Application Activity instances
Inspect Activity instances only for the configured and verified current application and bot. Accept one bounded opaque instance ID plus one exact expected guild and channel already inside ordinary read scope, and optionally one exact user ID for a boolean membership answer. Accept no caller-selected application, participant enumeration, private-channel target, display name, profile, token, URL, Gateway dependency, cache, write, activity record, operation receipt, telemetry payload, or persistent file.
Require the Discord response to match the pinned application, requested instance, and exact expected public guild-channel location before returning any active evidence. Fail closed on private-channel locations, guild or channel drift, malformed or duplicate participant IDs, malformed known fields, excess bounds, unknown location kinds, or identity mismatch. Treat only Discord's exact not-found response as inactive or unavailable; do not convert transport, rate-limit, server, or malformed-response failures into absence.
Return only verified application and bot IDs, active state, exact expected location, launch ID, participant count, optional membership evidence for the one caller-supplied user, fixed warnings, and count-only unknown fields. Never return or persist the participant list, display names, profiles, opaque location ID, raw response, error evidence, or transport cause. Describe the result as a transient snapshot, never as durable membership, authorization, an Activity launch or join, or voice-session evidence.
Canonical source: SECURITY.md
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.