refreshed canonical schema and complete annotations, executes only minimum bounded read-only calls, and stops at one matching plan_* result for a write objective. It never invents authority input, broadens policy, calls a tool whose readOnlyHint is false, or substitutes an immediate write when no reviewed planner exists. When an exact planner requires an operation or idempotency key and the caller omitted it, the router generates a fresh opaque bookkeeping key, retains it unchanged for later separately approved execution, and does not ask the caller to invent or confirm it. The connector-scoped application-command prompt performs one privacy-safe audit, treats returned names as untrusted, explains aggregate exposure and permission limitations, and forbids every write. The guild application-command lifecycle prompt accepts one strict complete create, update, or delete request JSON object, validates it through the authoritative command normalizer, emits only that exact caller-retained input, and requires plan-only review of complete definitions, localized inventory, permissions, reset effects, and readback boundaries. The native Interaction review prompt reads one status, pending, and continuation snapshot, treats request text as untrusted data, presents token-free capability evidence, drafts clearly unsent initial and contextual follow-up responses, and forbids both response tools. The guild-scaffold prompt accepts bounded strict JSON arrays inside two flat string arguments, validates their complete graph locally, and then emits arrays in the literal tool input. The guild-blueprint authoring prompt accepts an exact guild, bounded literal objective, audit reason, and master operation key; tells the client model to draft the narrowest supported caller-retained candidate without tools, invented IDs, remote templates, or hidden validation claims; and hands off to a separate review prompt. The guild-recovery prompt performs exactly one two-pass blueprint capture, isolates an optional exact role or channel binding, presents the caller-retained artifact, omissions, expiry, and non-backup limitations, and forbids every planner, executor, persistence step, and synthesized no-artifact opt-out. The guild-blueprint review prompt accepts one strict request JSON object, validates the complete manifest locally, and emits the exact caller-retained plan input without interpreting it as a style request or choosing a canned template. The announcement-subscription, channel-clone, channel-deletion, channel-metadata, channel-ordering, forum-tag, reaction-moderation, role-configuration, role-deletion, role-ordering, thread-governance, Guild Template, guild-settings, guild Community, guild-incident-action, onboarding, Welcome Screen, and widget-settings prompts each accept one strict request JSON object because nested prompt arguments are not portable, validate the complete partial or action-specific input locally, and emit only that exact validated input. The permission-overwrite prompt accepts bounded PERMISSION:state entries, validates every permission name and allow, deny, or inherit state locally, and emits only the named changes. The application-emoji and guild-expression prompts validate action-specific flat fields and reject URLs, transported base64 payloads, relative paths, and fields unrelated to the selected action; the guild-expression prompt additionally converts comma-separated role IDs to exact arrays and rejects duplicate IDs. The application-intent prompt accepts only an explicit privilege-expansion acknowledgement, Guild Members or Message Content, one one-shot operation key, and a bounded ephemeral rationale, then emits a plan-only workflow that treats the rationale as untrusted and forbids execution. The static rich-embed prompt accepts one strict request JSON object, validates the complete remote-free presentation and action fields locally, emits only that exact caller-retained input, and limits the workflow to local preview plus plan review without execution. The soundboard prompt validates action-specific flat fields, tagged custom, Unicode, or absent emoji selection, normalized sound names, bounded volume, exact IDs, and canonical local paths while rejecting transported audio. The AutoMod prompt accepts one strict request JSON object, validates its complete action-specific shape locally, and emits only that exact validated input. The three native-poll prompts make the create, observe, and finalize lifecycle explicit: creation validates and normalizes bounded flat arguments plus one strict answer array before plan-only review, inspection performs one aggregate read without voter identities, and ending stops at a live-count-bound irreversible plan. The scheduled-event prompt validates action-specific hosting and lifecycle fields, canonical timestamps, local cover paths, and one strict recurrence JSON value. The Stage-instance prompt accepts only exact guild and Stage-channel IDs, one strict lifecycle action, action-specific topic and notification fields, a bounded audit reason, and a one-shot operation key. The member-voice prompt accepts only exact guild and user IDs, one strict action, the action-specific destination or enabled state, a bounded audit reason, and a one-shot operation key. The webhook-creation prompt accepts only one exact channel, name, audit reason, and operation key. The webhook-change prompt accepts only one exact source channel and Incoming webhook plus a replacement name, same-guild destination, or both. Neither accepts a token or execution URL. The integration-deletion prompt accepts only exact guild and integration IDs, explicit webhook and bot consequence acknowledgments, a bounded audit reason, and a one-shot operation key. The invite-deletion prompt accepts only an exact guild ID, opaque process-local reference, bounded audit reason, and operation key; no invite code or URL field exists. The Guild Template prompt rejects raw codes and URLs by accepting only the action-specific strict request object and opaque process-local references. Rendered prompts pass through the connector's token-redaction boundary before they are returned. The application-command audit prompt is listed only with connector, message prompts are listed only with messages, the native Interaction review prompt is listed only with native-interactions, find_guild_members is listed only with members, inspect_guild_ban is listed only with bans, and each authoring, inspection, or reviewed prompt is listed only with its matching announcement-subscriptions, application-commands, application-emojis, application-entitlement-changes, application-monetization, application-security, bot-profile, attachments, automod, direct-messages, embed-messages, forum-posts, forum-tags, guild-blueprints, guild-expressions, guild-settings, guild-community, guild-incidents, guild-templates, integrations, interactions, linked-roles, polls, soundboard, scheduled-events, stage-instances, onboarding, welcome-screen, widget-settings, guild-scaffolds, channel-cloning, channel-creation, channel-deletion, channel-metadata, channel-ordering, member-roles, voice-moderation, thread-governance, role-creation, role-configuration, role-deletion, role-ordering, pins, webhooks, invites, permission-overwrites, permission-sync, deletion, or moderation toolset.

The connector-scoped audit_bot_installations prompt has no arguments and performs exactly one call to the matching read-only tool. It reports exact configured, installed, installed-in-scope, missing, and unexpected IDs plus completeness and privacy evidence; it does not resolve guild metadata, call list_guilds, mutate policy, leave a guild, or invoke any write.

The bot-profile prompt accepts an explicit application-wide acknowledgement, strict optional username and image-action fields, one one-shot operation key, and a bounded ephemeral rationale. It requires one canonical local path only for each requested image replacement, emits the exact plan input, treats presentation and file metadata as untrusted transient data, calls only plan_bot_profile_change, and stops before execution.

The global application-command lifecycle prompt accepts one strict complete create, update, or delete request JSON object, validates it through the authoritative global command normalizer, emits only that caller-retained input, and requires plan-only review of application support, explicit contexts and installation types, complete definitions, localized inventory, capacities, cross-guild permission-reset effects, and readback boundaries.

The application test-entitlement prompt accepts only strict flat create or delete fields for one configured beneficiary and subscription SKU. Deletion additionally requires the literal irreversible acknowledgement, exact entitlement ID, and original creation operation key whose completed connector receipt must prove that target. The prompt emits the exact validated plan input, explains the receipt, no-retry, readback, persistence, and rollback boundaries, calls only plan_application_test_entitlement_change, and stops before execution.

The consumable-entitlement prompt accepts only one exact configured user, consumable SKU, entitlement ID, literal external-fulfillment acknowledgement, caller-owned durable fulfillment reference, local reason, and one-shot operation key. It emits the exact validated plan input, explains that the connector cannot verify fulfillment and persists only the reference hash, calls only plan_application_entitlement_consumption, and stops before execution.

Guild-blueprint guidance identifies local whole-manifest preview and live capture as separate steps. Authoring recommends the local preview but cannot invoke it, review invokes only the live planner, and a review-required capture remains ineligible for planning until every omission and exact-bound reference has been explicitly reviewed and the partial desired state has been accepted or edited.

On a progressive tool surface, reveal the exact plan_guild_blueprint contract before invoking author_guild_blueprint. If that schema is absent, the authoring prompt returns no candidate and asks for local progressive discovery followed by a fresh prompt invocation; it never calls discovery or guesses a hidden schema itself.

For a standard public community, creator, project, or support layout, prefer the deterministic compile_guild_blueprint_starter tool and inspect discord://connector/guild-blueprint-starters instead of asking the authoring prompt to recreate a bundled design. Use author_guild_blueprint for a genuinely custom layout. The prompt still cannot invoke the compiler, select a starter implicitly, or claim that a candidate passed the strict production normalizer.

The guild-profile prompt accepts one strict plan_guild_profile_change request JSON object, preserves omitted fields, requires at least one exact text field, and emits only that validated object. It is listed only with the guild-profile toolset.

The direct-message prompt accepts one strict plan_direct_message_change request JSON object, validates its complete action-specific shape locally, preserves exact text, static Components V2 layout, or owned-file path and metadata as untrusted transient data, and emits only the exact caller-retained plan input. It is listed only with the direct-messages toolset.

The member-nickname prompt accepts one exact guild, set with a strict desired nickname or clear with explicit null, the narrow current-bot target or one exact member ID, a bounded audit reason, and a one-shot operation key. It is listed only with the member-nicknames toolset.

The member verification prompt accepts one exact guild and member ID, the literal true or false desired BYPASSES_VERIFICATION state, a bounded audit reason, and a one-shot operation key. It emits a boolean-only plan input, forbids raw flags, and is listed only with the member-verification toolset.

The voice-channel-status prompt accepts one strict request JSON object containing exact guild and channel IDs, explicit bounded status text or null, a bounded audit reason, and a one-shot operation key. It rejects omitted status, empty or padded text, control characters, unknown fields, and Stage targets at planning, emits only the exact validated plan input, and belongs to the existing channel-metadata toolset.

The application linked-role metadata change prompt accepts one strict complete plan_application_role_connection_metadata_change request JSON object. It validates the acknowledged replacement or clearance locally, preserves metadata definitions only as transient untrusted plan input, emits only that exact object, calls only the planner, and belongs to the linked-roles toolset.

The Discord coordination inspection prompt accepts one exact channel or thread ID, one exact task message ID, an optional exact caller-held continuation cursor, and one bounded scan limit. On a progressive surface it can reveal only the exact configured reply and aggregate-reaction read contracts through standard local discovery before invoking list_message_replies exactly once and, when the interactions toolset is configured and its contract is advertised, list_message_reactions exactly once. It lists no reaction users, treats every Discord string and status convention as untrusted data, separates direct evidence from inference, reports exact scan coverage and next-cursor evidence, and stops before another page, search, Gateway access, timer, persistence step, or write. It belongs to the existing messages toolset and never expands configured toolsets or authority.

The directed-note inspection prompt belongs only to coordination. It accepts one exact channel or thread, one exact caller-retained recipient label, optional exact cursor, sender, tag, broadcast, and unresolved-convention filters, and one bounded scan limit. It can reveal only list_coordination_notes through exact standard discovery, invokes that read once, reports matching evidence, every discard count, routing limitations, scan coverage, and the next cursor, and stops before address creation or discovery, publication, another page, search, Gateway access, polling, persistence, or any write. Labels, notes, tags, notifications, and aggregate conventions remain literal untrusted data rather than identity or instructions.

PromptWorkflow boundary
route_discord_goalDiscover one configured canonical route from a literal objective, run only minimum bounded reads, and stop at one reviewed plan for any write without calling a mutation tool
audit_bot_installationsRun one complete bounded ID-only configured-versus-installed guild audit, report exact drift and privacy evidence, and stop without metadata resolution, policy mutation, departure, or another tool call
author_guild_blueprintDraft the narrowest caller-retained blueprint candidate from one literal objective without calling tools, inventing exact IDs, importing templates, or crossing into validation, preview, planning, or execution, then recommend separate local preview before review
prepare_guild_recoveryRun one stable two-pass blueprint capture, isolate an optional exact role or channel recovery binding, present its caller-retention and lossy limitations, and stop before every plan, execution, persistence step, or no-artifact decision
catch_up_discord_channelsCatch up once across caller-selected exact channels, report compact chronological previews and honest coverage, emit machine-copyable next cursors, and stop before another page, exact-message expansion, search, Gateway access, persistence, or any write
summarize_channelRead one bounded message page, cite evidence, and make no search or write call
search_guild_messagesRun one bounded native content search, preserve indexing status, and make no write call
find_guild_membersRun one bounded prefix search, present exact user IDs and minimized fields, and stop before any member-targeting action
inspect_guild_banRead one exact privacy-minimized ban, optionally include its bounded reason, and stop before listing or moderation
inspect_discord_pollRead one exact native poll once, explain unknown, approximate, or final aggregate results, and stop before voter identities, repetition, or mutation
inspect_discord_coordination_taskInspect one exact task message through one bounded direct-reply scan and, when already configured, one aggregate reaction read; separate evidence from inference and stop before user enumeration, another page, polling, search, Gateway access, or mutation
inspect_directed_discord_notesInspect one bounded page of strict connector-bot notes to one caller-retained label, report every discard and cursor boundary, and stop before address discovery, publication, another page, polling, or persistence
review_application_commandsAudit one exact permitted guild's complete current-application command exposure and permission objects, explain privacy and effective-access limits, and make no write call
review_application_role_connection_metadataAudit the current application's complete bounded linked-role metadata schema, treat labels as untrusted, explain privacy and eligibility limits, and make no write call
review_application_role_connection_metadata_changeValidate one acknowledged complete linked-role schema replacement or clearance, build its application-wide keyed plan, treat every definition as untrusted transient data, and stop before execution
review_application_skusAudit the current application's complete bounded SKU catalog, treat labels as untrusted, explain commerce-data and access-evidence limits, and make no write call
review_application_monetizationAudit one exact configured guild or user through present entitlement access evidence or one exact user through subscription-lifecycle evidence, explain the privacy and authority limits, and make no write call
review_application_test_entitlement_changeValidate one strict test-entitlement creation or acknowledged receipt-proven deletion request, build its exact beneficiary and subscription-SKU lifecycle plan, explain its testing-only and irreversible boundaries, and stop before execution
review_application_entitlement_consumptionValidate one strict externally fulfilled consumable-entitlement request, build its exact user, SKU, entitlement, and hash-bound fulfillment plan, explain its irreversible and external-system boundaries, and stop before execution
review_bot_profile_changeValidate one acknowledged strict username, avatar, or banner request with conditional canonical file paths, build its identity-bound application-wide keyed plan, treat all presentation and file evidence as untrusted transient data, and stop before execution
review_guild_webhooksAudit one exact guild's complete credential-redacted webhook exposure, treat names as untrusted, explain bearer-credential and evidence limits, and make no channel or write call
review_pending_native_interactionsRead one bounded status, pending, and token-free continuation snapshot, draft clearly unsent initial or contextual follow-up responses, and stop before both response tools
review_direct_message_changeValidate one strict exact-recipient text, static Components V2, or independently gated owned-file send or reply, same-format connector-message edit, or irreversible supported-message deletion request, build its private-message plan, and stop before execution
review_attachment_messageBuild and review one exact byte-bound local-file attachment plan, then stop before execution
review_channel_creationBuild and review one additive keyed channel-creation plan, then stop before execution
review_channel_cloneBuild and review one exact atomic same-guild channel-clone plan with complete topology, preservation, capacity, overwrite, permission, privacy, and default-placement evidence, then stop before execution
review_channel_metadata_changeBuild and review one exact partial keyed channel-metadata plan, then stop before execution
review_voice_channel_status_changeBuild and review one exact ordinary voice-channel status set or explicit clear plan with transient Gateway state, connection-sensitive permission evidence, privacy guarantees, and one-shot intent, then stop before execution
review_channel_orderBuild and review one exact relative channel-order plan with complete obfuscation-safe layout, visibility-bounded HTTP, full-family payload, and connector-authority evidence, then stop before execution
review_channel_deletionValidate one strict exact-channel request and exact recovery choice, pass a supplied attestation only to the planner, present its credential-free verification and limitations with the privacy-minimized irreversible-loss plan, and stop before execution
review_forum_postBuild and review one exact keyed public forum-post plan, then stop before execution
review_forum_tag_changeBuild and review one exact keyed stable-forum tag create, metadata-update, or deletion plan from strict action-specific input, then stop before execution
review_application_emoji_changeBuild and review one exact application-wide emoji create, exact-ID rename, or acknowledged exact-ID delete plan, then stop before execution
review_guild_expression_changeBuild and review one exact privacy-safe emoji or sticker create, update, or delete plan, then stop before execution
review_soundboard_changeBuild and review one exact privacy-safe guild soundboard create, update, or delete plan, then stop before execution
review_automod_changeBuild and review one strict privacy-safe AutoMod create, update, enable, disable, or delete plan, then stop before execution
review_scheduled_event_changeBuild and review one exact privacy-safe event create, metadata update, lifecycle transition, or delete plan, then stop before execution
review_stage_instance_changeBuild and review one exact privacy-safe Stage start, topic update, or end plan, then stop before execution
review_guild_scaffoldBuild and review one bounded resumable additive scaffold frontier, then stop before execution
review_member_nickname_changeBuild and review one exact current-bot or separately gated exact-member nickname set or explicit clear plan with complete permission, hierarchy, privacy, and one-shot evidence, then stop before execution
review_member_verification_changeBuild and review one exact member's named verification-bypass boolean with complete permission, hierarchy, privacy, unrelated-bit preservation, and one-shot evidence, then stop before execution
review_member_role_changeBuild and review one exact allowlisted member-role add or remove plan with bounded direct-channel impact, then stop before execution
review_member_voice_changeBuild and review one exact member move, disconnect, server-mute, server-unmute, server-deafen, or server-undeafen plan with complete source, destination, permission, hierarchy, and privacy evidence, then stop before execution
review_thread_changeBuild and review one exact thread lifecycle, metadata, invitation-policy, connector self-membership, or exact-member plan with minimized state, complete inherited permissions, action-specific authority, privacy evidence, and strict action fields, then stop before execution
review_role_creationBuild and review one additive keyed role-creation plan with exact named permissions, then stop before execution
review_role_configurationBuild and review one exact partial standard-role configuration plan with tagged role-icon and owned local-file evidence, affected-member, hierarchy, modern-color, and permission-grantability evidence, then stop before execution
review_role_deletionValidate one strict exact-role request and exact recovery choice, pass a supplied attestation only to the planner, present its credential-free verification and limitations with the privacy-minimized irreversible-loss and dependency plan, and stop before execution
review_role_orderBuild and review one exact relative role-order plan with complete hierarchy, holder impact, sensitive-permission, management-boundary, and connector-authority evidence, then stop before execution
review_message_deletionBuild and review an exact keyed deletion plan, then stop before execution
review_message_pinBuild and review one exact content-bound pin-state plan, then stop before execution
review_poll_creationValidate one bounded immutable native poll, normalize explicit defaults, build its exact identity-and-permission-bound plan, and stop before execution
review_poll_endBuild and review one exact bot-owned poll's irreversible live-count-bound ending plan, then stop before execution even when the plan is a no-op
review_reaction_moderationBuild and review one exact user, emoji, or complete reaction-removal plan from strict action-specific input, then stop before execution
review_announcement_crosspostBuild and review one exact irreversible announcement-crosspost plan with unknown-fanout and permission evidence, then stop before execution
review_message_forwardBuild and review one exact native immutable-snapshot forward with source, target, age-restriction, complete permission, boundary, exposure, delivery-control, and one-shot evidence, then stop before execution
review_announcement_subscriptionBuild and review one exact subscribe or exact-ID unsubscribe plan with aggregate capacity, exact follower, permission, duplicate, and privacy evidence while a keyed digest privately binds the complete inventory, then stop before execution
review_webhook_creationBuild and review one exact credential-safe Incoming-webhook creation plan with complete inventory, capacity, permission, privacy, and bearer-capability evidence, then stop before execution
review_webhook_changeBuild and review one exact credential-free Incoming-webhook rename or same-guild move plan with complete source and destination evidence, then stop before execution
review_webhook_deletionBuild and review one exact credential-free Incoming-webhook deletion plan, then stop before execution
review_guild_integration_deletionBuild and review one exact privacy-safe guild-integration deletion plan with explicit webhook and bot consequence acknowledgments, then stop before execution
review_guild_departureBuild and review one exact privacy-safe connector-departure plan with explicit access-loss, re-entry, and quiescence acknowledgments, then stop before execution
review_invite_deletionBuild and review one capability-safe invite revocation plan from an opaque process-local reference, then stop before execution
review_guild_template_changeBuild and review one capability-safe native Guild Template create, synchronize, metadata-update, or delete plan from strict action-specific input and an opaque reference when required, then stop before execution
review_onboarding_changeBuild and review one exact complete guild onboarding replacement plan with all additions, removals, modifications, and safety evidence, then stop before execution
review_welcome_screen_changeBuild and review one exact complete ordered Welcome Screen replacement plan with all additions, removals, moves, modifications, and safety evidence, then stop before execution
review_widget_settings_changeBuild and review one exact complete authenticated widget-settings replacement plan with action-sensitive public-exposure authorization and privacy evidence, then stop before execution
review_guild_profile_changeBuild and review one exact sparse guild name or description plan with complete permission, media-presence, privacy, and one-shot evidence, then stop before execution
review_guild_settings_changeBuild and review one exact sparse named guild-settings plan with field effects, exact channel evidence, unknown-bit safety, and privacy evidence, then stop before execution
review_guild_incident_action_changeBuild and review one exact sparse time-bounded guild incident-action plan with complete authority, privacy, effect, risk, and local-reason evidence, then stop before execution
review_guild_blueprintRecommend separate authority-free whole-manifest preview when needed, then build and review only the next fixed-order frontier or channel-ordering, Community, AutoMod, or publication blocker with the complete freshly-assessed-versus-deferred overlay of one exact caller-retained additive structure, exact-ID role and channel configuration, bottom-up role and channel ordering, profile, settings, Community, Welcome Screen, onboarding, staged AutoMod, and ordered static publication manifest, with optional live-capture review guidance, then stop before execution
review_channel_permission_overwriteBuild and review one exact named-delta update or explicit overwrite-deletion plan, then stop before execution
review_channel_permission_syncBuild and review one exact complete parent-category permission-sync plan with structural overwrite delta, protected-member, connector-authority, future-propagation, replacement, quiescence, and privacy evidence, then stop before execution
review_member_moderationBuild and review one exact keyed moderation plan, then stop before execution
review_bulk_guild_banBuild and review one exact native batch-ban plan with every target, permission, hierarchy, partial-success, readback, and keyed-digest boundary, then stop before execution

The direct-message, announcement-crosspost, message-forward, announcement-subscription, application-emoji, bot-profile, attachment, AutoMod, channel-clone, channel-creation, channel-deletion, channel-metadata, voice-channel-status, channel-ordering, forum-post, forum-tag, guild-blueprint, guild-expression, Guild Template, guild-profile, guild-settings, guild-incident-action, guild-integration deletion, reaction-moderation, poll-creation, poll-ending, soundboard, scheduled-event, Stage-instance, onboarding, Welcome Screen, widget-settings, guild-scaffold, member-nickname, member-role, member-voice, role-creation, role-configuration, role-deletion, role-ordering, message-pin, webhook-creation, webhook-change, webhook-deletion, invite-deletion, channel-permission-overwrite, deletion, moderation, and bulk-guild-ban prompts do not collapse approval stages. They explicitly forbid their execution tools, leaving MCP host write approval, signed elicitation, fresh-plan verification, interactive confirmation, and pending content-free records on the separate write call.

review_guild_departure follows the same plan-only rule and explicitly forbids execute_guild_departure.

review_channel_permission_sync follows the same plan-only rule, belongs only to permission-sync, and explicitly forbids execute_channel_permission_sync, including when the planner proves that no write is needed.

Canonical source: docs/reference.md

Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.