Directed coordination routing
Keep directed coordination in its independent toolset. Address creation must remain a local credential-free randomness operation with no policy read, Discord access, registration, persistence, activity record, or authority. Accept later addresses only by one strict canonical syntax. Never claim that syntax, random issuance, Discord authorship, page observation, a sender field, a tag, a body, a notification mention, or a reaction authenticates a participant, binds a model or session, reserves a name, proves ownership or liveness, conveys approval, or authorizes another tool.
Read one exact policy-permitted channel or inherited thread page per call. Require pinned application and bot identity, exact route and successful channel-history evidence, bounded unique messages with deterministic ordering, and strict connector-bot authorship before parsing. Discord exempts content in messages an app sends from the Message Content privileged intent, so this bot-authored protocol must not require that intent. Never broaden the reader to foreign-authored content without introducing the appropriate privileged-intent gate. Admit only canonical plain ordinary notes or strict same-channel replies. Reject or count every unsupported webhook, foreign author, rich payload, attachment, component, embed, sticker, snapshot, poll, TTS, everyone or role mention, malformed notification, reference, or envelope without returning raw evidence. A malformed page-level identity, route, duplication, timestamp, or shape claim must fail the whole read closed. See Discord's Message Content intent contract.
Address observation may return only page-local sender labels, exact last-message IDs, counts, and timestamps. It must omit bodies, tags, recipients, notification targets, profiles, reaction users, raw payloads, and differently addressed content and must never become a registry, directory completeness claim, listener, presence signal, or mailbox guarantee. Recipient reads may return only exact matches and selected broadcasts after strict filters. Fixed aggregate status emoji are optional untrusted conventions; user enumeration remains a separate disabled-by-default gate, and no aggregate can identify a claimant, prove work, or authorize execution.
Route every note write through the existing guarded message interaction with one stable idempotency key, exact interaction-channel scope, complete direct or thread send evidence, host write approval, shared anti-spam controls, pending content-free activity, strict response validation, and exact readback. Keep the optional exact notification user separate from the routing label and require both visible mention alignment and the existing mention allowlist. Return no body, address, tag, notification ID, idempotency key, or compiled envelope from a successful send.
Never add a connector-owned address registry, note database, retained listener, timer, polling loop, automatic second page, background worker, persona authority, name-based protected target, or autonomous executor. Never persist an address, note body, tag, recipient, notification target, cursor, observation, status signal, profile, or raw Discord response in activity, operation, durable coordination, diagnostics, errors, logs, metrics, traces, or caches. The MCP host and model provider remain external custodians of invoked inputs and matching transient results.
Keep principal permission diagnostics read-only and inside the same exact guild and derived channel scope as other reads. Fetch a requested member only through the exact guild-member endpoint and private-thread membership only through the exact thread-member endpoint; never replace either with member enumeration or a privileged Gateway member cache. Validate the complete bounded role inventory, exact response identities, overwrite uniqueness, arbitrary-width bitfields, timeout timestamps, thread parent, and hierarchy target before claiming a complete decision. Missing or contradictory evidence must produce an unknown decision or fail closed, never an optimistic allowance.
Treat channel-role audits as standalone role baselines. Member-specific overwrites, member timeouts, and private-thread membership cannot be attributed to a role; report their limitations explicitly and do not inspect or return member profiles to fill the gap. Permission diagnostics may return live role names and decision evidence to the MCP caller, but must not persist names, member data, permission results, or raw Discord responses.
Canonical source: SECURITY.md
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.