DiscordBLOCK
Open-source Discord MCP server for Claude, Codex, Cursor and other AI clients: 209 typed tools, caller-owned bots, safety controls and verifiable guild builds.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Discord MCP
An open-source Model Context Protocol (MCP) server for Discord. Connect Claude, Codex, Cursor, and other MCP-compatible AI clients to your own Discord bot. Manage messages, channels, roles, moderation, and server setup through 221 typed tools.
[](https://github.com/cappyeo/discord-mcp/actions/workflows/ci.yml) [](https://www.npmjs.com/package/@discord-mcp/cli) [](https://www.npmjs.com/package/@discord-mcp/cli) [](LICENSE)
ba79b17268c8OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cli --env DISCORD_TOKEN=${DISCORD_TOKEN} -- npx -y @discord-mcp/[email protected]Exposed tools (45)
36 read · 9 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
BadName | read | |
Level | read | XP level |
WaveHello | read | a friendly wave |
WaveHi | read | |
a | read | a |
arg | read | arg |
b | read | b |
channels_edit | write | Edit one channel. |
channels_get | read | Read one channel. |
channels_list | read | List channels. |
create_text_channel | write | Create a new text channel |
discord_audit_alert | read | PaSympa-specific audit alert (no discord-mcp equivalent) |
discord_create_channel | write | Create a new channel in a guild |
discord_edit_message | write | Edit a previously sent message |
discord_list_channels | read | List all channels in a guild |
discord_read_messages | read | Read recent messages from a channel |
discord_send_message | write | Send a message to a Discord channel |
edit_message | write | Edit a previously sent message. |
get_bot_info | read | Get the running bot user info (gateway only) |
get_messages | read | Fetch recent messages from a Discord channel. |
greet | read | say hi |
group1 | read | group |
guide.txt | read | Guide attachment |
guildping | read | guild ping |
health_check | read | Report runtime health (no discord-mcp equivalent - gateway client). |
help | read | Show help |
invalid_output | read | Exercise the output contract guard |
list_channels | read | List all channels in a guild (synthetic fixture). |
list_projects | read | List configured projects (no discord-mcp equivalent). |
list_templates | read | List server templates |
messages_lite | read | Profile-variant: lite messaging (synthetic fixture). |
meta_defaults | read | d |
meta_introspect | read | Introspect me |
ping | read | Ping the bot |
pong | read | pong |
poster.png | read | Poster |
probe | read | A credential-free stdio protocol probe (factory ${factoryCalls}). |
rules.txt | read | Existing rules |
send_message | write | Send a message to a Discord channel (synthetic fixture). |
set_bot_status | write | Set the bot presence (gateway only, no REST equivalent) |
set_slowmode | write | Set rate-limit-per-user on a channel. |
sub1 | read | sub |
test_echo | read | Echo back input |
with_meta | read | meta |
x | read | y |
Trust audit
BLOCKgrade F · trust 57/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
payload-confirmation.ts
const API_KEY = 'sk-ant-test-key-that-must-never-be-written-to-disk';
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
token: 'fake-token-aaaaaaaaaaaaaaaaaaaaaaaaaaaaa',
payload-confirmation.composer.test.ts
payload-confirmation.file-ledger.test.ts
payload-confirmation.test.ts
server.payload-approval.integration.test.ts
serverPath: '/usr/local/bin/node',
expect(parsed.mcpServers['discord-mcp'].command).toBe('/usr/local/bin/node');serverPath: '/usr/local/bin/discord-mcp',
expect(parsed.mcpServers['discord-mcp'].command).toBe('/usr/local/bin/discord-mcp');const DIST = fileURLToPath(new URL('../../dist/index.js', import.meta.url));import packageJson from '../../package.json' with { type: 'json' };import type { DiscordAccessRequirement } from '../../access/requirements.js';} from '../../pieces/Tool.js';
import { ValidationError } from '../../errors/client.js';OTEL_EXPORTER_OTLP_ENDPOINT: `http://127.0.0.1:${otelPort}`,const httpEndpoint = new URL(`http://127.0.0.1:${httpPort}/mcp`);baseUrl = `http://127.0.0.1:${addr.port}`;baseUrl = `http://127.0.0.1:${addr.port}`;baseUrl = `http://127.0.0.1:${addr.port}`;Gates applied: no_behavioural_pass.
ba79b17268c8full audit observations/trust-audit/mcp-server/cappyeo__discord-36.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ba79b17268c8 | BLOCK | F | 57 | first audit |
Questions
What is the Discord MCP server?
Open-source Discord MCP server for Claude, Codex, Cursor and other AI clients: 209 typed tools, caller-owned bots, safety controls and verifiable guild builds.
What tools does Discord expose?
45 in total: 36 read-only, 9 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Discord safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (57/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Discord need?
It reads ANTHROPIC_API_KEY, DISCORD_MCP_ACCESS_TOKEN, DISCORD_TOKEN, GITHUB_TOKEN and MCP_APPROVAL_HMAC_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Discord run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as site at 0.31.1.
How current is this page?
The grade is for one exact copy of the source (ba79b17268c8), read on 2026-10-07. The repository is watched and re-audited when it changes.