Skip to content

AutoMod

Keep AutoMod inventory and exact lookup behind a separate audit gate and exact guild allowlist. Project list results to structural counts and reference health, return complete policy strings only through deliberate exact lookup, and treat every name, keyword, regex, preset, custom response, and Discord string as transient untrusted data. Never ingest AutoMod execution events because their payloads can contain message content, matched content, and matched keywords.

Keep changes behind an additional gate. Require complete MANAGE_GUILD evidence, conditional MODERATE_MEMBERS for timeout actions, strict trigger and action compatibility, complete exact role and channel references, and a separate exact visible alert-channel allowlist. Always create rules disabled, require a separate reviewed enable action, and require a disabled rule before policy update or deletion. Every write must use a fresh keyed plan, signed approval, durable guild AutoMod-collection coordination, one-shot reservation, pending content-free activity, one non-retried mutation, and exact rule-state or absence readback.

Persist strict schema-2 AutoMod receipts only. Bind the normalized caller-retained request and pinned identities through a token-derived keyed request digest, and reject schema-1 receipts without a parser, fallback, or migration. After pinned facade identity verification, inspect the receipt before guild, permission, inventory, or exact-rule reads. Never recover a created rule from its name, trigger, creator, singleton status, or inventory position; only a matching completed receipt may supply its exact rule ID. Request mismatch, nonterminal or malformed evidence, drift, and uncertainty must remain content-free blockers, and uncertainty must retain durable quarantine.

Canonical source: SECURITY.md

Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.