Thread creation
Do not add a general thread-creation shortcut that bypasses the capability gate, exact parent-channel allowlist, pinned bot identity, strict mode-specific request, exact parent and optional source IDs, complete guild-role and parent-overwrite evidence, process-keyed planning, signed interactive confirmation, write-aware client approval, final fresh-plan match, shared interaction limiter, atomic one-shot operation-key reservation, pending activity journaling, single POST, or exact readback. If a client cannot support MCP elicitation, keep thread-creation execution unavailable in that client.
Keep the surface to message-anchored creation in text or announcement parents and explicit standalone public or private creation in text parents. Reject forum and media parents, starter messages, files, tags, notifications, lifecycle or membership changes, edits, deletion, retries, rollback, and reconciliation. Require VIEW_CHANNEL and the exact mode's CREATE_PUBLIC_THREADS or CREATE_PRIVATE_THREADS; anchored creation additionally requires READ_MESSAGE_HISTORY and an exact fresh source-message snapshot.
Bind the exact application and bot identity, guild, parent, source snapshot, existing anchored thread, member roles, complete role and overwrite inventories, effective permissions, resolved defaults, desired settings, audit reason, and domain-separated operation-key hash into the plan. Exclude the raw key from plan material and signed request state. The reviewed plan may transiently contain untrusted names, source content, profiles, and attachment metadata, but none may enter activity records or operation receipts.
Treat an existing valid thread at the deterministic source-message ID as a no-op without confirmation, key reservation, activity, or mutation. For a real write, reserve and journal before the one non-retried POST. Require an exact bot-owned, active, unlocked response and fresh readback. Report only fixed drift fields when Discord adjusts safe settings.
After an ambiguous anchored write, recover only through the deterministic source-message ID and only when every expected identity and setting matches. Never infer standalone success from a logical name or channel listing. Permanently block the same normalized standalone target inside the direct service instance after uncertainty. The production facade also acquires a durable exact parent-channel claim, so connector processes sharing the activity-state root exclude overlapping thread creation and retain the claim after uncertainty. Never compensate by editing or deleting a possibly created thread.
Canonical source: SECURITY.md
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.