← Back to all Flat Fee outputs

Read-only local campaign artifact

COMMAND-EVIDENCE.md

direct-local-ops-wave-6/COMMAND-EVIDENCE.md

# Safe command evidence

Run at `2026-08-12T04:19:52Z` from `F:\Projects\mdai`. Commands were read-only. No remote connection, credential lookup, configuration read, policy change, service change, network fetch, or repository mutation occurred.

| Check | Actual outcome |
| --- | --- |
| Defender status | Normal mode, antivirus and real-time protection enabled. |
| Firewall profiles | Domain, Private, and Public profiles enabled; default inbound action is Block for all three. |
| Selected services | RemoteRegistry stopped and disabled; WinRM stopped and manual. Fax is not installed. |
| Listener review | A read-only listener inventory was collected. No ports were opened, closed, or remediated. |
| Git integrity | `git status`, history, branch/remote, reflog, and `git fsck --no-reflogs --no-dangling` ran. `git fsck` returned success. The working tree is intentionally dirty due to active campaign work. |
| Fleet parser | Offline documented mock asserted an online Windows host, an offline host, and a missing host. It printed `fleet-infra offline self-test OK`. |
| OpenClaw capability | `openclaw` command was not found. The local `.openclaw` directory exists, but `openclaw.json` was absent and was not read. |

## Deliberate limits

The skill contracts require authority and target selection for any hardening or live fleet work. This wave did not alter Windows firewall or services, run `tailscale status`, access an OpenClaw configuration, contact a remote machine, inspect credentials, or fetch Git remotes.