Skip to content

Command-processing signals

Keep transient processing feedback inside the existing interaction capability and exact channel or thread allowlist. Require the verified connector bot as the only target and one caller-known exact source message. Never expose a generic typing dispatcher, arbitrary presence control, repeating loop, duration control, model-selected target, name lookup, or authority inherited from a parent, guild, read scope, native Interaction, or Gateway event.

Before contact, freshly prove a supported active channel, an ordinary user-authored regular or reply source, both parsed and literal direct mention of the verified bot, consistent timestamp and snowflake creation evidence inside the fixed freshness window, exact thread parent, exact private-thread membership where applicable, complete role and overwrite evidence, and effective read plus send permission. Fail closed on a webhook, bot, system source, indirect mention, stale or future source, malformed evidence, unsupported or inactive target, incomplete permission inventory, missing scope, or identity drift.

Use one bounded process-local ledger to coalesce the exact channel-and-source pair while fresh. Keep transient and durable per-channel cooldowns separate so the hint does not postpone the response, but charge both against the shared rolling interaction budget. Append pending content-free activity before exactly one non-retried bodyless request, accept only the documented 204, and return only exact identifiers, fixed status, replay state, and expiry. Never return or persist source content, mention data, profile fields, permission evidence, response data, or transport cause. Since Discord exposes no typing-state readback and local coalescing ends on restart, advertise the tool as non-idempotent and never treat it as work, completion, liveness, or delivery evidence.

Canonical source: SECURITY.md

Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.