Migration planning
Keep migration planning release-exact, offline, non-mutating, and separate from runtime policy. Accept only a canonical versioned source identity from the shipped manifest catalog. Never accept or read a source checkout, source configuration, MCP host configuration, active connector policy, environment value, credential file, token, Discord content, activity state, coordination record, arbitrary URL, or nearest-version alias. Do not start a process, contact a network or Discord endpoint, open a Gateway, export telemetry, create an activity record, or change the source, target, policy, host, or Discord installation while producing a plan.
Account for every public tool in the audited source inventory exactly once. Preserve whether the evidence came from a public version tag or only version-matching public source, require one commit-pinned GitHub tree URL plus the exact versioned Registry identity, and bind the canonical inventory to its audited SHA-256 digest. Each outcome must state a closed supported, review-required, or intentionally excluded disposition, exact target tools, applicable additive recipes, a fixed operator instruction, and a fixed trust-model change. Intentionally excluded outcomes must claim no target route. Never claim argument compatibility, configuration compatibility, permission readiness, or semantic equivalence merely because names resemble one another.
Validate every mapped target tool against the credential-free production catalog and every preset and recipe against its canonical local catalog. Bind the normalized source manifest, migration catalog, negotiated target contract, mappings, staged commands, limitations, and non-execution disclosures into deterministic digests. Reject a stale target route rather than emitting partial guidance. Migration output may contain only public release identities, public HTTPS evidence links, public tool and route names, fixed placeholders, digests, counts, dispositions, and durable explanatory text. It must contain no real Discord ID, local source path, secret value, display name, message content, profile, or host-specific state.
Write optional migration HTML only through exclusive mode-0600 creation without replacement. Require a fresh valid plan digest before rendering, escape every embedded value, allow no automatic network request or external asset, persist no browser state, and remove a partial file after failure. Evidence links may navigate only after explicit user activation and must use HTTPS with no referrer. The page has no import, approval, configuration-write, host-write, process-launch, or Discord authority. A migration plan never restores legacy environment-policy compatibility or becomes an alternate runtime policy source.
Canonical source: SECURITY.md
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.