GuildControl MCP server
Safety-first MCP server for Discord with privacy-safe reads, audits, and reviewed administration
1 stars105 downloads/wk
Reviews
Write oneNobody has reviewed GuildControl MCP yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
GuildControl MCP tools (100, 6 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
analyze_community_activityAnalyze a bounded transient metadata sample from exact permitted guild channels. Returns aggregate participation, concentration, explicit-reply latency, reciprocity, UTC timing, and honest pagination coverage without using message content or returning participant identities, names, profiles, or per-message evidence. Nothing is persisted.
audit_application_commandsAudit the verified current Discord application's complete global and guild command inventories plus guild command-permission decisions. Returns strict structural exposure evidence that distinguishes known, inherited, defaulted, and incomplete contexts while omitting raw definitions, option descriptions, choice values, permission bitfields, profiles, and role or channel names. Persists nothing.
audit_application_entitlementsAudit one bounded present-access entitlement page for exactly one configured guild or user beneficiary and one to ten configured current-application SKUs. Discord is always asked to exclude ended and deleted entitlements. Returns exact entitlement and SKU IDs, normalized type, optional validity interval, consumed state, bounded page evidence, and count-only future evidence while omitting guild-ent
audit_application_postureAudit the verified current Discord application's installation, privileged-intent, Interaction delivery, event-webhook, and connector-compatibility posture without returning profiles, text, URLs, raw flags, permission bitfields, or unknown fields.
audit_application_role_connection_metadataAudit the verified current Discord application's complete linked-role metadata schema. Returns bounded transient untrusted labels, exact structural keys, normalized comparison semantics, verification-endpoint presence, and count-only future evidence while omitting URLs, localization values, user metadata, guild role configuration, and raw payloads. Persists nothing and cannot mutate the schema.
audit_application_skusAudit the verified current Discord application's complete bounded SKU catalog. Returns exact IDs, bounded transient untrusted names and slugs, normalized known types, availability and purchase-scope flags, and count-only future evidence while omitting benefits, prices, media, store URLs, entitlement and subscription data, purchaser and beneficiary identifiers, payment data, raw payloads, and unkno
audit_application_subscriptionsAudit one bounded subscription lifecycle page for exactly one configured user and one configured current-application subscription SKU. Returns exact subscription and configured SKU IDs, normalized lifecycle status and period, count-only entitlement links, bounded page evidence, and count-only future evidence while omitting country, payment data, profiles, product text, raw payloads, unconfigured r
audit_bot_installationsVerify pinned application and bot identity, scan the complete bounded current guild membership from an explicit zero cursor, and compare exact installed IDs with configured outer guild scope. Returns missing and unexpected IDs while omitting guild names, icons, permissions, features, member counts, presence counts, and raw payloads; persists nothing and grants no authority outside scope.
audit_channel_orderwrite actionAudit complete obfuscation-safe Discord channel layouts for one exact separately allowlisted guild. Joins a coherent Gateway layout with either complete or visibility-bounded HTTP evidence, returns canonical same-parent sortable families, reveals no hidden channel metadata, proves MANAGE_CHANNELS from guild or visible parent-category authority, and never writes or persists Discord text.
audit_channel_role_accessAudit a bounded page of every guild role's effective access to one permitted Discord channel or thread. Returns compact per-action decisions plus full-inventory totals, deterministic exact-role pagination, member-overwrite warnings, and partial confidence when Discord evidence is incomplete. Private-thread role membership remains unknown unless Manage Threads grants moderator access.
audit_forum_tagsAudit the complete bounded ordered tag inventory of one exact separately allowlisted stable Discord forum. Returns transient tag names, moderation state, privacy-safe emoji metadata, complete VIEW_CHANNEL evidence, and unknown channel and tag fields only as counts. Unknown permission-overwrite fields fail closed. Never scans posts or threads, persists tag text, or accepts media channels.
audit_guild_communityAudit one separately allowlisted guild's Discord Community state with verified identity, exact ownership, complete bounded bot-role authority, continuity-safe channel evidence, exact routing IDs, and @everyone rules visibility and sendability. Returns only Community presence, content-free feature and state digests, minimized permission evidence, fixed warnings, privacy guarantees, and verification
audit_guild_webhooksAudit the complete Discord webhook inventory for one separately allowlisted guild with complete guild-level MANAGE_WEBHOOKS evidence. Returns exact IDs, transient untrusted webhook names, normalized types and application ownership, exposure aggregates, and fixed findings while omitting credentials, execution URLs, avatars, creator profiles and usernames, source objects, guild and channel names, ch
audit_role_orderwrite actionAudit the complete canonical Discord role hierarchy for one exact separately allowlisted guild. Returns stable low-to-high ranks, raw positions, aggregate holder counts without member identities, managed and connector-held boundaries, known and unknown permissions, hierarchy-sensitive permissions, and complete connector MANAGE_ROLES authority evidence without writing or persistence.
catch_up_messagesCatch up across bounded exact Discord guild channels in one privacy-minimized read. Each selection starts from its caller-retained cursor or explicitly initializes from the newest bounded page. All channels, connector membership, Message Content intent, and complete read permissions are verified before message reads; results are chronological compact previews with honest coverage and safe next cur
check_soundboard_playbackCheck whether the verified bot can play one exact default or custom sound in one exact allowlisted ordinary voice channel. Fresh evidence must prove channel type and scope, complete overwrites and roles, VIEW_CHANNEL, CONNECT, SPEAK, USE_SOUNDBOARD, conditional USE_EXTERNAL_SOUNDS, the exact available sound, and the bot's current connection without server mute, server deaf, self-deaf, or suppressi
create_coordination_addresswrite actionCreate one random caller-retained coordination routing label locally without credentials, Discord access, network access, registration, authority, authentication, or connector persistence. Any syntactically valid label is accepted later, and any participant able to send through the same bot can copy or spoof it.
execute_direct_message_changewrite actionexplain_channel_accessExplain the authenticated connector bot's effective permissions for one permitted Discord channel or thread using arbitrary-width bitfields and the official overwrite order. Returns partial confidence instead of claiming access when Discord evidence is incomplete.
explain_principal_permissionsExplain effective Discord permissions for the connector bot, one exact member, or one exact role in a permitted guild. Supports named permission checks, channel actions, and hierarchy actions with exact targets. Applies owner and Administrator bypasses, channel overwrite order, implicit dependencies, timeout restrictions, role hierarchy, thread inheritance, and exact private-thread membership. Par
get_application_emojiGet one exact emoji owned by the verified current Discord application. Returns no image bytes, CDN URL, roles, uploader identity or profile, or unknown raw field and persists nothing. No application ID is accepted from the caller.
get_application_entitlementInspect one exact Discord entitlement only after supplying its expected separately configured guild or user beneficiary and configured current-application SKU. Verifies pinned identity and complete SKU ownership, then returns exact IDs, normalized SKU and entitlement lifecycle state, and count-only future evidence while omitting purchaser identity outside the exact beneficiary, product text, payme
get_automod_ruleGet one exact AutoMod rule from a separately allowlisted Discord guild. Returns the complete projected policy and exact permission and reference evidence transiently for review; action-execution content, matched content, matched keywords, and unknown raw fields are omitted, and nothing is persisted.
get_channelFetch one exact readable non-thread Discord guild channel and return a strict metadata projection with type-applicable text, slowmode, voice settings, parent and position evidence, overwrite count, and unknown fields represented only as a count. Persists nothing and omits raw payloads.
get_channel_webhookGet one exact Discord webhook through the bounded inventory of one separately allowlisted direct guild channel. The result contains no webhook credential, execution URL, avatar, creator profile, source object, unknown raw field, or unrelated channel metadata and is never persisted.
get_connector_statusVerify the configured Discord application and bot identity, count the first guild page, and report effective connector scope plus the durable reviewed-write coordination boundary without reading messages.
get_current_bot_profileRead the authenticated Discord bot's editable global profile through pinned application-and-bot identity evidence. Returns the transient username plus avatar and banner presence and animation state, while projecting raw image hashes, CDN URLs, application text, profile payloads, and all durable content out.
get_direct_messageRead one exact Discord DM message from a caller-known one-to-one channel for one separately configured ordinary user. Re-verifies pinned connector identity, exact channel participants, recipient policy, message boundary, and author identity. Returns plain text or a supported callback-free static Components V2 layout transiently with deterministic preview, untrusted link destinations, presentation
get_gateway_eventsRead a bounded process-local page of in-scope Discord Gateway event kinds and identifiers after an optional opaque cursor. No message content, profile data, emoji, URLs, or raw payloads are retained.
get_gateway_statusRead content-free local health, privacy guarantees, reconnect and continuity-gap counters, and buffer state for the optional Discord Gateway connection without contacting Discord.
get_guild_audit_entryLook up one exact Discord guild audit entry by ID without scanning newer history. The result omits embedded objects plus change and option values, redacts non-snowflake targets, and includes its reason only by explicit opt-in.
get_guild_banFetch one exact privacy-minimized Discord guild ban through a separately gated read. The ban reason is omitted unless explicitly requested, and the result persists nothing.
get_guild_emojiGet one exact Discord guild emoji through the complete bounded inventory of a separately allowlisted guild. Returns no CDN URL, image bytes, uploader profile, or unknown raw field and persists nothing.
get_guild_incident_actionsAudit one separately allowlisted Discord guild's incident-action deadlines with verified connector identity, exact guild ownership, complete bounded bot-role evidence, and an explicit known MANAGE_GUILD authority verdict. Detection timestamps are reduced to booleans, guild presentation and role names are omitted, unknown incident fields are counted, and nothing is persisted.
get_guild_inviteResolve one exact process-local invite reference through a fresh complete, separately gated Discord guild inventory. The result exposes bounded metadata and risk evidence but no invite code, URL, inviter profile, target profile, role name, or raw Discord object, and persists nothing.
get_guild_memberFetch one exact Discord guild member by guild and user snowflake through the separately gated member directory. The privacy-minimized result omits avatars, presence, voice state, boost state, permissions, flags, and raw payloads.
get_guild_onboardingAudit one separately allowlisted guild's complete Discord onboarding state with verified identity, membership, bounded role, continuity-stable channel, overwrite, emoji, and onboarding evidence. Channel metadata is labeled complete or visibility-bounded; any role reference is conservatively unsafe when obfuscated-channel overwrites are unavailable. Prompt, option, description, and Unicode emoji te
get_guild_profileAudit one separately allowlisted Discord guild's name and description with verified identity, complete bounded role and permission evidence, and an explicit change-authority verdict. Media hashes are reduced to presence booleans, role names and raw payloads are omitted, returned profile text is explicitly untrusted and transient, and nothing is persisted.
get_guild_settingsAudit one separately allowlisted guild's bounded named Discord settings with verified identity, complete MANAGE_GUILD evidence, and continuity-safe channel inventory. Returns verification, default notifications, explicit-media filtering, AFK routing and timeout, system routing and named notification suppressions, and premium progress state. Guild and channel names, member data, raw payloads, raw b
get_guild_soundboard_soundGet one exact Discord guild soundboard sound through a fresh complete bounded guild inventory. Returns privacy-safe stable metadata and complete ownership-aware connector permission evidence without audio bytes, CDN URLs, creator profiles, or unknown raw fields and persists nothing.
get_guild_stickerGet one exact Discord guild sticker through the complete bounded inventory of a separately allowlisted guild. Returns no CDN URL, image bytes, uploader profile, or unknown raw field and persists nothing.
get_guild_vanity_urlAudit one separately allowlisted Discord guild's vanity invite eligibility, configured state, usage count, and complete MANAGE_GUILD evidence through Discord's documented read endpoint. The exact code is omitted by default and returned only after explicit includeCode opt-in; full URLs, raw payloads, and unknown-field values are always omitted, and nothing is persisted.
get_guild_welcome_screenAudit one separately allowlisted guild's complete Discord Welcome Screen state with verified identity, bounded role, channel, overwrite, emoji, and permission evidence. Descriptions and Unicode emoji text are omitted by default and returned transiently only after explicit includeText opt-in. Unknown future fields are counted without values, nothing is persisted, and disabled screens without MANAGE
get_guild_widget_settingsAudit one separately allowlisted guild's authenticated Discord widget settings with verified identity, complete MANAGE_GUILD evidence, bounded channel and overwrite evidence, exact @everyone visibility and invite-generation capability, an explicit public-exposure projection, and optional guild-object cross-checking. Channel names, invite codes and URLs, member and presence data, raw payloads, and
get_member_voice_stateFetch one exact member's minimized Discord voice state through separate exact guild and channel scope. Returns verified application, bot, guild, and target identity, bounded untrusted display names, connection state, exact scoped channel identity, server mute and deafen state, complete VIEW_CHANNEL plus CONNECT evidence, and an unknown-field count. Session IDs, embedded members, self-state, stream
get_messageRead one exact Discord message from a permitted guild channel. Preserves structured fields and adds untrusted readable message, Text Display, and embed text with explicit notes for unsupported components. The complete result must fit the configured response budget; media is not downloaded.
get_observability_statusRead process-local aggregate MCP tool and Discord REST health, bounded connector-observed pressure toward Discord's IP-wide invalid-request limit, OTLP exporter health, and explicit telemetry privacy guarantees without contacting Discord.
get_pollRead one exact Discord poll from a separately allowlisted channel. Returns bounded question, answer, expiry, lifecycle, and aggregate result evidence transiently without fetching voter identities or persisting Discord content. Answer IDs are preserved exactly and need not be sequential; absent results remain explicitly unknown.
get_roleFetch one exact Discord role by guild and role snowflake through Discord's exact role endpoint, then validate and normalize its colors, hierarchy fields, permissions, and managed-role classification.
get_scheduled_eventGet one exact scheduled event from a separately allowlisted Discord guild with complete entity-specific read-permission evidence. The aggregate subscriber count is opt-in; subscriber identities, creator profiles, cover URLs and hashes, and unknown raw fields are omitted. Nothing is persisted.
get_stage_instanceInspect the active or inactive Stage-instance state for one exact separately allowlisted Discord Stage channel. Returns bounded projected metadata and complete read-permission evidence without speaker, audience, or raw payload data. Nothing is persisted.
get_thread_membershipFetch one exact privacy-minimized Discord thread-membership state for a separately allowlisted user. Uses only exact guild-member and thread-member endpoints with embedded member hydration disabled, evaluates target parent access, enumerates no members, returns no messages or raw payloads, and persists nothing.
get_thread_stateFetch one exact privacy-minimized Discord thread lifecycle state through separate exact guild and thread scope. Returns pinned identity, exact guild, parent, thread and connector-membership evidence, inherited parent permission evaluation, bounded unknown-field counts, and explicit omissions without enumerating members, returning messages, exposing raw payloads, or persisting Discord content.
get_voice_channel_statusFetch the transient status of one exact separately allowlisted ordinary Discord voice channel through a fresh Gateway channel-info request. Verifies pinned identity, channel type and guild, complete permission evidence, and the bot's target/other/disconnected connection class. Discards every non-target channel entry before projection and never persists status text or raw payloads.
inspect_application_activity_instanceVerify one opaque Discord Activity instance for the pinned current application and one exact expected guild channel. Scope is checked before the instance read. Returns active state, launch ID, participant count, and optional exact-user membership only after the response location matches; participant enumeration, private-channel locations, profiles, raw payloads, and unknown values are omitted and
list_active_threadsList a bounded set of active Discord threads visible inside one permitted guild. Optionally restrict to an exact permitted parent channel; forum and media posts are returned as public threads with applied tag IDs.
list_application_emojisList the complete bounded emoji inventory owned by the verified current Discord application. Returns stable metadata while projecting out image bytes, CDN URLs, roles, uploader identities and profiles, and unknown raw fields. Nothing is persisted and no application ID is accepted from the caller.
list_archived_threadsList one bounded page of archived Discord threads beneath a permitted parent channel. Public includes archived forum posts, private additionally requires Manage Threads, and joined-private is the least-privilege private view. Public/private cursors are timestamps; joined-private cursors are thread IDs.
list_automod_rulesList the complete bounded AutoMod rule inventory for one separately allowlisted Discord guild. Returns names, trigger and action types, policy-entry counts, exact reference health, complete connector permission evidence, and privacy omissions without exposing policy strings or persisting Discord data.
list_channel_permission_overwritesList one deterministic bounded page of role and member permission overwrites for an exact readable Discord channel. Threads report their inherited parent overwrite source. Known permissions are named while arbitrary-width unknown bits remain explicit decimal evidence. Results are never persisted.
list_channel_webhooksList the complete Discord webhook inventory for one separately allowlisted direct guild channel. Webhook credentials, execution URLs, avatars, creator profiles, source objects, unknown raw fields, and unrelated channel metadata are projected out before the result is built. Complete VIEW_CHANNEL and MANAGE_WEBHOOKS evidence is required, and nothing is persisted.
list_channelsList one bounded page of channels visible through configured policy and Discord's HTTP visibility for one permitted guild without reading message content. The first page defaults to a compact directory projection; use nextCursor for the same fresh ordered inventory and get_channel for exact metadata. The result explicitly remains visibility-bounded and never claims hidden-channel completeness.
list_coordination_addressesObserve sender routing labels from connector-bot-authored canonical coordination notes in one exact readable Discord channel by scanning one bounded page once. Returns page-local counts and timestamps without note bodies, tags, recipients, notification targets, profiles, or reaction users. Observation does not authenticate, register, reserve, or prove liveness for any label, and nothing is persist
list_coordination_notesRead canonical connector-bot-authored coordination notes directed to one caller-retained routing label from one exact readable Discord channel by scanning one bounded page once. Optionally includes broadcasts and exact sender, tag, or unresolved-convention filters. Returns only matching note bodies with fixed reaction aggregates and honest cursor coverage; routing labels, content, and reaction con
list_default_soundboard_soundsList the complete bounded Discord default soundboard inventory after strict privacy projection. Audio bytes, CDN URLs, creator profiles, and unknown raw fields are omitted, and nothing is persisted.
list_direct_messagesRead one bounded page from an exact caller-known one-to-one Discord DM channel for one separately configured ordinary user. Re-verifies pinned connector identity, exact channel participants, and recipient policy on every call. Returns plain text or supported callback-free static Components V2 layouts transiently with exact IDs, deterministic previews, untrusted link destinations, presentation clas
list_discord_interaction_continuationsRead bounded content-free process-local native Interaction continuation capabilities. Returns rotating opaque references, source kind, exact verified identities, request-button source metadata when applicable, expiry, and fixed remaining allowance without request text, button labels, custom IDs, routes, response text, profiles, raw payloads, or Discord Interaction tokens.
list_guild_audit_entriesList a bounded newest-to-oldest page of privacy-minimized Discord guild audit entries with exact actor, action, and before-entry filters. Embedded objects, change and option values, and non-snowflake targets are omitted; reasons require explicit opt-in.
list_guild_bansList one bounded ascending page of privacy-minimized bans from a separately gated Discord guild. Ban reasons require explicit opt-in, and nextAfterUserId is returned only when a private lookahead proves another page exists.
list_guild_emojisList the complete bounded emoji inventory for one separately allowlisted Discord guild. Returns stable metadata and complete connector permission evidence while projecting out CDN URLs, image bytes, uploader profiles, and unknown raw fields. Nothing is persisted.
list_guild_integrationsList the bounded privacy-safe Discord integration inventory for one separately allowlisted guild. External account identities, integration and application names, descriptions, icons, user profiles, raw payloads, and unknown scope values are projected out. Complete MANAGE_GUILD evidence is required, a …-item response is marked ambiguous, and nothing is persisted.
list_guild_invitesList one bounded local page of a separately gated Discord guild invite inventory. Every invite code and URL is replaced with a process-local HMAC reference before the MCP result is built. Each continuation cursor is authenticated and bound to the complete fresh inventory, complete MANAGE_GUILD evidence is required, and nothing is persisted.
list_guild_membersList one bounded ascending page of privacy-minimized members from a separately gated Discord guild. Continue only with the returned nextAfterUserId cursor; a full page does not prove that another page exists.
list_guild_soundboard_soundsList the complete bounded soundboard inventory for one separately allowlisted Discord guild. Returns privacy-safe stable metadata and complete ownership-aware connector permission evidence while omitting audio bytes, CDN URLs, creator profiles, and unknown raw fields. Nothing is persisted.
list_guild_stickersList the complete bounded sticker inventory for one separately allowlisted Discord guild. Returns stable metadata and complete connector permission evidence while projecting out CDN URLs, image bytes, uploader profiles, and unknown raw fields. Nothing is persisted.
list_guild_templatesAudit one complete bounded Guild Template inventory for a separately allowlisted source guild. Continuity-stable Gateway and HTTP evidence labels the live channel structure as complete or visibility-bounded. Every raw code and use URL is replaced before result construction with an opaque process-local HMAC reference. Names, descriptions, creator profiles, role and channel names, topics, icon hashe
list_guild_voice_regionsList the complete bounded voice-region inventory available to one exact permitted Discord guild, including guild-specific and VIP choices. Returns strict deterministic ID, transient name, optimal, deprecated, custom, and unknown-field-count projections without persistence or raw payloads.
list_guildsList a bounded page of Discord guilds visible to the bot and permitted by connector scope.
list_message_pinsList one bounded page of pinned messages from a permitted Discord channel using the current timestamp-paginated pin endpoint. Returns message content without persisting it and exposes the next pinned-at cursor when more results exist.
list_message_reactionsList the strict aggregate reaction snapshot for one exact message in a readable Discord channel. Returns normal and burst counts plus the verified bot's own state without user identities, message content, author data, burst colors, profiles, raw payloads, or persistence.
list_message_repliesInspect direct replies to one exact Discord message by scanning one bounded page after a caller-held exact cursor. Returns a privacy-minimized source and only strict same-channel replies in ascending order plus honest scan coverage and the next cursor; non-replies advance coverage but are omitted, profile and rich payload fields are withheld, and nothing is persisted.
list_pending_discord_interactionsRead the bounded process-local queue of private Discord native Interaction requests from the managed slash command or authenticated request Buttons. Slash-command text and request-button labels are transient untrusted data. Button entries identify only the exact source message, bounded index, and style; custom IDs, routes, tokens, profiles, component trees, and raw payloads are never exposed or pe
list_poll_answer_votersList one bounded ordered page of voter user IDs for one exact answer in a separately allowlisted Discord poll. Requires the additional voter-audit toggle, verifies that the answer exists, returns no usernames or profile fields, and persists nothing.
list_reaction_usersList one bounded ordered page of user IDs and bot flags for one exact normal or burst reaction. Requires the separate user-audit toggle and exact reaction-channel allowlist; usernames, profile fields, burst colors, message content, raw payloads, and persistence are excluded.
list_rolesList the complete Discord role inventory for one permitted guild, bounded by Discord's documented role limit and normalized with current colors, hierarchy fields, known permission names, unknown permission bits, and managed-role classification.
list_scheduled_event_usersList one bounded ascending page of subscriber user IDs and bot flags for one exact scheduled event. Requires the additional user-audit toggle, verifies complete entity-specific read permissions before fetching identities, explicitly disables member expansion, omits all profile fields and raw payloads, and persists nothing.
list_scheduled_eventsList the complete bounded scheduled-event inventory for one separately allowlisted Discord guild. Returns privacy-safe event metadata and complete entity-specific read-permission evidence. Aggregate subscriber counts are opt-in; subscriber identities, creator profiles, cover URLs and hashes, and unknown raw fields are omitted. Nothing is persisted.
list_stage_instancesInspect every separately allowlisted Discord Stage channel as a bounded configured inventory. Returns exact active or inactive state, guild-only or deprecated-public privacy, scheduled-event linkage, schema-drift count, and complete read-permission evidence without speaker, audience, or raw payload data. Nothing is persisted.
list_voice_regionsList the complete bounded global Discord voice-region inventory usable for voice and Stage channel RTC selection. Returns strict deterministic ID, transient name, optimal, deprecated, custom, and unknown-field-count projections without persistence or raw payloads.
parse_discord_referenceParse one complete canonical discord.com channel or message jump link, or an official typed user, channel, role, application-command, or custom-emoji mention, into exact typed IDs. This local tool contacts no network, omits embedded names and input text, persists nothing, and reports only bounded local read-policy eligibility rather than Discord access or downstream authorization.
plan_direct_message_changeplay_soundboard_soundPlay one exact default or allowlisted custom sound in one exact allowlisted ordinary voice channel after fresh readiness proof and host write approval. Uses a one-shot request-bound operation key, durable exact-channel cross-process coordination, shared anti-spam limits, pending content-free audit, one non-retried Discord request, and optional exact Gateway event corroboration. A strict 204 respon
read_message_attachmentRead one exact attachment from one exact message in a permitted guild channel or thread as a native MCP image or audio block, with an embedded octet-stream fallback and an equivalent private resource link. The connector refetches current Discord evidence, validates the signed CDN route, refuses redirects and credentials, enforces the configured MCP response budget while streaming, verifies support
read_messagesRead one bounded Discord message page from a permitted guild channel, newest to oldest according to Discord. Preserves structured fields and adds untrusted readable message, Text Display, and embed text with explicit notes for unsupported components. The complete result must fit the configured response budget; media is not downloaded.
recall_conversationRecall a vaguely remembered Discord conversation in one permitted guild. Searches one to five caller-supplied literal phrase variants through Discord's official relevance endpoint, fuses duplicate candidates, ranks phrase coverage and reciprocal rank, then refetches bounded current context around each target. Phrase text, names, profiles, raw payloads, and Discord content are never persisted. Requ
respond_to_discord_interactionConsume one opaque pending slash-command or request-button Interaction reference and send one bounded ephemeral plain-text response. The Interaction token remains private, mentions and rich content are disabled, pending activity is recorded first, and the non-retried response is consumed even after uncertainty. Response evidence must match the exact source kind and, for a request Button, Discord's
search_guild_memberswrite actionRun one bounded Discord username-or-nickname prefix search inside a separately gated guild. Results are privacy-minimized, are not fuzzy or exhaustive, and must not be treated as write targets without exact-ID review.
search_messagesSearch indexed Discord message history in one permitted guild using the official bot search endpoint. Requires Message Content intent and Read Message History. Every request has at least one substantive filter, returns at most 25 compact messages, honors exact local channel search scope, and reports Discord indexing state without automatic retries.
send_discord_interaction_followupwrite actionConsume one rotating process-local continuation reference and send one bounded ephemeral plain-text native Interaction follow-up. The Discord token never crosses MCP, mentions and rich content are disabled, pending content-free activity precedes one non-retried write, exact response plus independent readback are required, and any post-dispatch ambiguity consumes the reference. Set keepOpen only to
verify_direct_message_changeVerify one exact caller-retained private-message change request against its token-keyed schema-v2 content-free operation receipt and receipt-bound exact Discord message or absence. Receipt and request matching plus current exact link-origin policy enforcement happen before Discord or local-file access. Returns only lifecycle status, exact IDs, hashes, timestamps, and fresh match state; attachment
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
- Code scan425 source files scanned20/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 2 days ago15/15
- Maintainer identitynamespace and repository owner differ; GitHub account older than a year; website matches verified namespace7/10
Findings (1)
- mediumeval / new Function used
exec.evaldist/catalog.js: …ML", "document.write", "eval(", "Function(", "fetch("…
Install directly
Runs npx -y guildctl on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add discord -- npx -y guildctl
GuildControl MCP: common questions
- Is GuildControl MCP server safe?
- Mostly: it is graded B (74/100). Read the GuildControl MCP safety report
- How do I install GuildControl MCP?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does GuildControl MCP need an API key?
- Yes. The registry entry asks for
DISCORD_BOT_TOKEN. - Is GuildControl MCP maintained?
- The last commit was 4 days ago (2026-09-17). The latest release is v2.3.0.