Overview
OpenShell is NVIDIA's open-source answer to a trade-off every agent builder hits: agents are most useful when they can read files, install packages, call APIs and use credentials, and that same access is what makes them risky. The project describes itself as "the safe, private runtime for fleets of autonomous AI agents": you declare what each agent can touch in a policy, and OpenShell enforces it.

Enforcement happens in two ways. At runtime OpenShell instruments the kernel to apply policy to every file access, system call and network connection. Before a policy change is applied, a policy prover running in the gateway uses formal verification to check what the change would allow, flagging things such as new credentialed reach, new HTTP methods or access to cloud metadata endpoints.
The architecture splits into a sandbox that lives inside the boundary with the agent, owning its processes and forwarding TCP and DNS traffic; a supervisor on the trusted side that checks requests against policy, supplies credentials, resolves DNS and opens approved connections; a gateway that handles identity, stores sandbox state, delivers policy and attaches providers; and a compute runtime that creates the sandbox and builds its network fence. The agent itself is treated as an untrusted workload whose only allowed egress is to the supervisor.
Protection is layered: filesystem rules block reads and writes outside allowed paths and are locked at sandbox creation, network rules block unauthorized outbound connections and can be hot-reloaded at runtime, process rules block privilege escalation and dangerous syscalls, and provider credentials are opaque placeholders resolved only at profile-authorized endpoints. OpenShell runs on Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), with Docker, Podman or host virtualization, and is written in Rust under the Apache-2.0 license. NVIDIA's NemoClaw reference stack runs its supported agents inside OpenShell sandboxes.
What it does
- Kernel-level enforcement of policy on every file access, system call and network connection
- Formal verification of agent-proposed network rules before they are applied

- Filesystem and process rules locked at sandbox creation; network rules hot-reloadable at runtime
- Credentials handed to agents as opaque placeholders, resolved only at profile-authorized endpoints
- Agents propose new access; you approve or reject each rule from the host
- Gateway control plane with CLI, SDK and TUI front ends
- SDKs for Python, TypeScript, Go and Rust
- Runs on Linux, macOS on Apple Silicon and Windows with WSL 2 (experimental)
Getting started
The installer sets up the openshell CLI and a local gateway. You need Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman or host virtualization. The steps below follow the README quickstart and the docs' run-your-first-agent guide.
Install and create a sandbox
Run the installer, then create your first sandbox.
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demoAdd a model provider
Set OPENROUTER_API_KEY first, then import the provider profile and create a provider from the existing key. The agent never sees the raw key.
openshell profile import \
--url https://raw.githubusercontent.com/NVIDIA/OpenShell/main/providers/openrouter.yaml
openshell provider create \
--name openrouter \
--type openrouter \
--from-existingRun an agent in a sandbox
Create the sandbox, attach the provider and pass the agent command. This example runs OpenCode from its container image.
openshell sandbox create \
--name my-agent \
--from ghcr.io/anomalyco/opencode:latest \
--provider openrouter \
-- opencode -m openrouter/nvidia/nemotron-3.5-lightning:freeReview the access the agent asks for
When the agent needs access its policy does not grant, it proposes a rule. List pending proposals from the host, then approve the ones that match the access you intend to grant and reject the rest.
openshell rule get my-agent --status pending
openshell rule approve my-agent --chunk-id <chunk-id>
openshell rule reject my-agent \
--chunk-id <chunk-id> \
--reason "Not needed for this task."Optional: skills and telemetry
Install the public OpenShell skills for your coding agent. OpenShell collects anonymous operational telemetry by default; set the environment variable below to turn it off.
npx skills add NVIDIA/OpenShell
export OPENSHELL_TELEMETRY_ENABLED=falseCommands and code are distilled from the project's own documentation — always check the official repo for the latest.
When to use it
- Reach for it when an autonomous coding agent needs a shell, packages and API keys but must not reach the rest of your machine or network
- Reach for it when you want to review and approve each new network destination an agent asks for, with a prover flagging risky changes
- Reach for it when agents need credentials without ever holding the raw secrets
- Reach for it when running a fleet of agents behind one gateway that stores their policies, providers and settings
How OpenShell compares
OpenShell alongside other open-source code sandboxes & isolation tools AI/TLDR tracks, ranked by GitHub stars.
| Tool | Stars | What it does |
|---|---|---|
| Daytona | ★ 71.7k | Daytona is an open-source runtime that spins up isolated sandboxes in under 90ms so agents can safely run and persist AI-generated code. |
| NVIDIA NemoClaw | ★ 22.6k | NVIDIA's reference stack for running OpenClaw, Hermes and LangChain Deep Agents Code inside OpenShell sandboxes, adding managed inference, network policy, snapshots and CLI lifecycle control. |
| OpenSandbox | ★ 15.6k | OpenSandbox gives AI agents a safe place to run code and commands, with one unified API across Docker and Kubernetes runtimes and SDKs in five languages. |
| E2B | ★ 14k | E2B is open-source infrastructure that runs AI-generated code inside secure, isolated cloud sandboxes, controlled from JavaScript or Python SDKs. |
| AX (Agent Executor) | ★ 12.4k | Google's declarative orchestrator for agent workloads: a Task runs untrusted agent code in a sandbox, while Workspace, Gateway and Model resources wire up its repos, network allowlist and LLM credentials. |
| Astrid | ★ 10.3k | A portable Rust runtime that executes software as sandboxed WebAssembly capsules, where every file, network, process and tool call is gated by a signed, revocable, per-principal capability instead of ambient authority. |
| Cloudflare Computer | ★ 9.3k | A virtual filesystem inside a Durable Object that gives an agent one execution surface across Workers isolates and full Linux containers. |
| OpenShell | — | NVIDIA's open-source, policy-enforced sandbox runtime for fleets of autonomous AI agents |