- Any write outside the temp directory: output redirects (`> file`), in-place editors (`sed -i`, `awk -i inplace`), `dd of=`, the file and tree mutators (`tee`/`touch`/`cp`/`mv`/`rm`/`mkdir`) against paths outside it, and package managers (`npm`, `pip`, `brew`, ...). Redirecting to `/dev/null` is allowed; the temp location is also `$TMPDIR`, and a scratch directory can be bound with `NAME=$(mktemp -d -p "$TMPDIR")` and referenced as `$NAME` (a bare `mktemp -d` on macOS ignores TMPDIR and lands elsewhere, still inside the allowed temp roots).
- Unprovable command words: a variable can stand for the command name only when it is bound to a plain literal earlier in the same invocation (`BIN=cargo; "$BIN" --list` passes). Substitution-derived bindings (`BIN=$(which cargo)`), transitive chains (`X=rm; Y="$X"`), and unbound variables are rejected — write the command name literally instead.
- Wrapping the command in another interpreter is not chased (`sh -c "…"`, `bash -c …`).
- Command names are matched case-sensitively: a destructive verb written in a different case is not recognised as one, though on a case-insensitive filesystem such a spelling still resolves.
- What an approved program *starts with* is the loader's: `LD_PRELOAD`/`LD_LIBRARY_PATH` (macOS: `DYLD_INSERT_LIBRARIES`/`DYLD_LIBRARY_PATH`); `$TMPDIR`/`$HOME` are the values the product pins.