Atlas / MCP servers / cappyeo / Discord

DiscordBLOCK

mcp/cappyeo/discord-36

Open-source Discord MCP server for Claude, Codex, Cursor and other AI clients: 209 typed tools, caller-owned bots, safety controls and verifiable guild builds.

Verdict
BLOCK
Grade
F
Trust score
57 /100
Exposed tools
45 36r · 9w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
122
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Discord MCP

An open-source Model Context Protocol (MCP) server for Discord. Connect Claude, Codex, Cursor, and other MCP-compatible AI clients to your own Discord bot. Manage messages, channels, roles, moderation, and server setup through 221 typed tools.

[](https://github.com/cappyeo/discord-mcp/actions/workflows/ci.yml) [](https://www.npmjs.com/package/@discord-mcp/cli) [](https://www.npmjs.com/package/@discord-mcp/cli) [](LICENSE)

Read from source at commit ba79b17268c8OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add cli --env DISCORD_TOKEN=${DISCORD_TOKEN} -- npx -y @discord-mcp/[email protected]
03

Exposed tools (45)

36 read · 9 write · 0 destructive.

ToolRiskDescription
BadNameread
LevelreadXP level
WaveHelloreada friendly wave
WaveHiread
areada
argreadarg
breadb
channels_editwriteEdit one channel.
channels_getreadRead one channel.
channels_listreadList channels.
create_text_channelwriteCreate a new text channel
discord_audit_alertreadPaSympa-specific audit alert (no discord-mcp equivalent)
discord_create_channelwriteCreate a new channel in a guild
discord_edit_messagewriteEdit a previously sent message
discord_list_channelsreadList all channels in a guild
discord_read_messagesreadRead recent messages from a channel
discord_send_messagewriteSend a message to a Discord channel
edit_messagewriteEdit a previously sent message.
get_bot_inforeadGet the running bot user info (gateway only)
get_messagesreadFetch recent messages from a Discord channel.
greetreadsay hi
group1readgroup
guide.txtreadGuide attachment
guildpingreadguild ping
health_checkreadReport runtime health (no discord-mcp equivalent - gateway client).
helpreadShow help
invalid_outputreadExercise the output contract guard
list_channelsreadList all channels in a guild (synthetic fixture).
list_projectsreadList configured projects (no discord-mcp equivalent).
list_templatesreadList server templates
messages_litereadProfile-variant: lite messaging (synthetic fixture).
meta_defaultsreadd
meta_introspectreadIntrospect me
pingreadPing the bot
pongreadpong
poster.pngreadPoster
probereadA credential-free stdio protocol probe (factory ${factoryCalls}).
rules.txtreadExisting rules
send_messagewriteSend a message to a Discord channel (synthetic fixture).
set_bot_statuswriteSet the bot presence (gateway only, no REST equivalent)
set_slowmodewriteSet rate-limit-per-user on a channel.
sub1readsub
test_echoreadEcho back input
with_metareadmeta
xready
04

Trust audit

BLOCKgrade F · trust 57/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (2 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
packages/mcp-core/src/middleware/payload-confirmation.ts
payload-confirmation.ts
Why it matters. member named after an attack tool
Fix. remove or justify
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
packages/mcp-server/scripts/benchmark/claude-code-driver.test.mjs:29
const API_KEY = 'sk-ant-test-key-that-must-never-be-written-to-disk';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mcp-core/src/gateway/client.test.ts:75
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mcp-core/src/gateway/client.test.ts:88
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mcp-core/src/gateway/client.test.ts:109
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mcp-core/src/gateway/client.test.ts:127
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mcp-core/src/gateway/client.test.ts:145
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/mcp-core/src/middleware/payload-confirmation.composer.test.ts
payload-confirmation.composer.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/mcp-core/src/middleware/payload-confirmation.file-ledger.test.ts
payload-confirmation.file-ledger.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/mcp-core/src/middleware/payload-confirmation.test.ts
payload-confirmation.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/mcp-core/src/server.payload-approval.integration.test.ts
server.payload-approval.integration.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
packages/mcp-server/src/lib/client-snippets/claude-desktop.test.ts:6
serverPath: '/usr/local/bin/node',
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
packages/mcp-server/src/lib/client-snippets/claude-desktop.test.ts:46
expect(parsed.mcpServers['discord-mcp'].command).toBe('/usr/local/bin/node');
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
packages/mcp-server/src/lib/client-snippets/cursor.test.ts:6
serverPath: '/usr/local/bin/discord-mcp',
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
packages/mcp-server/src/lib/client-snippets/cursor.test.ts:44
expect(parsed.mcpServers['discord-mcp'].command).toBe('/usr/local/bin/discord-mcp');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-core/src/resources/built-artifact.test.ts:27
const DIST = fileURLToPath(new URL('../../dist/index.js', import.meta.url));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-core/src/telemetry/conventions.ts:12
import packageJson from '../../package.json' with { type: 'json' };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-core/src/tools/_lib/defineTool.ts:2
import type { DiscordAccessRequirement } from '../../access/requirements.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-core/src/tools/_lib/defineTool.ts:8
} from '../../pieces/Tool.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-core/src/tools/_lib/forum-tags.ts:3
import { ValidationError } from '../../errors/client.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/scripts/assert-packaged-cli.mjs:647
OTEL_EXPORTER_OTLP_ENDPOINT: `http://127.0.0.1:${otelPort}`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/scripts/assert-packaged-cli.mjs:676
const httpEndpoint = new URL(`http://127.0.0.1:${httpPort}/mcp`);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mcp-core/src/rest/resilience-429.integration.test.ts:81
baseUrl = `http://127.0.0.1:${addr.port}`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mcp-core/src/rest/resilience-circuit.integration.test.ts:79
baseUrl = `http://127.0.0.1:${addr.port}`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mcp-core/src/rest/resilience-retry.integration.test.ts:80
baseUrl = `http://127.0.0.1:${addr.port}`;

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ba79b17268c8full audit observations/trust-audit/mcp-server/cappyeo__discord-36.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ba79b17268c8BLOCKF57first audit
06

Questions

What is the Discord MCP server?

Open-source Discord MCP server for Claude, Codex, Cursor and other AI clients: 209 typed tools, caller-owned bots, safety controls and verifiable guild builds.

What tools does Discord expose?

45 in total: 36 read-only, 9 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Discord safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (57/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Discord need?

It reads ANTHROPIC_API_KEY, DISCORD_MCP_ACCESS_TOKEN, DISCORD_TOKEN, GITHUB_TOKEN and MCP_APPROVAL_HMAC_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Discord run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as site at 0.31.1.

How current is this page?

The grade is for one exact copy of the source (ba79b17268c8), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement