Explaining the working principles of a Windows right-click menu editing tool that runs on a single PowerShell script

PowerShellカテゴリを表すパンダのイラスト PowerShell

About this article
This article was created using an automated generation workflow powered by generative AI. Although organized based on reference information, it has not been verified on actual hardware by the author.

Verification status: unverified (not tested on physical hardware)

The Windows File Explorer right-click menu consists of a mixed architecture of registry commands, COM shell extensions, and Windows 11 packaged apps. "ROCI's Context Menu Editor" is a portable tool designed to centrally manage these without external dependencies, using only a single PowerShell script and a WPF UI.

The three-tier structure of the Windows context menu and how disabling works

The Explorer context menu is not built from a single registry key, but is dynamically constructed from three distinct information sources with different historical backgrounds. According to primary sources, the tool consolidates these into a single list and applies disabling actions tailored to the characteristics of each.

KindStorage locationDisabling behavior
CommandHKCU/HKLM\Software\Classes\<class>\shell\<verb>Add LegacyDisable value under verb (does not delete the key itself)
Shell extension<class>\shellex\ContextMenuHandlers (7-Zip, PowerToys, etc.)Register CLSID to Shell Extensions\Blocked
Windows 11 menuPackaged apps declaring windows.fileExplorerContextMenusRegister CLSID to Shell Extensions\Blocked

Rather than deleting the key, Command-format items are hidden without losing the original configuration by setting LegacyDisable. On the other hand, shell extensions that load DLLs and Windows 11-specific packaged app menus are prevented from loading by adding the respective extension CLSIDs to the per-user blocklist.

flowchart TD
    A[右クリックメニュー項目] --> B{項目の種類}
    B -->|Command| C[レジストリのverbキー]
    B -->|Shell extension| D[ContextMenuHandlersのCLSID]
    B -->|Windows 11 menu| E[パッケージアプリのCLSID]
    C --> F[無効化: LegacyDisable値を付与]
    D --> G[無効化: Shell Extensions/Blockedに追加]
    E --> G

Additionally, the sidebar allows filtering based on the target display location (files, folders, folder backgrounds, desktop, drives, and individual file extensions). When extracting individual extensions, SystemFileAssociations\.ext, the extension's ProgID, PerceivedType, and the default application's ProgID are combined to identify the menu structure.

Main Features and Operation System of ROCI's Context Menu Editor

The tool goes beyond simple on/off toggling, covering practical maintenance functions such as editing items and cleaning up broken items.

  • Adding and Editing Commands: You can specify the name, execution command line (using %1 to represent the target path and %V to represent the folder), icon, display position, setting to show only when the Shift key is pressed, and the presence of the UAC shield icon.

  • Submenu Grouping: SubCommands="" and nested shell keys adopt a static formatting approach, completing operations such as creating hierarchies or moving between levels at the registry editing level.

  • Detection of Broken Entries: Lists items whose referenced programs or DLLs do not exist, as well as unregistered handler CLSIDs, allowing them to be removed in bulk (Remove all). To prevent false positives, only absolute paths are validated, and wt.exe such as standalone command names, UNC paths, and Store app folders are excluded from validation.

  • Management of New Menus: Manages extensions under the ShellNew key. When disabled, the key is renamed to _ShellNew to remove it from Windows recognition, and restored when enabled.

  • Bulk Operations and Testing: You can select multiple rows to execute bulk toggles or deletions. Additionally, clicking the "Test" button in the edit screen allows you to run tests on specified files or folders with %1 or %V expanded.

Send To Integration and Windows 11 Packaged App Support

In addition to managing shortcuts in the "Send To" folder, it includes a feature to convert standard right-click context menu items into Send To items.

Conversion of Standard Commands

Commands that pass the file path at the end of the arguments (e.g., app.exe -x "%1") are registered in Send To as shortcuts excluding the trailing argument. This is because the Windows Send To feature automatically appends the selected file path to the end. For commands where the argument position is not at the end, a message is displayed indicating that conversion is not possible.

COM Bridge for Windows 11-Specific Items

Windows 11-style context menu items do not have a command line; the COM handler is invoked directly from Explorer. To call this from Send To, the tool compiles and places a small executable (CmeSendTo.exe under %LOCALAPPDATA%\ContextMenuEditor) from embedded C# code upon initial use. Shortcuts call the original COM handler via this bridge.

Implementation Strategy for Backups and Registry Operations to Ensure Safety

In tools involving registry edits, designs are implemented throughout to prevent system corruption.

  1. Automatic Differential Backup: Before executing edits or deletions, the target key is automatically exported as Backups\<timestamp>_<name>.reg. Undo can be invoked from the status bar to revert the immediately preceding operation.

  2. Permission Management Based on Scope: Items for HKCU (Current User) can be modified without administrator privileges. When modifying items for HKLM (All Users), you are prompted to restart the tool as an administrator.

  3. Direct utilization of the .NET Registry API: Standard PowerShell registry providers (Get-Item and Set-ItemProperty) have an issue where they misinterpret *\shell included in paths like * as wildcards. To prevent this, the .NET Microsoft.Win32.Registry API is used directly for all operations.

Architecture and single-file compilation structure

Although distributed as a single ContextMenuEditor.ps1, the source repository splits files by feature to maintain maintainability.

  • scripts/header.ps1: Help blocks and argument definitions (param())

  • scripts/start.ps1: Assembly loading, native type definitions, and constant definitions

  • functions/core/*.ps1: UI-independent logic such as registry scanning, Send To processing, and the Tweaks engine

  • functions/ui/*.ps1: WPF dialogs, views, undo management, and command editing screens

  • scripts/main.ps1: Window construction and event handler binding

  • xaml/*.xaml: UI screen definitions

  • native/*.cs: Win32 interop code and Send To bridge (C#)

  • config/*.json: Tweak definitions (registry values, detection scripts, rollback processing, etc.)

These are combined into a single script by a Compile.ps1 script with validation. During output, it keeps without BOM (maintaining compatibility with PowerShell 5.1 and 7) and supports irm | iex execution securely.

Calling from scripts utilizing LibraryOnly

To allow scripts to utilize only backend processing without launching the UI, a -LibraryOnly switch is provided. This allows scan results to be retrieved as objects from CI or terminal scripts.

Examples of calls depending on the execution environment are as follows.

# 保存名: inspect_menu.ps1
# 実行前提: ContextMenuEditor.ps1 と同じディレクトリで実行すること
# 期待できる確認内容: GUIを表示せずに非標準の右クリックメニュー項目一覧を取得する

. .\ContextMenuEditor.ps1 -LibraryOnly

# スキャンを実行
Invoke-Scan

# Windows標準機能以外の項目を抽出して表示
$App.Items | Where-Object { -not $_.IsBuiltIn } | Format-Table Kind, Hive, Name, LocLabel, Enabled

Although execution results on an actual device have not been verified, primary documentation states that this command outputs a group of objects with properties such as Kind, Hive, Name, LocLabel, and Enabled.

Usage Precautions and Boundary Conditions

During operation, it is necessary to understand the following constraints and operational specifications resulting from the tool's design philosophy.

  • Explorer Restart: Shell extensions and certain registry modifications are not reflected immediately and require restarting the Explorer process (it is stated that this can be restarted from the tool's status bar).

  • Judgment Boundaries for Broken Entries: Detection of missing paths targets absolute paths only. Executable file names and Store app paths that depend on the PATH environment variable are skipped from validation to prevent false positives.

  • ProgID Constraints for the New Menu: When adding an extension to the New menu, registration is rejected if no ProgID associated with the target extension exists.

  • Scope of Export/Import: Configuration export (.reg output) targets only user-specific (HKCU) settings, and program-specific entries for all users (HKLM) are excluded.

Conclusion

ROCI's Context Menu Editor is a portable utility that allows you to organize complex Windows context menu structures using only PowerShell and WPF.

The key points to verify before deploying to a production environment are as follows:

  • Whether administrator privileges are required depends on whether the modification target is HKCU (current user) or HKLM (all machines).

  • Non-destructive control is performed using LegacyDisable or Shell Extensions\Blocked rather than simple deletion.

  • Backups created when running the script standalone are saved in the Backups folder located in the same directory as the executable.

  • You need to verify whether automatically generated bridge functions such as CmeSendTo.exe violate the environment's security policies.

References

  • A Windows context menu editor in one PowerShell file: https://github.com/RoeeIlouz/ROCIsContextMenu-Editor

  • A Windows context menu editor in one PowerShell file (DEV Community): https://dev.to/rocisapps/a-windows-context-menu-editor-in-one-powershell-file-2mc

この記事の更新履歴

この記事は、生成AIを活用した自動レビュー・更新フローにより内容を見直し、必要な修正を反映しています。

2026年10月6日

  • 変更Fix broken heading tags and list formatting where HTML and markdown artifacts were leaked.
  • 変更Correct the table layout and unescaped characters in the Windows context menu three-tier structure description.

Document information

Article title
Explaining the working principles of a Windows right-click menu editing tool that runs on a single PowerShell script
Published
Updated
Source
https://papanda925.com/?p=17846&lang=en

License: Text and original figures for which this site holds the relevant rights are available under CC BY 4.0 , unless otherwise noted. This article may include content created or edited with generative AI. If code has a separate license notice or a linked GitHub repository license, that license takes precedence for the code. Quotations, third-party materials, images, and trademarks are excluded from this license. Usage policy

Copied title and URL