Skip to content

Global application commands

Keep global application-command mutation behind capabilities.globalApplicationCommandChanges, pinned application and bot identities, and the independent application-commands toolset. Never infer this application-wide authority from guild command changes, command exposure audit, native Interaction management, guild scope, another administrative capability, a command name, or another application's command object. Do not accept a caller-selected application ID, application-default inheritance, bulk overwrite, raw REST, name-targeted mutation, partial definitions, type changes, command-permission writes, propagation polling, or immediate-call paths.

Accept only strict complete canonical chat-input, user, message, or Primary Entry Point definitions with explicit nonempty canonical contexts and installation types. Require explicit global-exposure acknowledgement, named default member permissions or null, explicit NSFW state, complete localization arrays, and the exact type-specific option or handler fields. Require User Install for private-channel context, fresh application support for every requested installation type, and fresh EMBEDDED evidence for every Primary Entry Point. Reject unknown fields, raw numeric codes or permission bitfields, omitted complete-state fields, unsupported application contexts, future evidence that cannot be understood, and incompatible option combinations.

Planning must re-verify the pinned identities and complete application installation configuration, fetch the complete full-localization global command inventory, and bind application support, EMBEDDED evidence, the canonical inventory digest, every command ID, version, type, transient name and definition digest, separate type capacities, total capacity, exact target, complete current and desired definitions, collision and no-op decisions, global exposure, cross-guild permission-reset effects, privacy claims, risks, warnings, operation-key hash, and verification contract into the process-keyed plan. A same-name and same-type collision must block creation because Discord POST otherwise upserts. Require exact-ID targeting and immutable type for update and deletion. Require explicit global deletion and cross-guild permission-reset acknowledgements where applicable. Never claim to enumerate affected guilds or permission targets because the bot-token trust boundary cannot do so.

Preserve every reviewed-write gate: fresh complete evidence, process-keyed plan binding, destructive MCP annotation, write-aware host approval, signed request state, interactive confirmation, a final fresh matching plan, durable application-wide global-command collection coordination, atomic one-shot key reservation, pending content-free activity, one non-retried mutation, strict route-specific response validation, and exact complete inventory and survivor readback. Creation must accept only one exact new command and reject Discord's same-name upsert response. Update must send one exact-ID complete replacement. Delete must send one exact-ID request. A no-op must bypass confirmation, coordination, reservation, activity, and mutation.

Permit a deterministic Discord client refusal other than timeout or rate limiting to settle as failed. Treat rate limiting, transport ambiguity, server failure, malformed success, response mismatch, complete-readback failure, survivor drift, or completion-record failure as uncertain and potentially completed. Spend every reserved key, quarantine the application-wide global-command collection for the process lifetime, and never retry, bulk reconcile, compensate, recreate, restore permissions, or roll back automatically. Persist only exact application, bot, and command IDs; command type; definition, inventory, plan, and operation-key digests; timestamps; fixed status and verification values; activity ID; and sanitized error category. Never persist command, option, choice, or localization text, permission target IDs, Discord names, raw requests or responses, raw keys, transport causes, or audit reasons.

Canonical source: SECURITY.md

Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.