█

AI/TLDR

OpenShell

NVIDIA's open-source, policy-enforced sandbox runtime for fleets of autonomous AI agents

Code Sandboxes & IsolationOpen source
Updated
28 Sep 2026
Language
Rust
License
Apache-2.0
Coverage
1 story

What's new

28 Sep 2026

NVIDIA makes OpenShell the CPU-side runtime of its new Open Agent Safety Platform, pairing it with NVIDIA Sentry, a watchdog on BlueField-4 DPUs that monitors agents out of band and quarantines ones that leave their policy boundary.

Latest news

Overview

OpenShell is NVIDIA's open-source answer to a trade-off every agent builder hits: agents are most useful when they can read files, install packages, call APIs and use credentials, and that same access is what makes them risky. The project describes itself as "the safe, private runtime for fleets of autonomous AI agents": you declare what each agent can touch in a policy, and OpenShell enforces it.

OpenShell system architecture: CLI, SDK and TUI talk to a gateway control plane with API server, policy prover, durable state and compute driver, which fences a sandboxed agent whose traffic goes through a supervisor to external services and models, plus the propose-check-approve-reload policy lifecycle
The gateway is the control plane; the supervisor governs the untrusted agent, and new access flows through a propose, prove, approve, reload loopOpenShell docs ↗

Enforcement happens in two ways. At runtime OpenShell instruments the kernel to apply policy to every file access, system call and network connection. Before a policy change is applied, a policy prover running in the gateway uses formal verification to check what the change would allow, flagging things such as new credentialed reach, new HTTP methods or access to cloud metadata endpoints.

The architecture splits into a sandbox that lives inside the boundary with the agent, owning its processes and forwarding TCP and DNS traffic; a supervisor on the trusted side that checks requests against policy, supplies credentials, resolves DNS and opens approved connections; a gateway that handles identity, stores sandbox state, delivers policy and attaches providers; and a compute runtime that creates the sandbox and builds its network fence. The agent itself is treated as an untrusted workload whose only allowed egress is to the supervisor.

Protection is layered: filesystem rules block reads and writes outside allowed paths and are locked at sandbox creation, network rules block unauthorized outbound connections and can be hot-reloaded at runtime, process rules block privilege escalation and dangerous syscalls, and provider credentials are opaque placeholders resolved only at profile-authorized endpoints. OpenShell runs on Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), with Docker, Podman or host virtualization, and is written in Rust under the Apache-2.0 license. NVIDIA's NemoClaw reference stack runs its supported agents inside OpenShell sandboxes.

What it does

  • Kernel-level enforcement of policy on every file access, system call and network connection
  • Formal verification of agent-proposed network rules before they are applied
OpenShell sandbox enforcement path: an agent process inside a network-isolated sandbox sends requests over the sandbox protocol to an isolation backend and policy enforcement in the trusted supervisor, which alone connects to the upstream service while all other egress is denied
Every request leaves the sandbox through one channel, where the supervisor checks destination, binary, L7 rules and credentialsOpenShell docs ↗
  • Filesystem and process rules locked at sandbox creation; network rules hot-reloadable at runtime
  • Credentials handed to agents as opaque placeholders, resolved only at profile-authorized endpoints
  • Agents propose new access; you approve or reject each rule from the host
  • Gateway control plane with CLI, SDK and TUI front ends
  • SDKs for Python, TypeScript, Go and Rust
  • Runs on Linux, macOS on Apple Silicon and Windows with WSL 2 (experimental)

Getting started

The installer sets up the openshell CLI and a local gateway. You need Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman or host virtualization. The steps below follow the README quickstart and the docs' run-your-first-agent guide.

Install and create a sandbox

Run the installer, then create your first sandbox.

bashbash
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demo

Add a model provider

Set OPENROUTER_API_KEY first, then import the provider profile and create a provider from the existing key. The agent never sees the raw key.

bashbash
openshell profile import \
  --url https://raw.githubusercontent.com/NVIDIA/OpenShell/main/providers/openrouter.yaml

openshell provider create \
  --name openrouter \
  --type openrouter \
  --from-existing

Run an agent in a sandbox

Create the sandbox, attach the provider and pass the agent command. This example runs OpenCode from its container image.

bashbash
openshell sandbox create \
  --name my-agent \
  --from ghcr.io/anomalyco/opencode:latest \
  --provider openrouter \
  -- opencode -m openrouter/nvidia/nemotron-3.5-lightning:free

Review the access the agent asks for

When the agent needs access its policy does not grant, it proposes a rule. List pending proposals from the host, then approve the ones that match the access you intend to grant and reject the rest.

bashbash
openshell rule get my-agent --status pending

openshell rule approve my-agent --chunk-id <chunk-id>

openshell rule reject my-agent \
  --chunk-id <chunk-id> \
  --reason "Not needed for this task."

Optional: skills and telemetry

Install the public OpenShell skills for your coding agent. OpenShell collects anonymous operational telemetry by default; set the environment variable below to turn it off.

bashbash
npx skills add NVIDIA/OpenShell
export OPENSHELL_TELEMETRY_ENABLED=false

Commands and code are distilled from the project's own documentation — always check the official repo for the latest.

When to use it

  • Reach for it when an autonomous coding agent needs a shell, packages and API keys but must not reach the rest of your machine or network
  • Reach for it when you want to review and approve each new network destination an agent asks for, with a prover flagging risky changes
  • Reach for it when agents need credentials without ever holding the raw secrets
  • Reach for it when running a fleet of agents behind one gateway that stores their policies, providers and settings

How OpenShell compares

OpenShell alongside other open-source code sandboxes & isolation tools AI/TLDR tracks, ranked by GitHub stars.

ToolStarsWhat it does
Daytona★ 71.7kDaytona is an open-source runtime that spins up isolated sandboxes in under 90ms so agents can safely run and persist AI-generated code.
NVIDIA NemoClaw★ 22.6kNVIDIA's reference stack for running OpenClaw, Hermes and LangChain Deep Agents Code inside OpenShell sandboxes, adding managed inference, network policy, snapshots and CLI lifecycle control.
OpenSandbox★ 15.6kOpenSandbox gives AI agents a safe place to run code and commands, with one unified API across Docker and Kubernetes runtimes and SDKs in five languages.
E2B★ 14kE2B is open-source infrastructure that runs AI-generated code inside secure, isolated cloud sandboxes, controlled from JavaScript or Python SDKs.
AX (Agent Executor)★ 12.4kGoogle's declarative orchestrator for agent workloads: a Task runs untrusted agent code in a sandbox, while Workspace, Gateway and Model resources wire up its repos, network allowlist and LLM credentials.
Astrid★ 10.3kA portable Rust runtime that executes software as sandboxed WebAssembly capsules, where every file, network, process and tool call is gated by a signed, revocable, per-principal capability instead of ambient authority.
Cloudflare Computer★ 9.3kA virtual filesystem inside a Durable Object that gives an agent one execution surface across Workers isolates and full Linux containers.
OpenShell—NVIDIA's open-source, policy-enforced sandbox runtime for fleets of autonomous AI agents