- Any write outside the temp directory: output redirects (`> file`), the file and tree mutators (`del`/`erase`/`rd`/`md`/`move`/`ren`/`replace`/`mklink`, with `copy`/`xcopy`/`robocopy` gated on the destination only), and the package managers the guard names (`npm`, `pip`, ...). Redirecting to `NUL` is allowed, and `%TMP%`/`%TEMP%` always mean that same daemon temp root.
- Spellings cmd.exe reads differently from the shell parser this guard parses are rejected: double-quote a temp path that carries a space (`del /f /q "C:\…\junk.txt"` — cmd splits an unquoted operand), name every path you write to absolutely (a relative operand never satisfies the temp gate: cmd resolves it against a directory this guard does not model, and a `cd` elsewhere in the line is not tracked), keep a caret or `!NAME!` out of an operand, space a switch from its operand (a switch glued to one by cmd's `,`/`=` parameter delimiter — `del /f,x` — is refused). `set TEMP=…` is refused.
- Wrapping the command in another interpreter or launcher is not chased and is admitted (the command interpreter itself with `/c`, PowerShell, the other launchers). Command shapes cmd.exe accepts but this guard's parser cannot read (`if exist x ( … )`, `for` loops) stay refused. A command word spelled through a variable (`%DEL%`) or a caret (`d^el`), and a name decorated with a trailing dot (`del.`), match no table and pass; so does a word that escapes a separator or a redirect character, unless the guard reads that word as a path operand of a verb it knows — then it is refused (`del %TEMP%\a\&b.txt`).
- `PATHEXT` decides which extensions a bare name may carry and `ComSpec` which interpreter a nested command gets; `HOME`/`%TMP%`/`%TEMP%` are the values the product pins.