PowerShell · Windows-Native · Tool Registry Safety

PowerClaw

Built for Windows power users, solo operators, and technical builders who want machine answers without unrestricted shell generation.
Describe the issue. PowerClaw previews or runs an approved tool chain, then returns an operator-style answer.

Get Started See Top Workflows
⚡ Windows PowerShell
−
□
✕
PS C:\Users\Chris\PowerClaw> powerclaw "Give me a full system health check"

PowerClaw v0.2.0
Prompt: Give me a full system health check

[PowerClaw] Registered 15 tools: Search-LocalKnowledge, Get-EventLogEntries, Get-NetworkStatus...

[Step 1/8]
[Executing] Get-NetworkStatus
[Step 2/8]
[Executing] Get-StorageStatus
[Step 3/8]
[Executing] Get-EventLogEntries
[Step 4/8]

[Answer]

Your system is healthy. Drive C: is 76% full (57 GB free). External
IP: 98.x.x.x. No critical errors in the last 24h — only a routine
TPM warning and a stopped Everything service (auto-start, non-critical).
Network adapter running at 585 Mbps on ethernet.

PS C:\Users\Chris\PowerClaw> █

# Why

Not another shell wrapper

PowerClaw is for Windows operators who want faster machine diagnosis and cleanup without handing a model free-form command execution.

Constrained execution

The model chooses tools, not raw PowerShell. The system only executes actions you already defined and approved through the tool registry.

Windows-native leverage

This is meant to feel better on Windows than generic agents do. Event logs, services, Windows Search, local diagnostics, and filesystem workflows are core product value.

Human remains in control

PowerClaw is optimized for inspectable automation. Preview a short intended tool chain with -Plan, block writes with -DryRun, require confirmation for destructive tools, and inspect the results.


# Design

How it works

The design is intentionally narrow: useful Windows operations, strong safety boundaries, and a fast path to a first real result.

🗂️

Tool registry, not command generation

The model picks from a known, approved list of tools. It never writes raw PowerShell. The blast radius of any action is defined at design time, not at query time.

🔒

Discovery is not trust

Tools are auto-discovered from disk but only tools explicitly listed in tools-manifest.json become executable. Everything else is ignored.

👁️

Write ops require confirmation

Any tool marked Write risk pauses, shows you the arguments, and requires a typed confirmation token before executing.

🪟

Windows-first

COM, WMI, Task Scheduler, Windows Search index, native Office object models. Not a Linux tool ported to Windows.

🔍

Every run is inspectable

Plans, tool requests, outcomes, final answers, and errors are logged as structured append-only entries. Use -Verbose to see the full request/response JSON. Use -Plan to preview without running.

🧩

Drop-in tools

Add a .ps1 file to tools/ with .CLAW_* metadata and add it to the manifest. No core changes needed.

Core vs optional: the default registered set is the portable product surface. Personal tools can live in the repo without becoming part of the default onboarding path.

# Tools

Selected tools in the workbench

The default workbench covers machine health, files, networking, local reads, and local knowledge search. Personal overlays stay outside the default onboarding path.

ReadOnly

Get-SystemSummary

CPU load, RAM usage, uptime, top processes by CPU and memory.

SystemInfo
ReadOnly

Get-TopProcesses

Processes sorted by CPU or memory usage with configurable count.

SystemInfo
ReadOnly

Get-EventLogEntries

Query System, Application, or Security event logs for errors and warnings.

SystemInfo
ReadOnly

Get-ServiceStatus

Check Windows services — running, stopped, or failed auto-start services.

SystemInfo
ReadOnly

Get-NetworkStatus

Active interfaces, TCP connections, DNS servers, external IP.

Network
ReadOnly

Get-NetworkUsage

Per-process and connection-level network usage to spot who is talking and how much.

Network
ReadOnly

Get-StorageStatus

Disk usage across all drives, largest folders by size.

SystemInfo
ReadOnly

Search-Files

Windows Search index queries — by name, kind, size, date. Much faster than disk scan.

Filesystem
ReadOnly

Get-DirectoryListing

List files and folders in a directory with optional filtering.

Filesystem
ReadOnly

Read-FileContent

Read any file and let the model reason about it — logs, configs, scripts, journals.

Filesystem
ReadOnly

Search-LocalKnowledge

Search configured local knowledge directories for notes, docs, journals, and other text files. Defaults to Documents.

Filesystem
Write

Remove-Files

Delete specific full-path files. Sends to Recycle Bin by default, requires confirmation, blocks protected system locations, and limits batch/permanent delete scope.

Filesystem
Optional later add-on: Fetch-WebPage stays in the repo, but it is opt-in in the manifest, requires a one-time Playwright browser setup, and is meant as a secondary evidence source after local machine evidence. Machine-specific note-search tools still live under overlays\personal\ instead of the main portable tool directory.

# Setup

Get started

Requires PowerShell 7+. You can start in demo mode with -UseStub, or configure an Anthropic or OpenAI API key for live runs. Webpage lookup stays out of the default path and is only a later add-on.

1

Clone the repo

# Clone and enter the directory
git clone https://github.com/spinchange/PowerClaw.git
cd PowerClaw
2

Copy a starter config

Copy-Item .\config.example.json .\config.json

# Or start from a provider-specific template
Copy-Item .\config.claude.example.json .\config.json
# or
Copy-Item .\config.openai.example.json .\config.json
3

Optional fast first win: demo mode

Import-Module .\PowerClaw.psd1
powerclaw -UseStub "What's eating my CPU?"
powerclaw -UseStub "Find the 10 biggest files in Downloads"
4

Set your API key

# Set for this session
$env:CLAUDE_API_KEY = 'sk-ant-...'

# Or set provider=openai in config.json
# and point api_key_env at OPENAI_API_KEY
5

Import the module

Import-Module .\PowerClaw.psd1
6

Validate setup

Test-PowerClawSetup
7

Run first prompts

powerclaw "What's eating my CPU?"
powerclaw "Read config.json and explain my settings"
powerclaw "Search my notes for PowerClaw setup decisions"
8

Optional later add-on: enable webpage lookup

# Only if local machine evidence is not enough:
# add Fetch-WebPage to approved_tools, then install its runtime
pwsh -File .\Install-PowerClawWebRuntime.ps1
9

Optional: install a real shell command

pwsh -File .\Install-PowerClaw.ps1 `
  -ModuleRoot C:\dev\powershell-modules `
  -BinRoot C:\dev\bin

The installer copies the example configs and seeds config.json in the installed module directory if needed.


# Trust

What keeps it safe

PowerClaw is trying to be useful without asking you to trust a model with unconstrained shell access.

Approved tools only

Only tools in tools-manifest.json can register. Discovery from disk is not enough to make a tool executable.

Write confirmation

Write-risk tools pause and show arguments before execution. You must type the confirmation token to allow the operation.

Write intent gate

Write tools are blocked unless the user goal explicitly asks for a destructive change. Advisory prompts stay read-only until the user asks to act.

Path policy

Remove-Files accepts only fully qualified file paths, blocks deletes from Windows, System, Program Files, and ProgramData locations, caps delete batches by default, and limits permanent delete to one file per call.

Preview mode

-Plan shows a short intended tool chain before execution. Health checks and cleanup prompts can preview multiple planned steps instead of only the first tool.

Demo mode and logs

-UseStub is the explicit no-key demo path for the flagship workflows, and each run remains inspectable for debugging and review.


# Workflows

Start with these three

PowerClaw can grow beyond these, but the default product story is strongest when it starts with the highest-value Windows workflows.

1. Machine triage

Use PowerClaw when your machine feels wrong and you want a fast, inspectable answer. Ask about CPU pressure, memory load, service failures, reboot timing, network state, and recent event log issues. The goal is one operator summary, not a pile of tool output.

powerclaw "Give me a full system health check"

2. File and storage cleanup

Use PowerClaw to find the junk before you remove it. Search indexed files, inspect directory contents, identify large or stale items, then get a review-oriented answer about what looks worth checking before anything destructive happens.

powerclaw -Plan "Find the 10 biggest files in Downloads"

3. Read and investigate local evidence

Use PowerClaw when the answer sits across a config, log, note, or local document set. Inspect local files, search configured knowledge directories, and pull supporting evidence into the machine diagnosis when it materially changes the answer. Web fetch remains available only as a later opt-in source when the local machine evidence is not enough.

powerclaw "Read config.json and explain my settings"
Useful flags: -Plan previews a short chain, -DryRun skips write tools, -Verbose exposes raw API traffic, and -UseStub runs an explicit demo path without an API key.