Atlas / MCP servers / barryyip0625 / Discord Integration

Discord IntegrationCAUTION

mcp/barryyip0625/discord-integration

Implement Discord MCP server enabling AI assistants to interact with the Discord platform.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
46 16r · 21w · 9d
Transport
stdio · streamable-http
License
MIT
Stars
106
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mcptoplist.com/server/smithery%2Fbarryyip0625%2Fmcp-discord) [](https://hub.docker.com/r/barryy625/mcp-discord)

A Discord MCP (Model Context Protocol) server that enables AI assistants to interact with the Discord platform.

Overview

MCP-Discord provides the following Discord-related functionalities:

  • Login to Discord bot
  • List servers the bot is a member of
  • Get server information
  • List members and inspect member details
  • List, create, edit, delete, assign, and remove roles
  • Search messages in a server
  • Read, edit, and delete channel messages
  • Send messages to specified channels
  • Retrieve forum channel lists
  • Create, update, delete, and reply to forum posts
  • List forum threads and manage forum tags
  • Create, edit, and delete text, forum, voice channels, and categories
  • Set and remove channel permission overrides
  • Add/remove message reactions
  • Create/edit/delete/use webhooks

Table of Contents

  • Prerequisites
  • Installation
  • Configuration
  • Tools Documentation
  • Basic Functions
  • Channel Management
  • Forum Functions
  • Messages and Reactions
  • Webhook Management
  • Role Management
  • Member Management
  • Development
  • License

Prerequisites

  • Node.js (v18.0.0 or higher)
  • npm (v7.0.0 or higher)
  • A Discord bot with
Read from source at commit 0c80f6a9a2cfOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-discord --env DISCORD_TOKEN=${DISCORD_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-discord": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DISCORD_TOKEN": "${DISCORD_TOKEN}"
      }
    }
  }
}
03

Exposed tools (46)

16 read · 21 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
discord_add_multiple_reactionswriteAdds multiple emoji reactions to a Discord message at once
discord_add_reactionwriteAdds an emoji reaction to a specific Discord message
discord_assign_rolereadAssigns a role to a member in a Discord server
discord_create_categorywriteCreates a new category in a Discord server.
discord_create_forum_channelwriteCreates a new forum channel in a Discord server, optionally under a category
discord_create_forum_postwriteCreates a new post in a Discord forum channel with optional tags
discord_create_rolewriteCreates a new role in a Discord server
discord_create_text_channelwriteCreates a new text channel in a Discord server with an optional topic and parent category
discord_create_voice_channelwriteCreates a new voice channel in a Discord server with an optional parent category
discord_create_webhookwriteCreates a new webhook for a Discord channel
discord_delete_categorydestructiveDeletes a Discord category by ID.
discord_delete_channeldestructiveDeletes a Discord channel with an optional reason
discord_delete_forum_postdestructiveDeletes a forum post or thread with an optional reason
discord_delete_messagedestructiveDeletes a specific message from a Discord text channel
discord_delete_roledestructiveDeletes a role from a Discord server
discord_delete_webhookdestructiveDeletes an existing webhook for a Discord channel
discord_edit_categorywriteEdits an existing Discord category (name and position).
discord_edit_channelwriteEdits a Discord channel
discord_edit_messagewriteEdits a message previously sent by the bot. Only messages authored by the bot can be edited.
discord_edit_rolewriteEdits an existing role in a Discord server
discord_edit_webhookwriteEdits an existing webhook for a Discord channel
discord_get_forum_channelsreadLists all forum channels in a specified Discord server (guild)
discord_get_forum_postwriteRetrieves details about a forum post including its messages
discord_get_forum_tagsreadGets all available tags for a Discord forum channel, including tag IDs, names, and emoji
discord_get_memberreadGets detailed information about a specific member in a Discord server
discord_get_reaction_usersreadLists the users who reacted with a specific emoji to a Discord message. Uses REST fetch and does not require Gateway intents. Returns up to 100 users per call.
discord_get_server_inforeadRetrieves detailed information about a Discord server including channels and member count
discord_list_forum_threadsreadLists all threads (posts) in a Discord forum channel, including both active and archived threads
discord_list_membersreadLists members in a Discord server with their roles
discord_list_pinned_messagesreadLists the pinned messages of a channel, newest pin first.
discord_list_rolesreadLists all roles in a Discord server with their properties
discord_list_serversreadLists all Discord servers the bot is a member of
discord_loginreadLogs in to Discord using the configured token
discord_pin_messagereadPins a message to its channel. A channel can hold at most 50 pinned messages.
discord_read_messagesreadRetrieves messages from a Discord text channel. Supports date-based filtering via before/after/around params (accepts snowflake IDs or ISO 8601 dates).
discord_remove_channel_permissionsdestructiveRemoves all permission overrides for a role or user on a channel or category
discord_remove_reactiondestructiveRemoves a specific emoji reaction from a Discord message
discord_remove_roledestructiveRemoves a role from a member in a Discord server
discord_reply_to_forumwriteAdds a reply to an existing forum post or thread
discord_search_messagesreadSearches for messages in a Discord server
discord_sendwriteSends a message to a specified Discord text channel. Optionally reply to another message by providing its message ID.
discord_send_webhook_messagewriteSends a message to a Discord channel using a webhook
discord_set_channel_permissionswriteSets permission overrides for a role or user on a channel or category
discord_set_forum_tagswriteSets the available tags for a Discord forum channel. Replaces all existing tags.
discord_unpin_messagereadRemoves a message from its channel
discord_update_forum_postwriteUpdates a forum post
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (4)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tools/login.test.ts:92
const args = { token: 'test-token-from-args' };
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
discord_delete_category, discord_delete_channel, discord_delete_forum_post, discord_delete_message, discord_delete_role, discord_delete_webhook, discord_remove_channel_permissions, discord_remove_reac
Why it matters. 9 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, discord.js, dotenv, express, zod, @types/express, @types/jest, @types/node
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:76
- **Administrator (full access):**

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 0c80f6a9a2cffull audit observations/trust-audit/mcp-server/barryyip0625__discord-integration.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070c80f6a9a2cfCAUTIONB89first audit
06

Questions

What is the Discord Integration MCP server?

Implement Discord MCP server enabling AI assistants to interact with the Discord platform.

What tools does Discord Integration expose?

46 in total: 16 read-only, 21 that write, and 9 that can delete or overwrite (discord_delete_category, discord_delete_channel, discord_delete_forum_post, discord_delete_message, discord_delete_role). Every one is listed on this page with its risk.

Is Discord Integration safe to connect to an agent?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Discord Integration need?

It reads DISCORD_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Discord Integration run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-discord at 1.5.1.

How current is this page?

The grade is for one exact copy of the source (0c80f6a9a2cf), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement