Get StartedNative Windows

Capabilities and commands

Native Windows capability status and the complete public DefenseClaw CLI and gateway command-family inventory.

Command registration is not the same as Windows certification. This page separates what the installed binaries expose from the native Windows behavior the release actually qualifies.

Capability matrix

CapabilityStatusNative Windows boundary
Codex, Claude Code, and Amp connector setupSupportedSame-user native agent, native hook or owner-only Amp system plugin, authenticated loopback gateway.
Cursor, Windsurf, Gemini CLI, Copilot CLI, Antigravity, OpenCode, and Hermes setupNot certifiedCross-platform setup code exists, but the native Windows release does not qualify it.
OpenHands, OmniGent, OpenClaw, and ZeptoClaw setupUnsupportedTheir required WSL, terminal/sandbox, or proxy topology is not hosted by native Windows DefenseClaw.
Python CLISupportedPackaged launcher and embedded runtime; PowerShell and cmd. Individual optional/network subcommands retain their caveats below.
TUISupportedNative console input, UTF-8 output, clipboard support, managed process cancellation, and safe fallback when redraw is unavailable.
AI Discovery and model provenanceSupportedNative process enumeration covers unique exact executable aliases across the full discovery catalog and fails closed on shared aliases. Classic installed-app metadata and current-user Store/MSIX/UWP registrations from the supported AppsFolder Shell API, PowerShell history, AppData editor-extension stores, and common local-model roots use bounded native discovery. The TUI keeps models in a separate table with ISO country code/flag, publisher, root/base, and derivation. Public Hugging Face enrichment is off by default and requires explicit opt-in.
Gateway start/status/restart/stopSupportedDetached current-user process with authenticated PID/start/executable identity. Not a Windows service.
Logon startupSupportedInstaller-owned HKCU Run value and no-console startup helper when a connector is configured.
WatchdogLimitedConfig-enabled detached process with protected identity. Not a service or Scheduled Task.
Observe and action modesSupportedAction applies only to declared connector/event response surfaces.
Fail open/fail closedSupportedEffective connector setting covers transport and invalid response failures. Internal evaluator panic remains a reported fail-open boundary.
Native hooks and policy pluginSupportedCodex and Claude Code use defenseclaw-hook.exe; Amp loads %USERPROFILE%\.config\amp\plugins\defenseclaw.ts directly. No Bash, cmd wrapper, jq, WSL, or proxy is required.
Native OTLP ingressSupportedCodex logs/metrics/traces; Claude Code logs/metrics with traces disabled. Observation only. Amp has no documented native-OTLP channel and uses hook-generated telemetry.
Mandatory local auditSupportedSQLite persists locally even without an outbound destination.
Remote telemetry destinationsLimitedSupported when explicitly configured and reachable; credentials, network policy, and destination capabilities remain operator responsibilities.
Skills, plugins, MCPs, agents, and command discoverySupportedScans the supported connectors' documented native roots. Discovery is not proof an asset is safe.
Skill and MCP scanningSupportedPackaged scanners are included. Remote URL/registry scans require optional network access.
CodeGuardLimitedExplicit opt-in; Codex/Amp AgentSkill and Claude Code plugin installation may need the agent/network. It is never silently installed.
Skill runtime enable/disableLimitedExact inventoried identities only. Hard load-event enforcement is limited to Codex leading $skill selection and Claude Code UserPromptExpansion; Amp has no separate skill-load callback.
Plugin runtime enable/disableLimitedHard event enforcement for Claude Code expansion; Codex is advisory. Amp runs plugin top-level code at load, so quarantine is the filesystem enforcement control.
Skill quarantine/restoreSupportedJournaled, provenance/hash-checked move and restore. Separate block/disable state survives restore.
Plugin quarantine/restoreLimitedValidated filesystem move/restore; no claim of the stronger skill transaction guarantee.
Alerts and local historySupportedConnector-attributed list/show/acknowledge/dismiss and TUI views.
Windows notificationsLimitedNative notification broker for an attended Explorer user session; not a service/session-zero delivery guarantee.
Policy create/validate/test/activateSupportedLocal policy and firewall evaluation; external judges/providers remain optional configuration.
Status, doctor, config, and versionSupportedSafe default output masks secrets; doctor can preview approved repair actions.
Connector/global enable and disableSupportedRestart reconciles runtime state. --no-restart can leave visible desired/runtime drift.
Gateway token rotationSupportedGlobal transactional rotation, all active connectors refreshed, readiness/auth verified, exact prior state restored on failure.
Native automatic upgradeUnavailable for published releases through 0.8.10Every published manifest has an empty Windows tested-source list. A future target could authorize only sources named by its authenticated manifest. No manual downgrade/rollback command.
Fresh/repair/uninstall packaged lifecycleSupportedRelease-authenticated per-user Setup in a non-elevated interactive user session. Current Setup is not Authenticode-signed.
Offline install/servicingLimitedSelf-contained Setup after authenticated staging; remote registries/providers/destinations are not offline features.
Local observability and Local SplunkLimitedOptional Hyper-V Docker Desktop/Linux-container path on x64 Pro/Enterprise/Education only.
OpenShell sandboxUnsupportedLinux-only lifecycle.
Model proxy/rerouting for supported connectorsNot applicableCodex, Claude Code, and Amp keep their direct upstream path; Windows enforcement is hook/plugin-native.
POSIX services and hook shellsNot applicableWindows uses native processes, HKCU startup, and the native hook runner.

Public defenseclaw command inventory

The following groups come from the installed Click command tree. “Limited” means the group contains an optional dependency, a connector-specific surface, or an advanced operation; it does not mean every listed subcommand is broken.

Command familyPublic subcommandsWindows classification
agentcomponents, history, show; confidence explain, confidence policy default/show/validate; discover; discovery disable/enable/scan/setup/status; processes; signatures disable/enable/install/list/validate; usageSupported for local inventory/discovery. Public Hugging Face model-card enrichment is optional, transmits an exact recovered repository ID, and remains off until --lookup-model-provenance-online (or the matching interactive/config setting) is selected.
aibomscanSupported local scan.
alertsacknowledge, dismiss; the group itself lists/shows alertsSupported.
auditlog-activitySupported. Audit export is on defenseclaw-gateway.
codeguardinstall, install-skill, statusLimited explicit opt-in; agent/network requirements apply.
configpath, reference, show, validateSupported. Configuration v8 rejects config show --reveal; effective and source views remain masked.
doctorno subcommandsSupported. Use --fix --dry-run before approving fixes.
guardrailblock-message, disable, enable, fail-mode, hilt; judge add/list/remove; list-packs; statusSupported for Codex, Claude Code, and Amp; event limits still apply.
initno subcommandsLimited to supported native connector choices; sandbox setup is unsupported.
keyscheck, fill-missing, list, setSupported, but secret values must not be pasted into support output.
mcpallow, block, list, scan, set, unblock, unsetSupported for certified connector roots; remote scans are optional network operations.
migrationsreset, status, unmarkLimited advanced recovery/upgrade surface; do not change markers without a diagnosed reason.
observabilitydestination test, planLimited to configured destinations and their network/credential contract.
pluginallow, block, disable, enable, info, install, list, quarantine, remove, restore, scan, unblockLimited by connector runtime-disable and quarantine guarantees.
policyactivate, create, delete; edit actions/firewall/guardrail/scanner; list, show, test, validateSupported. Optional remote judge/provider behavior is separately configured.
quickstartno subcommandsLimited to supported native connectors; Windows sandbox/proxy choices are rejected.
registryadd, approve, edit, entries, list, reject, remove, require, show, sync, test, wizardLimited; sync/test can require network and registry trust policy.
resetno subcommandsSupported but destructive and confirmation-gated. It is not uninstall.
sandboxinit, setupUnsupported on native Windows.
settingssaveSupported.
setupSee the complete setup inventory below.Limited: only the explicitly supported connector and optional-feature paths apply on Windows.
skillallow, block, disable, enable, info, install, list, quarantine, restore, scan, search, unblockSupported, with the runtime-disable limits in the capability matrix.
statusno subcommandsSupported; --json includes per-connector runtime posture.
toolallow, block, list, status, unblockSupported local policy state.
tuino subcommandsSupported.
uninstallno subcommandsSupported; packaged installs hand off to trusted Setup.
upgradeno subcommandsUnavailable for published releases through 0.8.10 because no target manifest authorizes a Windows source.
versionno subcommandsSupported; detects component drift.

The root also exposes --version. With no command, an interactive terminal can launch the TUI; scripts should always name the intended command.

Complete setup inventory

The public tree contains:

  • Connector aliases: antigravity, claude-code, codex, copilot, cursor, geminicli, hermes, amp, omnigent, openclaw, opencode, openhands, windsurf, zeptoclaw.
  • Core setup: gateway, guardrail, llm, mcp-scanner, migrate-llm, notifications, notifications-set, registry, remove, rotate-token, skill-scanner, trusted-paths add/list/remove.
  • Providers and routes: provider add/list/remove/show, observability add/disable/enable/list/remove/test, and webhook add/disable/enable/list/remove/show/test.
  • Galileo: galileo disable/enable/remove/status/test.
  • Local observability: local-observability down/env/logs/reset/status/up/url.
  • Splunk: the splunk setup surface plus splunk dashboards apply/destroy/plan.

On native Windows, codex, claude-code, and amp are supported connector aliases. The other aliases remain visible because this is one cross-platform CLI; their presence does not override the platform gate. Local observability, Splunk, providers, webhooks, Galileo, registries, and remote destinations are optional and retain their own prerequisites.

Public defenseclaw-gateway command inventory

Command familyPublic subcommandsWindows classification
start, status, restart, stopno child commandsSupported current-user daemon lifecycle.
watchdogstart, status, stopLimited config-enabled detached monitor, not an OS service.
auditexportSupported. Exported content can be sensitive; handle it as audit data.
connectorlist-backups, reconcile, teardown, verifySupported for Codex, Claude Code, and Amp; low-level operator/recovery surface.
policydomains, evaluate, evaluate-firewall, reload, show, validateSupported.
provenanceshowSupported.
scancodeSupported CodeGuard/ClawShield source scan.
enterprise hooksinstall, reconcile, uninstall, watchUnsupported as a general public-package guardian. Limited exception: administrator-managed Claude Code policy when binaries are separately deployed in a protected machine-owned path; see Enterprise deployment.
sandboxexec, policy, restart, shell, start, status, stopUnsupported on native Windows.
completionpowershell; also generates bash, fish, zsh scriptsSupported for PowerShell. Other shell generators emit text but those shells are outside native Windows certification.

Hidden hook, notify, config-v8, and observability-v8 helpers are implementation interfaces used by managed launchers and the CLI. They are not public operator commands and are intentionally excluded from the inventory.

Safe common workflows

These commands do not require secret values:

# Identity and health
defenseclaw version
defenseclaw-gateway status
defenseclaw status
defenseclaw doctor

# Configuration and policy checks
defenseclaw config validate
defenseclaw policy validate
defenseclaw observability plan

# Local inventory and scans
defenseclaw skill list
defenseclaw skill scan
defenseclaw mcp list
defenseclaw mcp scan
defenseclaw-gateway scan code .

# Connector posture
defenseclaw guardrail status
defenseclaw guardrail fail-mode

The product commands are identical in cmd. PowerShell-specific multiline syntax and path expressions in this guide are labeled. Avoid environment-dump commands, the unsupported v8 config show --reveal flag, credential display flags, or copying audit and backup trees into a support ticket.

For the cross-platform option reference, see CLI reference.