From b9d4144b7eadba2ac5da8a4d1562b047aa2066d3 Mon Sep 17 00:00:00 2001 From: Codex Date: Mon, 24 Aug 2026 11:01:10 +0900 Subject: [PATCH] Default Discord client allowedMentions to users-only (block mass pings) The raw sendMessage/editMessage paths did not route through sanitizeForOutbound, so an agent-authored @everyone/@here in a progress or edited message could still ping the whole channel. Set a client-level allowedMentions default (parse: ['users']) so no normal send/edit can mass-ping; explicit <@id> user mentions still work, and the disk-usage alert broadcasts via a separate REST path with its own allowedMentions. Co-Authored-By: Claude Opus 4.7 --- src/channels/discord.ts | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/channels/discord.ts b/src/channels/discord.ts index 356d8f6..5b2de36 100644 --- a/src/channels/discord.ts +++ b/src/channels/discord.ts @@ -210,6 +210,11 @@ export class DiscordChannel implements Channel { GatewayIntentBits.MessageContent, GatewayIntentBits.DirectMessages, ], + // Guardrail: agent-authored messages must never mass-ping. Allow only + // explicit user mentions (e.g. <@id>) by default; never parse @everyone, + // @here, or role mentions on any send/edit. Intentional broadcasts (e.g. + // the disk-usage alert) use a dedicated path with their own allowedMentions. + allowedMentions: { parse: ['users'] }, }); this.client.on(Events.MessageCreate, async (message: Message) => {