Message forwarding
Do not add an immediate message-forward shortcut or bypass the dedicated forwarding toggle, exact direct source and target channel allowlists, pinned application and bot identities, confirmed Message Content intent, exact source message ID, same-guild default boundary, separate cross-guild toggle, complete endpoint guild, member, role, channel, and overwrite evidence, source VIEW_CHANNEL plus READ_MESSAGE_HISTORY, target VIEW_CHANNEL, READ_MESSAGE_HISTORY, plus SEND_MESSAGES, process-keyed content-bound planning, signed interactive confirmation, write-aware MCP host approval, final fresh-plan match, durable exact-target coordination, atomic one-shot key reservation, pending content-free activity, one non-retried create request, or strict response and independent readback verification. If a client cannot support MCP elicitation, keep forwarding unavailable in that client.
Accept only two different exact direct GUILD_TEXT or GUILD_ANNOUNCEMENT channels and one exact default, reply, chat-input command result, or context-menu command result source. Reject threads, polls, calls, activities, unsupported system types, malformed or missing reply references, an existing immutable snapshot, the HAS_SNAPSHOT source flag, nested forward references, batches, fuzzy selection, name resolution, caller-supplied content, caller-supplied embeds or components, arbitrary payload fields, and automatic destination choice. An age-restricted source must have an age-restricted target, and the downgrade check must run before reading source content. Cross-guild forwarding must fail unless both guilds independently pass read scope and the separate boundary toggle is enabled.
Bind the strict request, operation-key hash, deterministic nonce, verified identities, Message Content intent, exact source reference, complete validated source-author object and source body, stable attachment metadata, embeds, components, mentions, stickers, both exact endpoint states including age restriction, relevant roles and overwrites, complete effective permissions and unknown bits, boundary decision, empty allowed-mentions policy, nonce enforcement, one-snapshot requirement, and notification suppression into the opaque process-keyed digest. Exclude only expiring attachment delivery URLs from the stable attachment projection. Recursively and aggregately bound every rich JSON projection, preserve hostile property names as ordinary digest-bound data, reject invalid Unicode or non-JSON values, require the exact documented snapshot wrapper, and fail closed on any malformed, oversized, or unexpected evidence.
Send only an exact type-FORWARD message reference with source guild, channel, and message IDs, fail_if_not_exists, the deterministic nonce with enforcement enabled, empty allowed mentions, and SUPPRESS_NOTIFICATIONS. Disable automatic rate-limit retries. Do not add outer content, attachments, embeds, components, stickers, mentions, reply behavior, caller-selected flags, or audit-log reasons. Accept the response only when it is an empty ordinary message authored by the verified bot in the exact target, contains the exact forward reference, exactly one snapshot equal to the reviewed stable source projection, and exactly the required HAS_SNAPSHOT plus SUPPRESS_NOTIFICATIONS flags. Require the same proof from an independent exact target-message read.
Classify only a known pre-response Discord 4xx refusal other than request timeout or rate limiting as failed. Treat request timeout, rate limiting, transport ambiguity, server errors, malformed or mismatched responses, snapshot drift, readback failure, receipt-finalization failure, or any otherwise indeterminate state as uncertain and potentially completed. Preserve a known target message ID in content-free uncertain evidence when available, permanently spend the key, retain the exact source-message and target-channel claims, and never automatically retry, delete the created message, compensate, or roll back. Notification suppression is not a confidentiality boundary and may still produce an unread badge.
Return only the bounded source preview, counts, minimized author and endpoint identity, delivery controls, permission decision, risks, and keyed digest needed for review. Never persist or send to observability source or snapshot content, attachment filenames or metadata, attachment URLs, embeds, components, stickers, mentions, profiles, guild or channel names, permission evidence, raw payloads, raw operation keys, response bodies, or transport causes. Activity may retain only exact source and target guild, channel, and message IDs, the deterministic nonce, plan digest, operation-key hash, timestamp, fixed outcome and verification values, activity ID, and sanitized error category. Keep generic message normalization snapshot-blind: return only a bounded snapshot count and explicit redaction marker, never a forwarded snapshot body.
Canonical source: SECURITY.md
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.