kiro-discord-bot

Discord MCP Server #

mcp-discord 是 release archive 內附的可選 MCP server。它讓 agent 可以直接使用 Discord REST 能力,例如讀訊息、列頻道、送訊息、建立 thread、下載附件與加 reaction。

它不是一般 bot 回覆的必要路徑。一般 agent final answer 應直接回傳給 bot,由 bot 統一處理 redaction、分段與送出。

建置或找到 Binary #

Release archive 會包含 mcp-discord。從原始碼可建置:

go build -o mcp-discord-server ./cmd/mcp-discord

Catalog command 中請一致使用同一個 binary 名稱。部署環境常見做法是把 mcp-discord-server 放在 main bot binary 旁邊。

安裝 Steering Guidance #

repo 內有 .kiro/steering/discord-mcp.md。只有當你希望 bot 外的 Kiro sessions 也理解 Discord MCP tools 時,才需要安裝到全域:

mkdir -p ~/.kiro/steering
cp .kiro/steering/discord-mcp.md ~/.kiro/steering/discord-mcp.md

bot-managed runtime session 的 MCP 可見性仍由 channel policy 控制。

註冊到 MCP Catalog #

~/.kiro/settings/mcp.jsonKIRO_MCP_CONFIG 指向的檔案加入:

{
  "mcpServers": {
    "mcp-discord": {
      "command": "sh",
      "args": [
        "-c",
        "set -a && . /absolute/path/to/.env && exec /absolute/path/to/mcp-discord-server"
      ],
      "env": {}
    }
  }
}

本機多 bot 開發時,請確認 .env 是你正在測試的 bot 身分。如果畫面上是 M5Bot,但 catalog command 載入 ChunBot token,替 M5Bot 開 Discord 權限也無法修正 MCP 403 Missing Access

加上 Defense-in-depth Guards #

在載入的 .env 或 catalog environment 設定:

MCP_DISCORD_ALLOWED_GUILDS=123456789012345678
MCP_DISCORD_ALLOWED_CHANNELS=234567890123456789,345678901234567890
MCP_DISCORD_DOWNLOAD_DIR=/tmp/kiro-discord-mcp
MCP_DISCORD_READ_ONLY=false
MCP_DISCORD_ALLOWED_WRITE_TOOLS=discord_send_message,discord_reply_message,discord_resolve_mentions
MCP_DISCORD_ALLOW_DESTRUCTIVE=false
MCP_DISCORD_MEMBER_SCAN_LIMIT=5000

空 allowlist 會保留舊版 unrestricted 行為。正式環境若 bot 有廣泛 Discord 權限,建議明確設定 guild/channel allowlist。

依頻道啟用 #

註冊會把 server 加進 catalog。當這個 catalog entry 存在時,bot 的 default bot-tools setup 會自動只替 mcp-discord 開啟 discord_resolve_mentions,行為對齊預設開啟的 bot-native image URL egress,但其他 Discord REST tools 仍維持關閉。

若要額外啟用其他 tools,請在 Discord 中:

  1. 執行 /mcp status 確認 mcp-discord 出現。
  2. 執行 /mcp manage
  3. 掃描 server。
  4. 只啟用該頻道需要的額外 tools。
  5. 讓 bot 重啟 active agents,使新 policy 在下一個 session 注入。

常見工具群組 #

群組範例風險
Readdiscord_read_messages, discord_search_messages, discord_channel_info會讓 agent 看見 channel content
Mention resolverdiscord_resolve_mentions用 fresh Discord member lookup 解析使用者要求的名字,只把 exact/unique match 授權給目前 bot task,並回傳安全的 [[discord:user:...]] placeholder
Writediscord_send_message, discord_reply_message, discord_send_embed會送出可見 Discord 訊息
Threaddiscord_create_thread, discord_list_threads建立或檢視 conversation surfaces
Managementdiscord_edit_message, discord_pin_message, discord_edit_channel_topic維運風險較高
Attachmentdiscord_download_attachment需要 download directory 控制

建議先開 read-only,再只對工作流程需要的地方加入 non-destructive write tools。

當使用者要求 tag 或通知某個名字,但該人沒有出現在目前 prompt 的 mention references 時,優先使用 discord_resolve_mentions,不要用 discord_list_members 後自行猜 ID。它會先做 fresh REST member search,再做 bounded scan / cache fallback,並把解析出的 refs 寫入目前 bot target state,回傳 agent 可在 final answer 使用的 placeholders。Ambiguous 或 missing names 必須請使用者確認,不可猜。只有在 guild 很大且 exact name 常被預設 scan limit 漏掉時,才調高 MCP_DISCORD_MEMBER_SCAN_LIMIT