CLI commands
Every defenseclaw verb, grouped by what you are trying to do — first run, setup, audit, scanning, gateway control, status, uninstall.
Authoritative source for any flag is defenseclaw <command> --help. These groupings are curated for browsing.
Command availability is platform-specific
A registered command or connector alias is not, by itself, a native Windows support claim. Native Windows supports Amp plus Codex, Claude Code, Cursor, Devin, GitHub Copilot CLI, Antigravity, OpenCode, Hermes, Kiro, and OmniGent. OpenHands, OpenClaw, and ZeptoClaw remain unavailable there. Some commands require optional configuration or are unavailable there. Use the connector platform table for availability and each connector page for native Windows setup and quirks.
DefenseClaw ships three binaries:
defenseclaw— the operator-facing Python CLI. Entry point forinit,setup,audit,policy,skill/mcp/pluginscans, alerts, doctor, etc.defenseclaw-gateway— the long-running Go sidecar. Owns the on-host daemon (start/stop/restart), policy reload, code scanning, and the audit-DB JSONL exporter.defenseclaw-acp— the protocol-aware stdio guard spawned by ACP clients. It validates its runtime contract before launching the selected agent, then evaluates ACP traffic while it mediates stdio.
Tables below tag each row with the binary that owns it.
First run
| Command | Use it for |
|---|---|
defenseclaw init | Interactive first-run wizard. On a TTY, pre-selects installed hook connectors and lets you choose which ones stay observe vs action. Non-interactive multi-connector flags are --observe-all and --action-connectors; an explicit --connector keeps the single-connector path. |
defenseclaw quickstart | Zero-prompt first-run for one connector with safe defaults. Pass --connector <name> when more than one connector is configured or detected. See Quickstart. |
defenseclaw doctor | Health and repair check. Run this first whenever something feels off; see Doctor below. |
defenseclaw status | Enforcement flags and gateway state, plus a per-connector block for every active connector. Read commands like this fan out to all actives — the same layout whether one or N are wired. |
defenseclaw version [--json] [--no-drift-exit] | Versions of the CLI, the gateway binary and the OpenClaw plugin, which reads (not used) unless OpenClaw is an active connector. Exits 1 when their versions differ (not with --json or --no-drift-exit) or a component fails to report. |
Doctor
defenseclaw doctor [--json-output | --json] [--passive]
defenseclaw doctor --fix [--dry-run] [--yes] [--fix-id REPAIR_ID]...Common invocations:
defenseclaw doctor --json
defenseclaw doctor --passive
defenseclaw doctor --fix --dry-run
defenseclaw doctor --fix --fix-id doctor.gateway.token.ensureDoctor checks configuration, audit and identity state, component and active connector compatibility, scanner binaries, managed gateway health and authentication, configured guardrail and scanner services, credentials, and observability destination health.
--json-output (also available as --json) emits schema v2. Health remains in
checks and summary; repair attempts are independent records under repairs
and repair_summary. Repair states are applicable, noop, blocked,
manual, requires_confirmation, declined, applied, and failed. Each
record also carries its stable repair ID, risk, dependencies, effects, blockers,
restart potential, and platform. The top-level outcome and exit_code
combine health and repair results without adding repair failures to health
counters.
Use --passive to suppress synthetic telemetry, LLM, and
inspection-content-submitting probes. Every --fix --dry-run is passive and
runs planners only, so it cannot mutate disk or restart a service.
--fix-id is repeatable and selects exact work plus declared dependencies.
--yes may approve eligible safe and disruptive repairs, but does not select
policy or experimental work. A JSON repair must be a dry-run preview or include
--yes. See Reporting and diagnosis
for token, audit, identity, compatibility, and recovery safety boundaries.
Setup
| Command | Use it for |
|---|---|
defenseclaw acp detect [--json-output] | Report every known ACP client and classify each agent server as guarded, adoptable, client-registry (unmediated but not wrappable), or foreign. Read-only. |
defenseclaw acp adopt [--client X] [--activate] [--yes] | Adopt the agents detect found. |
defenseclaw acp catalog | Show the pinned ACP schema and built-in client/agent inventory. |
defenseclaw acp setup --client zed|jetbrains --agent <name> [--activate] | Install or reconfigure a managed guarded entry. Defaults to observe mode. |
defenseclaw acp setup --managed ... --runtime-data-dir <dir> --token-file <path> | Install only user-side editor/lock files for a centrally authorized enterprise enrollment. |
defenseclaw acp status | Show the ACP posture and configured bindings. |
defenseclaw acp remove --client <client> --agent <agent> | Remove only the DefenseClaw-owned entry. |
defenseclaw-gateway enterprise acp enroll|verify|revoke ... | Manage the protected per-principal/client/agent/profile credential and its private user copy. |
Hook setup aliases (setup codex, setup claude-code, setup hermes, and the rest) add or reconfigure one connector. On a host with another hook connector already active, choose Add to join the active roster; choose Replace only when you want to return to one wired connector. Proxy connectors (openclaw, zeptoclaw) own the traffic plane and do not join the hook-connector roster.
| Command | Use it for |
|---|---|
defenseclaw setup guardrail | The central setup command. See Setup Guardrail. |
defenseclaw setup routing --enable|--disable|--status | Configure or inspect semantic model routing for proxy-mode OpenAI Chat Completions traffic. Managed mode requires Docker; all config changes activate on gateway restart. See Semantic model routing. |
defenseclaw setup llm | Write the unified or role-scoped LLM block (--role unified|agent|judge). Supports SaaS providers and regional Bedrock / Vertex AI / Azure OpenAI via dedicated --bedrock-*, --vertex-*, --azure-* flags, plus --instance-name to bind a custom-provider overlay and --inherit-from to seed from a sibling component. Pair with --ping for an immediate reachability probe. See Unified LLM key. |
defenseclaw setup provider add|list|show|remove | Manage the ~/.defenseclaw/custom-providers.json overlay used to route LLM traffic through internal or self-hosted endpoints. add accepts --base-url, --domain (repeatable; required alongside --base-url so the gateway can match inbound URLs back to this overlay entry — defenseclaw doctor warns when the base_url host is not covered), --base-provider-type, --env-key, --allowed-request, --available-model, --request-path-override, TLS knobs (--ca-cert-file, --insecure-skip-verify), and provider-typed regional flags: Bedrock — --bedrock-region, --bedrock-auth-mode, --bedrock-access-key-env, --bedrock-secret-key-env, --bedrock-session-token-env, --bedrock-profile-name, --bedrock-inference-profile, --bedrock-deployment alias=model-id (repeatable); Vertex AI — --vertex-project-id, --vertex-region, --vertex-auth-mode, --vertex-service-account-json-env; Azure OpenAI — --azure-endpoint, --azure-api-version, --azure-auth-mode, --azure-deployment-alias model=deployment (repeatable). Each family is rejected against a mismatched --base-provider-type. Omit --name interactively for the wizard. |
defenseclaw setup claude-code | Hook setup alias for Claude Code; defaults to observe, pass --mode action to block hook-side. |
defenseclaw setup codex | Hook setup alias for Codex; defaults to observe, pass --mode action to block hook-side. |
defenseclaw setup cursor | User-hook alias for Cursor; defaults to observe, while --mode action uses event-native deny with failClosed: true. Native human approval is not enabled. |
defenseclaw setup devin | Native Devin CLI hook alias; defaults to observe, while --mode action can block only on the four documented block-capable events. |
defenseclaw setup copilot | Hook setup alias for GitHub Copilot CLI; defaults to observe, pass --mode action to block hook-side. |
defenseclaw setup hermes | Hook setup alias for Hermes; defaults to observe, pass --mode action to block hook-side. |
defenseclaw setup openhands | Hook setup alias for OpenHands on supported non-Windows platforms; it is unsupported in the native Windows release. Defaults to observe, pass --mode action to block hook-side. |
defenseclaw setup antigravity | Hook setup alias for Antigravity (agy); defaults to observe, pass --mode action to block hook-side. Native ask and deny are documented only for PreToolUse; no permission-bypass override is claimed. |
defenseclaw setup opencode | Hook setup alias for OpenCode; writes the auto-loaded bridge plugin. Defaults to observe, pass --mode action to block hook-side. |
defenseclaw setup acp | Find ACP agents an editor is launching unguarded and route them through defenseclaw-acp. Reuses the per-pair acp setup transaction and points the operator's existing entry at the guard, so no unmediated duplicate is left behind. Defaults to observe; --activate selects action. Alias of defenseclaw acp adopt. |
defenseclaw setup kiro | Native hook alias for Kiro IDE and Kiro CLI; defaults to observe, pass --mode action to block hook-side. The .kiro/hooks surface (Kiro IDE and kiro-cli --v3) vetoes PreToolUse, and UserPromptSubmit in Kiro IDE (kiro-cli 2.24.1 --v3 still sends a blocked prompt to the model); the CLI 2.x agent config vetoes PreToolUse only. ACP is optional and configured separately with defenseclaw acp setup --agent kiro. |
defenseclaw setup amp | Direct-to-upstream system-policy setup for Amp; writes the TypeScript plugin. Defaults to observe; pass --mode action for synchronous tool.call execution gating and model-bound tool.result output gating. Native confirmation is available only in the active foreground thread; background confirmation falls back to safe rejection or withholding. |
defenseclaw setup omnigent | Hook setup alias for OmniGent; installs the custom Python policy bridge. Defaults to observe, pass --mode action for ALLOW/ASK/DENY enforcement. |
defenseclaw setup openclaw | Full guardrail alias for OpenClaw (proxy connector); unsupported in the native Windows release. |
defenseclaw setup zeptoclaw | Full guardrail alias for ZeptoClaw (proxy connector); unsupported in the native Windows release. |
defenseclaw setup local-observability up|down | Bring up the bundled Prom/Loki/Tempo/Grafana stack. up --password requires the managed Grafana credential; up --no-password explicitly selects anonymous Admin on managed loopback. New stacks default to password and previously used anonymous stacks retain their mode. |
defenseclaw setup galileo [status|test|enable|disable|remove] | Configure and verify Galileo Cloud or self-hosted OTLP traces. |
defenseclaw setup splunk | Configure local Splunk in Docker, Splunk Enterprise HEC, or Splunk Observability Cloud. |
defenseclaw setup webhook | Configure Slack / PagerDuty / Webex / generic notifier webhooks (chat + incident routing). |
defenseclaw setup observability add|list|enable|disable|remove|test | Manage config-v8 destinations across OTLP, Galileo, Splunk HEC, JSONL, HTTP JSONL, console, and Prometheus capabilities. Omitted destination policy means all supported signals/buckets, unredacted. Distinct from setup webhook, which manages notifier webhooks. |
defenseclaw setup redaction [status|remove-all|apply|defaults|bucket|profile|destination|route] | Configure v8 redaction interactively or with scriptable subcommands. Bare invocation offers a simple baseline choice followed by Show advanced settings? for all buckets, profiles, destination policy, and ordered routes. Mutations preview the canonical effective diff; changed non-dry-run writes create a timestamped backup and verify the installed plan. |
defenseclaw observability plan | Print the masked effective v8 graph: generated local SQLite policy, collection, destination capabilities, routes, profiles, retention, and warnings. |
For observability destinations, name is the stable identity: a new name adds,
and an existing name updates only that destination. Run list --json for the
complete target/kind/signal inventory and add ... --dry-run for a safe preview.
The TUI mirrors the runtime-loaded inventory in Overview → Observability
Destinations and exposes the wizard at 0 Setup → Observability / Galileo.
The quickest way to remove every configurable redaction override is:
defenseclaw setup redaction remove-all --dry-runProfile none permits governed content without redaction
remove-all can expose governed content to configured destinations. Confirm that
each affected destination has an approved trust boundary before using --yes.
defenseclaw setup redaction remove-all --yesThis selects profile none for configurable log and trace projections without
changing collection or routing. It affects generated local SQLite, but never
weakens the release-owned managed enterprise destination. See
Redaction for the full interactive walkthrough and
advanced command examples.
| Command | Use it for |
|---|---|
defenseclaw setup trusted-paths list|add|remove | Manage the directories trusted for connector-binary version probing (action-mode setups refuse binaries outside this allow-list). list shows built-in defaults plus operator additions with source and status; add validates the directory (world-writable / relative paths refused unless --force) and persists to ~/.defenseclaw/.env; remove only touches operator-added entries. All verbs accept --json. |
Safety gates are intentional
Commands that fetch remote content fail closed when the trust boundary is
unclear. Connector version probes enforce trusted path prefixes when
ai_discovery.require_trusted_binary_paths: true; that gate defaults to
false for on-demand discovery. Registry and scanner fetches reject loopback,
link-local, cloud-metadata, and private-network targets unless explicitly
allowed; defenseclaw upgrade verifies release artifacts before stopping the
running gateway.
Guardrail
Per-connector guardrail controls. --connector X is the explicit scope selector on a multi-connector install: reads narrow to one active connector, and writes land in guardrail.connectors.<name>. Omit --connector for the broad path. Reads show the full active roster; global enable/disable affects the whole guardrail; fail-mode, HILT, and block-message writes reconcile active connector posture where supported. On a single-connector install --connector is rejected because there is only one posture, except for mode, block-at, alert-at, use-pack and protection, which accept the one active connector and write its override block. All of these are on the Python defenseclaw CLI.
| Command | Use it for |
|---|---|
defenseclaw guardrail status [--connector X] | Read-only. Shows the resolved guardrail posture (enabled, mode, fail mode, HILT, block message) as one per-connector block for every active connector by default. Pass --connector X to narrow the view to one active connector. |
defenseclaw guardrail enable [--connector X] | Turn the guardrail on. Global, or re-enable a single previously-disabled connector (restores its hooks with no re-prompt). |
defenseclaw guardrail mode observe|action [--connector X] [--clear] [--no-restart] [--json] | Switch between observe (log findings, block nothing) and action (enforce) without re-running setup. Sets only guardrail.mode, or with --connector X only guardrail.connectors.X.mode (the block is created if needed); --clear --connector X removes X's override so it follows the global mode. Never touches the guardrail's on/off state, rule pack, or port. Hook decisions read the configuration the gateway started with, so a mode change restarts a running gateway unless you pass --no-restart; a stopped gateway is never started. A global change names the connectors that keep their own mode. --json prints {"version": 1, "ok", "scope", "mode", "previous", "mode_source", "changed", "not_covered", "gateway", "message"}. |
defenseclaw guardrail block-at LEVEL [--connector X] [--no-restart] [--json] | Set the lowest severity at which tool calls are blocked. LEVEL is CRITICAL, HIGH, MEDIUM or LOW (any case), or inherit to clear the value. Sets only guardrail.block_at, or with --connector X only guardrail.connectors.X.block_at (the block is created if needed). A connector's own level wins over the global one, which wins over the level of the scope's rule pack (strict blocks MEDIUM+, default and permissive CRITICAL). It applies to tool-call decisions in action mode (hook tool calls, and tool calls the guardrail proxy finds in LLM responses); the named policy's thresholds for LLM traffic through the guardrail proxy are separate (policy edit guardrail). A change restarts a running gateway so hook decisions pick it up, unless you pass --no-restart; a stopped gateway is never started. A global change names the connectors that keep their own level and those whose stricter rule-pack level it replaces. See Tool-call levels. |
defenseclaw guardrail alert-at LEVEL [--connector X] [--no-restart] [--json] | The same for the lowest severity that raises an alert (guardrail.alert_at, pack levels: strict LOW+, default MEDIUM+, permissive HIGH+). Anything that blocks also alerts, so an alert level above the block level alerts from the block level. |
defenseclaw guardrail disable [--connector X] | Kill switch. Global disables everything; --connector X drops just that connector from the active set and removes its hooks. |
defenseclaw guardrail fail-mode [open|closed] [--connector X] | Show/set behavior for hook delivery, authentication, and invalid-response failures. Run bare it prints the global value plus a per-connector breakdown of every active connector's effective value. See Reference → Fail modes. |
defenseclaw guardrail hilt [on|off] [--min-severity high|medium|low|critical] [--connector X] | Show/set human-in-the-loop approval policy. Run bare it prints the global value plus a per-connector breakdown. |
defenseclaw guardrail block-message ["<text>"] [--clear] [--connector X] | Show/set the message the agent sees when an action is blocked. Run bare it prints the global value plus a per-connector breakdown. --clear --connector X removes that connector's override so it inherits the global message, or the built-in default when the global value is empty. Unscoped --clear also clears active connector overrides, returning the active roster to the built-in default. Do not pass text and --clear together. |
defenseclaw guardrail list-packs [--json] | Read-only. Lists the built-in rule-pack presets, custom packs found under ~/.defenseclaw/policies/guardrail/ or configured anywhere, and the pack each active connector enforces (per-connector override > global pack > built-in default). --json prints {"version": 1, "global": {...}, "connectors": [...], "packs": [...]}. |
defenseclaw guardrail use-pack PACK [--connector X] [--no-validate] [--no-restart] [--json] | Switch rule packs. PACK is a preset (default, strict, permissive), the name of a pack under ~/.defenseclaw/policies/guardrail/, or a directory. The pack is validated first and an invalid pack changes nothing. Without --connector, every connector uses PACK and all per-connector overrides are removed (the output lists them). --connector X writes only X's override. If the validator is unavailable, presets are applied with a warning and custom packs are refused (exit 2) unless you pass --no-validate. Never changes the guardrail's on/off state, mode, or port. A running gateway only loads a new pack when it restarts, so use-pack restarts it (--no-restart to skip; a stopped gateway is never started). --json prints {"version": 1, "ok", "scope", "connector", "pack", "path", "cleared_overrides", "validation", "gateway", "message"}. |
defenseclaw guardrail use-pack --clear --connector X | Remove X's rule-pack override so it uses the global pack again. |
defenseclaw guardrail protection list [--json] | Read-only. Lists the opt-in protection packs (five selectable, one staged) and which scope (the global pack or an active connector) has which on. See Opt-in protection packs. |
defenseclaw guardrail protection enable NAME [--connector X] [--no-validate] [--no-restart] [--json] | Turn an opt-in protection pack on for the global rule pack or for one connector. Composes, validates, and switches to ~/.defenseclaw/policies/guardrail/protected-<scope>/; an invalid composition (exit 1) or an unavailable validator (exit 2, unless --no-validate) switches nothing. Staged and unknown packs are refused (exit 1). |
defenseclaw guardrail protection disable NAME [--connector X] [--no-restart] [--json] | Turn it off again. The scope's pack is recomposed without it; when no opt-in pack is left, the scope goes back to its base pack. |
defenseclaw guardrail validate-pack PATH [--json] | Validate a rule pack offline with the gateway's own validator. Exit 1 means invalid, 2 means the validator is unavailable. |
defenseclaw guardrail status # full per-connector roster
defenseclaw guardrail status --connector codex # one connector's resolved posture
defenseclaw guardrail fail-mode closed --connector codex # scope to one connector
defenseclaw guardrail hilt on --min-severity HIGH --connector claudecode
defenseclaw guardrail block-message --clear --connector codex # inherit global / built-in
defenseclaw guardrail block-message --clear # clear global + active overrides
defenseclaw guardrail disable --connector codex # then `enable --connector codex` to restore
defenseclaw guardrail use-pack strict # every connector, clears overrides
defenseclaw guardrail use-pack ~/packs/my-org --connector codex
defenseclaw guardrail use-pack --clear --connector codex # back to the global pack
defenseclaw guardrail mode action # every connector without its own mode
defenseclaw guardrail mode observe --connector codex # codex only logs
defenseclaw guardrail block-at HIGH # every connector without its own level
defenseclaw guardrail block-at MEDIUM --connector codex # codex blocks MEDIUM+
defenseclaw guardrail alert-at inherit --connector codex # back to the global or rule-pack level
defenseclaw guardrail protection enable database-destruction-protection --connector codexSee Setup → Multi-connector for the full multi-connector model.
Tool-call levels
A tool call's finding is blocked at or above the block level and raises an
alert at or above the alert level. Each level resolves on its own: the
connector's guardrail.connectors.<name>.block_at / alert_at, else the
global guardrail.block_at / alert_at, else the level the scope's rule pack
implies (from its folder name: strict blocks MEDIUM+ and alerts on LOW+,
permissive blocks CRITICAL and alerts on HIGH+, anything else blocks
CRITICAL and alerts on MEDIUM+). The alert level is then lowered to the block
level if it sits above it. A global level therefore also replaces a stricter
pack's level on every connector without its own; the command names those.
In observe mode nothing is blocked; the levels apply once the scope is in
action mode.
block-at and alert-at --json print:
{
"version": 1,
"ok": true,
"scope": "codex",
"setting": "block_at",
"level": "CRITICAL",
"previous": "inherit",
"source": "override",
"effective_block_at": "CRITICAL",
"effective_alert_at": "LOW+",
"gateway": "restarted",
"message": "Codex (codex) now blocks tool calls at CRITICAL. Restarted the gateway; it is enforcing the change now."
}level and previous are the value the scope stores after and before the
change (inherit when it has none; when the command fails, level is the one
you asked for and nothing is written). source says where the scope's value of
this setting comes from now: override (its own), global, or pack.
effective_block_at and effective_alert_at are the scope's resulting levels
(CRITICAL, HIGH+, MEDIUM+, LOW+).
Opt-in protection packs
The packs in policies/guardrail-use-cases/ (shipped with the package) add
deterministic rules that only make sense where the operator declares a
protected environment, for example that a connector's database really is
production. See Protection packs
for what each one covers. Enabling one tells DefenseClaw that the scope's
environment is protected: it blocks what the pack proves there and never
infers that from resource names.
guardrail protection enable NAME builds the scope's pack from its current
base pack (a preset or a custom directory; a pack composed earlier is rebuilt
from the base it records) plus every opt-in pack that is on, using Policy
Creator's merge: the pack's rule IDs are removed from every base file, then
its rules are appended to the file with the same name or added as a new file.
The result goes to protected-global/ or protected-<connector>/ with a
defenseclaw-pack.json manifest ({"version": 1, "base", "base_name", "protection": [...]}), is validated before anything points at it, and the
scope is switched to it. The global scope doesn't touch connectors that have
their own rule pack; it lists them under not_covered so you can enable the
pack there too. A composition that fails validation, for example one that
exceeds the semantic-rule cost ceiling, changes nothing.
protection enable|disable --json prints:
{
"version": 1,
"ok": true,
"scope": "global",
"pack_path": "/Users/me/.defenseclaw/policies/guardrail/protected-global",
"protection": ["privacy-high-assurance", "cloud-production-protection"],
"validation": {
"wire_version": 1,
"kind": "validation",
"valid": true,
"summary": {
"judge_count": 4,
"judge_category_count": 23,
"rule_file_count": 8,
"rule_count": 247,
"enabled_rule_count": 243,
"local_pattern_count": 11,
"suppression_count": 9,
"sensitive_tool_count": 6,
"digest": "e9c55a1b691056955a3a2479b8eb694287dfb7b549cc869a01465e5583eaa5d5"
}
},
"not_covered": ["codex"],
"gateway": "restarted",
"message": "Cloud production protection is on for the global rule pack (protected-global, on top of 'default'). Restarted the gateway; it is enforcing the change now."
}protection list --json prints {"version": 1, "packs": [...], "scopes": [...]}.
Each pack has name, title, summary (the README's first paragraph),
covers (a short phrase), rule_count, rule_ids, status (selectable or
staged), and rules (id, severity, title). Each scope has scope
(global or a connector), pack, path, and enabled (the packs on there).
gateway in the mode, block-at, alert-at, use-pack, and protection
results says how the saved change reached the gateway: restarted, live
(applied without a restart), not_running (it loads the change when it
starts), guardrail_off (takes effect when you run
defenseclaw guardrail enable), restart_needed (--no-restart: the running
gateway keeps the old setting until you restart it), or restart_failed (the
change is saved but the restart failed; exit 1).
Policies
Named security policies (default, strict, permissive, plus any you create) set admission, skill actions, guardrail thresholds, and the firewall defaults. policy list shows only real security policies: the bundled host-firewall template (firewall-deny-default.yaml) is not a named policy, so policy list skips it and policy activate refuses it.
| Command | Use it for |
|---|---|
defenseclaw policy list [--json] | List built-in and custom policies and mark the active one. --json prints {"version": 1, "active": "<name>", "policies": [...]}; each policy reports block_at, alert_at, install_block_at (CRITICAL, HIGH+, MEDIUM+, LOW+ or none), firewall_default, hilt, scanner_overrides, and whether activating it replaces webhooks (replaces_webhooks) or changes Cisco AI Defense settings (sets_cisco). |
defenseclaw policy show NAME [--json] | Show one policy. --json prints {"version": 1, "policy": {...}} with the same fields; exits 1 if the policy doesn't exist. |
defenseclaw policy activate NAME [--reload/--no-reload] | Apply a policy to config.yaml and the OPA data.json, then (by default) ask the running gateway to reload it. If the gateway isn't running, the policy is saved and loads when the gateway starts (exit 0). If the gateway rejects the reload, the command exits 1; run defenseclaw policy validate to find the problem. |
defenseclaw policy edit guardrail|actions|scanner|firewall … [-p NAME] [--reload/--no-reload] | Edit one section of a policy (the active one unless -p NAME); editing a built-in saves a user copy first. When the edited policy is the active one, the change is synced to the OPA data.json and, by default, the running gateway is asked to reload it, with the same outcomes as policy activate. Editing any other policy only saves the draft. policy edit guardrail --block-threshold N --alert-threshold N takes severity ranks (4 = CRITICAL, 3 = HIGH, 2 = MEDIUM, 1 = LOW) and applies to every connector that uses the policy. |
defenseclaw policy list --json | jq -r '.active'
defenseclaw policy show strict --json
defenseclaw policy activate strict # save + live reload
defenseclaw policy activate strict --no-reload # save only
defenseclaw policy edit guardrail --block-threshold 3 # active policy blocks HIGH+ nowCredentials
| Command | Use it for |
|---|---|
defenseclaw keys list [--json] | Show every credential DefenseClaw knows about and where its value comes from. |
defenseclaw keys set NAME [--value V | --value-stdin] | Save a credential to ~/.defenseclaw/.env. Without a value option it prompts with hidden input. --value-stdin reads the first line of standard input (trailing newline removed) and never echoes it, so the secret stays out of shell history and process listings; an empty line exits 1. --value and --value-stdin can't be combined. |
printf '%s\n' "$VT_KEY" | defenseclaw keys set VIRUSTOTAL_API_KEY --value-stdinMulti-connector
One gateway can protect N hook connectors at once (see Setup → Multi-connector). That splits the CLI into a few contracts:
- Read / status / inventory — fan out to all active connectors.
defenseclaw status,defenseclaw doctor, baredefenseclaw guardrail status, the bareguardrail fail-mode/hilt/block-messagereads, and the list/status commands (skill list,mcp list,plugin list,tool list,tool status,codeguard status) render every active connector where applicable. Use--connector Xon commands that expose it to narrow the view. - Mutating guardrail commands —
--connectormeans one connector.guardrail enable/disable/fail-mode/hilt/block-messagechange one connector when given--connector X. Omit it for the broad path: enable/disable is global, while fail-mode, HITL, and block-message reconcile active connector posture where supported. - Asset policy/config commands — default broad,
--connectorscoped.skill,mcp,plugin, andtoolpolicy verbs write broad fallback state by default and one connector's scoped state with--connector X. Config/install verbs such asmcp set,mcp unset,skill install,plugin remove, andcodeguard installoperate across configured/active connectors by default and narrow with--connector X. - Scan commands — default to configured/active connectors, narrow with flags.
skill scan --all,mcp scan --all,plugin scan --all, andaibom scancover configured/active connector sources by default; pass a positional target and--connector Xwhere supported to scope to one.
These list/inventory verbs read across the full active roster:
| Command | Default scope |
|---|---|
defenseclaw skill list [--connector X] | All active connectors by default; one connector when scoped. |
defenseclaw mcp list [--connector X] | All configured connector MCP sources by default; one connector when scoped. |
defenseclaw plugin list [--connector X] | All configured connector plugin sources by default; one connector when scoped. |
defenseclaw tool list/status [--connector X] | Effective tool policy for all active connectors by default; one connector when scoped. |
defenseclaw codeguard status [--connector X] | CodeGuard install state across active connectors by default; one connector when scoped. |
Audit & alerts
| Command | Use it for |
|---|---|
defenseclaw tui | Interactive Textual dashboard — audit, alerts, logs, inventory, and setup panels. The recommended live view. |
defenseclaw alerts [--connector X] | Snapshot of recent alerts (default 25) as a table. --connector X filters by per-event connector attribution; --limit N widens the scan window, and --show <n> prints the full record. |
defenseclaw alerts acknowledge / dismiss | Acknowledge or dismiss alerts (writes an audit_log_activity mutation). --severity all|CRITICAL|HIGH|MEDIUM|LOW. |
defenseclaw audit log-activity --payload-file <f> | Record a config/operator mutation through the gateway's audit logger. Used internally by the TUI on save. |
defenseclaw-gateway audit export | JSONL export of audit_events from the SQLite DB, including structured when structured_json is present. Rows are emitted oldest-first; --limit N returns the earliest N matching rows, and with --newest the most recent N (still written oldest-first). --since (inclusive) and --until (exclusive) take an RFC3339 time or a duration ago such as 30m or 2h. --connector keeps one connector's rows. --include-activity also dumps activity_events, within the same window. |
defenseclaw-gateway audit findings [--since RFC3339] [--new-only] [--include-resolved] [--scanner NAME] [--target PATH] [--limit N] | Report the deduplicated finding lifecycle. Active current findings are the default; --include-resolved adds resolved state, while --since selects lifecycle changes and --new-only narrows that window to fingerprints first observed since the timestamp. JSON reports both the total distinct count and the returned page. |
tail -f ~/.defenseclaw/gateway.jsonl | jq | Tail the optional v8 JSONL destination when configured at that path. Mandatory local history is SQLite; JSONL is not an implicit mirror. |
AI discovery
agent discover is the fast, gateway-independent connector inventory. The
continuous scanner is a separate sidecar surface and is the one that inventories
local model APIs, known model caches, and standalone model files.
Enhanced mode expands the bounded roots searched for models; it does not relax what qualifies as a model. Outside recognized model stores, ambiguous ONNX/ORT, TFLite, PyTorch/checkpoint, and generic binary artifacts require explicit model context plus a meaningful, non-opaque identity. Known Chrome Optimization Guide cache payloads and opaque hash/version identities are suppressed, while high-signal formats and recognized model stores retain their established behavior.
| Command | Use it for |
|---|---|
defenseclaw agent discover [--refresh] [--no-cache] [--json] [--emit-otel/--no-emit-otel] | Inspect known connector configs and binaries without requiring the gateway. This does not run the continuous local-model scan. |
defenseclaw agent discovery enable [--mode passive|enhanced] [--scan-roots ROOTS] [--include-network-domains/--no-include-network-domains] [--lookup-model-provenance-online/--no-lookup-model-provenance-online] [--restart/--no-restart] [--scan/--no-scan] | Enable and tune the sidecar scanner. passive limits model-file coverage to known stores plus narrower configured roots and suppresses an exact user-home/~ root; enhanced also honors the broad home root and adds bounded macOS application-storage and app-resource roots for unknown applications. Vetted loopback model API reads follow include_network_domains; filesystem model discovery runs independently. Public Hugging Face lineage lookup is a separate opt-in because it transmits recovered model repository IDs. |
defenseclaw agent discovery setup|status|scan|disable | Configure discovery interactively, inspect on-disk/live state, trigger a full scan, or disable the service. |
defenseclaw agent usage [--refresh] [--detail] [--state STATE] [--category CAT] [--product NAME] [--component NAME] [--show-gone] [--by-detector] [--json] | Read the sidecar snapshot. Local-model rows show model ID, installed/loaded status, and format; --component also matches model IDs. active remains an alias for the steady seen lifecycle state. JSON output is the unfiltered API payload. |
defenseclaw agent processes [--refresh] [--json] [--limit N] | List live AI process signals with PID, user, command name, and uptime. |
defenseclaw agent components [--refresh] [--json] [--ecosystem ECO] [--name NEEDLE] | Show the deduplicated package/SDK component rollup and confidence scores. |
defenseclaw agent usage --refresh --category local_model --detail
defenseclaw agent usage --component Qwen3
defenseclaw agent usage --state seen
defenseclaw agent usage --show-goneSee AI Discovery for supported model servers, standalone file formats, lifecycle behavior, and privacy boundaries.
Scanning
The Python CLI exposes one scan group per asset family — there is no top-level scan group. Code-scanning lives on the Go gateway binary.
| Command | Binary | Use it for |
|---|---|---|
defenseclaw skill scan [target] [--connector X] [--all] [--path] [--remote] [--action] | defenseclaw | Scan a configured skill, a path, a URL (https://… / clawhub://…), or every configured skill with --all. A bare skill name searches matching configured connector copies; --connector X narrows. --all --json always emits one top-level result array, including per-skill error rows, before returning nonzero for scanner failures; a telemetry-recording warning never discards or fails a completed scan. |
defenseclaw mcp scan [target] [--connector X] [--all] [--scan-prompts] [--scan-resources] [--scan-instructions] | defenseclaw | Scan one MCP server by name or URL, every configured server with --all, or every server on one connector with --connector X. |
defenseclaw plugin scan [name_or_path] [--all] [--connector X] [--profile default|strict] [--use-llm] [--include-self] | defenseclaw | Scan one plugin/extension package, or all discovered plugins with --all. --connector X narrows discovery or duplicate plugin names to one connector. Exact first-party DefenseClaw package/connector artifacts are excluded by default; --include-self opts into scanning them for product development. Ordinary third-party dist/ trees and plugins merely named defenseclaw remain in scope. |
defenseclaw aibom scan [--connector X] [--json] [--summary] [--only <cat>] | defenseclaw | Build the agent SBOM (skills, MCP, plugins, models, sinks) for every active connector by default, or one connector when scoped. |
defenseclaw registry sync [source...] [--all] [--scan] | defenseclaw | Sync registries; with --scan, runs the scanner pipeline against every fetched entry. |
defenseclaw codeguard {status,install,install-skill} [--connector X] | defenseclaw | Manage the CodeGuard skill/rule install across active connectors by default, or one connector when scoped. |
defenseclaw-gateway scan code <path> [--json] [--no-redact] [--schema] | defenseclaw-gateway | Scan source files in <path> using the bundled CodeGuard rule pack. The version-7 CLI schema preserves safe context in its declared location/line_number fields while replacing detected sensitive substrings; detached REST/API responses may additionally expose a structured file field. --no-redact is an explicit local-stdout-only opt-in, requires --json, and prints a warning; the REST API remains protected. Runs in-process and does not require the sidecar daemon. |
Plugin META-* findings are correlations over the atomic plugin findings that
remain after the active scan policy is applied. Disabled/suppressed rules,
low-confidence matches, documentation, examples, benchmarks, tests, and
fixtures cannot become correlation legs. Each emitted correlation carries the
atomic rule IDs, locations, and propagated confidence that produced it; its
severity never exceeds its strongest atomic input, and its title says
pattern (correlated, N signals) because static correlation is not proof that
the behavior executed.
Asset Policy Commands
These commands are connector-aware because the same asset name can exist in more than one connector source. Bare commands keep the broad fallback behavior; --connector X writes or reads the connector-scoped state.
| Command | Use it for |
|---|---|
defenseclaw skill block|allow|unblock|disable|enable|quarantine|restore|install <name> [--connector X] | Manage skill policy, runtime disablement, quarantine, restore, and install. Without --connector, matching configured connector copies are handled together or the unscoped fallback is written; --connector X targets one connector copy. |
defenseclaw mcp set|unset|block|allow|unblock <name> [--connector X] | Manage connector MCP config and MCP admission policy. mcp set / unset write every configured connector source by default; --connector X writes one connector's MCP source. |
defenseclaw plugin remove|block|allow|unblock|disable|enable|quarantine|restore|info <name> [--connector X] | Manage plugin policy and runtime/file actions across configured connector copies by default, or one connector when scoped. |
defenseclaw tool block|allow|unblock|list|status <name> [--connector X] | Manage tool-level block/allow policy. Bare rows are the fallback tier for every configured connector; connector-scoped rows use the runtime-enforceable @connector/tool key. |
Gateway daemon
The sidecar is the Go binary; the Python CLI does not own a gateway group. Most operators never run these directly — defenseclaw setup * commands restart the sidecar implicitly when --restart is passed.
| Command | Binary | Use it for |
|---|---|---|
defenseclaw-gateway start | defenseclaw-gateway | Start the sidecar as a background daemon. |
defenseclaw-gateway stop | defenseclaw-gateway | Stop the running sidecar. |
defenseclaw-gateway restart | defenseclaw-gateway | Restart the sidecar. |
defenseclaw-gateway status | defenseclaw-gateway | Health snapshot of the running daemon. On a multi-connector install it also renders a per-connector "Connector Mode" section (one row per active connector) sourced from the /status endpoint's connector_modes array. |
defenseclaw-gateway policy reload | defenseclaw-gateway | Re-read OPA policies from disk without bouncing the daemon. |
defenseclaw-gateway watchdog [start|stop|status] | defenseclaw-gateway | Health-watchdog daemon that notifies when the gateway is down. |
tail -f ~/.defenseclaw/gateway.jsonl | jq | shell | Tail a configured kind: jsonl destination. It contains only records selected for that destination; mandatory complete local log history remains SQLite. |
TUI
| Command | Use it for |
|---|---|
defenseclaw tui | Open the interactive operator UI for audit, alerts, logs, inventory, and settings. It does not provide a resumable approval queue for hook calls. |
Upgrade
| Command | Use it for |
|---|---|
defenseclaw upgrade [--version X] [--yes] | Download the latest (or the given) release's installer, check it against that release's checksums.txt, and run it. The installer keeps your configuration and data, migrates them, restarts the gateway, and restores the previous install if anything fails. See Upgrade DefenseClaw. |
defenseclaw rollback [--yes] | Swap the live install with the one the last upgrade replaced. Run it again to roll forward. |
defenseclaw migrate [--check] [--from-version X] [--json] | Bring configuration and data to this version's schema. The installer runs it on every upgrade; --check changes nothing. Exits 2 for a configuration written by a newer release. |
Uninstall / disable
| Command | Use it for |
|---|---|
defenseclaw setup guardrail --disable | Roll back guardrail. Connector files restored from backup. |
defenseclaw uninstall | Reversible by default — runs connector teardown, stops the sidecar, removes the OpenClaw plugin, leaves ~/.defenseclaw/ (audit DB, config, secrets) intact. |
defenseclaw uninstall --all | Same as above, plus deletes ~/.defenseclaw/. Add --binaries to also remove the defenseclaw and defenseclaw-gateway binaries from ~/.local/bin. |
defenseclaw uninstall --skip-sandbox-teardown | Uninstall without the OpenShell sandbox teardown it runs first (when Docker or OpenShell are gone or broken); defenseclaw sandbox teardown removes the sandboxes later. reset takes it too. |
defenseclaw reset --yes | Wipe ~/.defenseclaw/ so defenseclaw quickstart starts clean — keeps binaries and the OpenClaw plugin in place. |
Sandbox
Linux, and Apple-silicon Macs, where sandboxes are OpenShell MicroVMs that
work on a copy (see macOS). The sandbox
commands run coding agents in NVIDIA OpenShell 0.1 sandboxes. defenseclaw sandbox checks the command
line, then hands it unchanged to defenseclaw-gateway sandbox;
legacy-cleanup is the one command the Python CLI runs itself. Every command
and flag, with an example, is on Sandbox CLI;
see also Sandbox.
| Command | Use it for |
|---|---|
defenseclaw sandbox setup [--harness H]... [--wrappers] [--non-interactive] | One-time setup: checks the machine, installs OpenShell when you agree, enables project-folder mounts, records the harnesses, offers shell wrappers, and builds the harness images. |
defenseclaw sandbox doctor [--fix] [--output json] | Check that this machine can run sandboxes. defenseclaw doctor shows the same checks in its Sandbox section. |
defenseclaw sandbox run <harness> [--copy] [--safe] [--profile open|balanced|strict] [-- args] | Run a harness, such as claude or codex, in a new sandbox on the current folder. |
defenseclaw sandbox list|status|connect|exec|logs|stop|start|delete | Manage sandboxes and their sessions. |
defenseclaw sandbox activity [-f]|approvals|approve|reject|unblock | Follow the live activity feed, answer the rare asks, and lift egress blocks. |
defenseclaw sandbox review|undo|pull <name> | Review a mounted project's changes, restore its pre-session snapshot, or bring a copy-mode sandbox's work back. |
defenseclaw sandbox policy show|explain|suggest|allow|block | Show where each setting of the sandbox policy comes from, suggest an allowlist, and edit the egress lists. |
defenseclaw sandbox pack list|show|validate | Inspect sandbox policy packs and their digests. |
defenseclaw sandbox image build|list|prune|rm | Build, list, prune, and remove the harness images. |
defenseclaw sandbox enable|disable <harness> | Add or remove the shell wrapper that makes a harness command run sandboxed. |
defenseclaw sandbox teardown [--dry-run] | Remove DefenseClaw's sandboxes, providers, images, gateway change, and wrappers. defenseclaw uninstall runs it. |
defenseclaw sandbox legacy-cleanup [--dry-run] [--yes] [--remove-user] [--remove-binary] | Linux only. Remove a retired openshell-sandbox 0.0.x standalone install and restore host OpenClaw networking, ownership, and config. |
Enterprise
Commands for administrator-owned enterprise deployments. They are on the Go binary. Run them as root on Linux and macOS, and from an elevated prompt on Windows.
| OS | Binary |
|---|---|
| Linux | /opt/defenseclaw/bin/defenseclaw-gateway |
| macOS | /opt/cisco/defenseclaw/bin/defenseclaw-gateway |
| Windows | C:\Program Files\Cisco\DefenseClaw\bin\defenseclaw.exe (the same Go binary under another name) |
Standalone lifecycle on Linux and macOS
defenseclaw-gateway enterprise linux|macos <action> manages the standalone
deployment. Run linux on Linux and macos on macOS; the other one exits 2.
Every mutating action is a transaction that rolls back on failure. See
Upgrade, repair and remove.
| Action | Use it for |
|---|---|
install | Install the deployment. Refuses when one is already installed |
upgrade | Upgrade an installed deployment from a new payload or package |
repair | Re-apply the installed deployment's files, modes, and services |
ensure | Install, upgrade, or repair as needed. Does nothing when nothing changed |
reconcile | Run one immediate hook guardian reconcile |
rotate-credentials | Replace the key every user's per-user credentials derive from. Every user moves to the new key before it takes effect. See Rotate per-user credentials |
status | Report the deployment state. Read-only |
verify | Check every file, permission, service, and readiness item. Read-only; exits non-zero on any problem |
uninstall | Stop and remove the deployment. --purge also removes config and state |
| Flag | Actions | Meaning |
|---|---|---|
--payload <dir> | install, upgrade, repair, ensure | Absolute directory that holds the staged binaries. Cannot be combined with --from-package |
--from-package | install, upgrade, repair, ensure | Use the binaries the defenseclaw-enterprise package installed |
--config <file> | install, upgrade, repair, ensure | Absolute path of the administrator config to install |
--no-start | install, upgrade, repair, ensure | Install without starting the services. Run repair or ensure to start them |
--product-version <v> | install, upgrade, repair, ensure | Refuse unless the payload is exactly this version |
--allow-downgrade | install, upgrade, repair, ensure | Allow a payload older than the installed release (a deliberate rollback). Without it the lifecycle refuses with downgrade_refused |
--adopt-existing | install, ensure | Back up and take over an unmanaged DefenseClaw layout |
--reason <text> | ensure | Why ensure runs. Recorded in the result |
--lock-wait <duration> | install, upgrade, repair, reconcile, rotate-credentials, ensure, uninstall | Wait up to this long (default 5s, at most 15m) for another lifecycle run before exiting 75 |
--purge | uninstall | Also remove config, credentials, state, and logs |
--remove-service-account | uninstall | With --purge, also delete the gateway service account |
--json | all | Print the lifecycle result as JSON |
Exit codes: 0 success or no-op, 1 failure (already rolled back), 2
invalid arguments, 75 another lifecycle run holds the lock.
sudo /opt/defenseclaw/bin/defenseclaw-gateway enterprise linux ensure --from-package --config /root/defenseclaw-config.yaml --json
sudo /opt/defenseclaw/bin/defenseclaw-gateway enterprise linux verify --json
sudo /opt/cisco/defenseclaw/bin/defenseclaw-gateway enterprise macos uninstall --purge --jsonLifecycle on Windows
defenseclaw.exe enterprise windows <action> manages the Windows deployment
for both profiles. Run it from an elevated prompt. The standalone profile runs
its transaction on PowerShell 7, which must be installed.
| Action | Profiles | Use it for |
|---|---|---|
install, upgrade, repair | Secure Client, standalone | Install, upgrade, or re-apply the deployment |
ensure | Standalone only | Install, upgrade, or repair as needed. Refuses to downgrade (downgrade_refused) |
reconcile | Secure Client, standalone | Restart the guardian and wait for a fresh reconcile |
status, verify | Secure Client, standalone | Read-only state, and the full check |
uninstall | Secure Client, standalone | Remove the services. Keeps state unless --purge |
| Flag | Meaning |
|---|---|
--profile secure_client|standalone | The profile. Default: the supplied config's enterprise.profile, then the installed profile, then secure_client |
--config <file>, --manifest <file> | Administrator config and guardian target manifest (targets.yaml) |
--trust-mode authenticode|hash_pinned | Standalone payload trust. Default at the CLI: authenticode |
--payload-manifest <file> | Standalone hash_pinned trust anchor: an administrator-owned JSON file of payload SHA-256 digests |
--allowed-signer <sha256> | Standalone: the SHA-256 thumbprint of an accepted Authenticode signer certificate. Repeatable |
--product-version <v> | Standalone: the version recorded for the deployment. Default: this CLI's version |
--gateway-binary, --hook-binary, --acp-binary, --sensor-helper-binary, --cli-binary | Source binaries for install, upgrade, repair, and ensure |
--broker-binary | Secure Client only: the source credential broker |
--installer <file> | An explicit install-enterprise.ps1 |
--no-start | Install, upgrade, repair, ensure: stage the services disabled and stopped |
--purge | Uninstall: also remove managed state |
--attest-claude-effective-policy | Install, upgrade, repair: record that an administrator confirmed that Claude Code runs DefenseClaw's managed hooks |
--json | Print the result as JSON |
Exit codes: standalone 0, 1603 failure, 1618 busy, 1639 invalid
arguments, and 3010 (reserved). Secure Client: 0 and 1603.
$DefenseClaw = 'C:\Program Files\Cisco\DefenseClaw\bin\defenseclaw.exe'
& $DefenseClaw enterprise windows status --profile standalone --json
& $DefenseClaw enterprise windows verify --profile standalone --jsonStandalone Setup on Windows
DefenseClawSetup-Enterprise-Standalone-x64.exe wraps the standalone
lifecycle for MDMs. Its release asset
DefenseClawSetup-Enterprise-Standalone-x64.payload-manifest.json lists the
payload digests. DefenseClawSetup-Enterprise-x64.exe is the Secure Client
Setup. See Install with an MDM.
| Argument | Meaning |
|---|---|
/install, /upgrade, /repair, /reconcile, /status, /verify, /uninstall, /ensure | The action |
CONFIG=<file> | Absolute path of the config. A first /ensure needs it and exits 1639 without it |
MANIFEST=<file> | Absolute path of a guardian target manifest. /install needs both CONFIG= and MANIFEST=; /ensure prepares a manifest from the config |
ALLOWEDSIGNERS=<sha256>,<sha256> | Accepted Authenticode signer thumbprints, comma-separated |
JSON=1, NOSTART=1, PURGE=1 | Print JSON, stage without starting, remove state on uninstall |
TIMEOUTSECONDS=<n> | Lifecycle timeout, from 60 to 7200 seconds. Default 1800 |
/quiet, /norestart | Accepted and ignored |
Property names are case-insensitive, and dashes in them are ignored. Paths
must be absolute: Setup refuses relative paths and paths that contain %.
The unsigned (hash-pinned) Setup writes its payload trust file itself from its embedded manifest; a signed Setup uses Authenticode trust, optionally pinned with ALLOWEDSIGNERS=. Setup's own argument errors, such as an unknown property, a missing, relative or environment-expanded CONFIG= or MANIFEST= path, /install without CONFIG= and MANIFEST=, or a TIMEOUTSECONDS out of range, exit 1639. A token that is not elevated, or a CONFIG= or MANIFEST= file a non-administrator can change, exits 1603. The Secure Client Setup returns only 0 and 1603.
Machine policy (enterprise policy)
These commands inspect DefenseClaw's entries in vendor machine policy. They never write machine policy; the lifecycle does. See Machine policy.
| Command | Use it for |
|---|---|
defenseclaw-gateway enterprise policy show | Show each connector's route, lock, and coverage. --connector X limits it to one connector, --user NAME also checks that user's agent config, and --project DIR (with --user) also scans a project directory for foreign hooks |
defenseclaw-gateway enterprise policy export --connector X | Print DefenseClaw's entries for your own policy tool. --format: codex takes toml or plist; claudecode takes json, claude-hklm-json, reg, plist, intune-settings-catalog, or version-floor (the version floor drop-in); cursor, copilot, and opencode take json. The default is the connector's native file |
defenseclaw-gateway enterprise policy verify | Verify coverage. Exits 1 when it is incomplete. Takes the same --connector and --user flags. --live also runs the real client as the user; it needs --user, one --connector (codex or claudecode), and --agent-binary with an absolute path. --audit-db (the gateway audit database searched for the Claude Code check's tool call; default: the configured audit_db) and --timeout (default 90s) tune the live check |
All three take --json. On this release, set DEFENSECLAW_CONFIG to the
managed config path when you run them. Otherwise they read the calling user's
~/.defenseclaw/config.yaml and refuse.
sudo DEFENSECLAW_CONFIG=/etc/defenseclaw/config.yaml /opt/defenseclaw/bin/defenseclaw-gateway enterprise policy show --json
sudo DEFENSECLAW_CONFIG=/opt/cisco/defenseclaw/etc/config.yaml /opt/cisco/defenseclaw/bin/defenseclaw-gateway enterprise policy export --connector claudecode --format plistProtected credentials (enterprise secret)
| Command | Use it for |
|---|---|
defenseclaw-gateway enterprise secret set --name N | Store a credential. Pass exactly one of --from-stdin or --from-file F. The value is never printed |
defenseclaw-gateway enterprise secret status | List stored credentials with a digest prefix and modification time, never the value |
defenseclaw-gateway enterprise secret remove --name N | Remove a credential |
Names use lowercase letters, digits, and dashes. Every action takes --json.
| Linux and macOS | Windows | |
|---|---|---|
After set or remove | Runs ensure. set refuses before writing when the service account does not exist (nothing installed) | Restarts the gateway |
| Requirements | root for set and remove | An elevated prompt. set and remove also need an installed standalone deployment |
| Exit codes | 0, 1, 2, and 75 when the ensure it runs finds the lock held | 0, 1603, 1639 (invalid input) |
Install first, then store the key. See AI Defense key.
Per-user hooks (enterprise hooks)
The guardian and the enumerator services run these commands. Administrators
normally need only the lifecycle status and verify, which include the
guardian's health.
| Command | Who runs it | Use it for |
|---|---|---|
defenseclaw-gateway enterprise hooks status | Administrator | Read-only: the last guardian reconcile and the authorization ledger |
defenseclaw-gateway enterprise hooks verify | Administrator | Read-only: verify every enabled target in the manifest without repairing it |
defenseclaw-gateway enterprise hooks watch | Guardian service | Watch the manifest's targets and repair them, with a periodic reconcile (--interval, default 1m) |
defenseclaw-gateway enterprise hooks reconcile | Guardian and lifecycle | Install or repair every enabled target once |
defenseclaw-gateway enterprise hooks install, uninstall | Root or a guardian on Linux and macOS; only the guardian on Windows | Install, repair, or remove one user's hook registration |
defenseclaw-gateway enterprise hooks enumerate | Enumerator service (Linux, macOS) | Publish the target manifest. The Windows enumerator service runs defenseclaw-gateway.exe enterprise windows enumerate |
defenseclaw-gateway enterprise hooks scrub | Uninstall scripts, or an administrator | Remove DefenseClaw's entries from one user's agent hook file (--connector, --file) |
remove-all and apply-target are hidden internal commands that the
lifecycle and the guardian use. The hooks commands read the managed config
and the ledger directory from the service environment
(DEFENSECLAW_CONFIG, DEFENSECLAW_HOOK_GUARDIAN_AUTH_DIR). To run status
or verify yourself, use the same values as the guardian's unit or plist,
and pass --manifest on macOS (/opt/cisco/defenseclaw/etc/hook-guardian/targets.yaml).
ACP credentials (enterprise acp)
defenseclaw-gateway enterprise acp enroll|verify|revoke manages the
protected ACP credential for one user, client, agent, and profile. See
ACP guard.
Discoverability
defenseclaw --help
defenseclaw setup --help
defenseclaw setup guardrail --help
defenseclaw audit --helpEvery command tree responds to --help. The CLI prints all flags, defaults, and a one-line description for each.
Reference
Lightweight reference index. CLI command index, gateway API surface, configuration files, and environment variables. Authoritative source for CLI flags is `defenseclaw <command> --help`.
Sandbox CLI
Every defenseclaw sandbox command and flag for NVIDIA OpenShell sandboxes, with an example for each. Covers setup and doctor, run and connect, the activity feed and asks, undo, review and pull, policy and packs, images, wrappers, and teardown.