NVIDIA has released OpenShell 0.1.0, an open-source runtime designed to add enforceable controls to AI agents without requiring code rewrites. The system combines sandboxed execution, controlled service access and formal policy analysis, allowing teams to grant agents necessary capabilities while maintaining security.
OpenShell supports popular frameworks including Codex, Claude Code, Pi and Hermes, and functions as the runtime layer within the larger NVIDIA Open Agent Safety Platform, which extends protection across application, runtime and infrastructure layers, the company says. Organizations like Cadence, Slack, and Gecko Robotics are already adopting OpenShell across applications ranging from chip design to physical AI.
NVIDIA OpenShell 0.1.0 Enforces Runtime Controls for AI Agents
NVIDIA OpenShell 0.1.0 manages agent sandboxes by restricting outbound communication to configured services, a capability important for long-running AI tasks. The system employs operating-system kernel controls to limit file access and prevent privilege escalation within these sandboxes, enhancing security beyond traditional virtualization, according to NVIDIA. This granular control extends to network access. Supervisors can inspect HTTP, GraphQL and Model Context Protocol traffic, permitting data queries while blocking potentially harmful write operations through the same API.
The system can oversee fleets of agents, each operating within its own sandbox and governed by specific permissions, enabling centralized governance across multiple agents simultaneously. Central to this control are three core components: the OpenShell Gateway, responsible for managing sandbox lifecycles and policies; the OpenShell Supervisor, which runs outside the agent workload and validates outbound requests against established policy; and the OpenShell Sandbox, providing kernel-level controls over filesystem access and processes.
The platform’s formal policy analysis provides reviewers with clear evidence of permitted actions, even when agents attempt to circumvent restrictions, according to NVIDIA. Documentation for supported checks, known as prover documentation, is available for those interested in the underlying verification processes. Alex Watson, senior director of product at NVIDIA AI, explains that OpenShell places “enforceable runtime controls around an existing AI agent—without rewriting it,” streamlining deployment and minimizing disruption for organizations adopting the technology.
This approach is particularly valuable given the increasing complexity of agentic AI, where agents are designed to independently investigate, experiment, and execute tasks over extended periods. Current development efforts focus on extending this policy analysis to encompass interactions between multiple agents, assessing the combined permissions of a system formed by their collaborative access. Ali Golshan, senior director of AI software at NVIDIA, leads product development in AI software.
This multi-layered approach addresses the growing need for robust security measures as AI agents gain access to increasingly sensitive workspaces, compute resources and credentials. The system’s ability to manage agent permissions and restrict access is not merely preventative; it also provides a mechanism for auditing and review, the company says.
“OpenShell’s formal policy analysis gave the reviewer evidence of what those permissions allowed, even when agents attempted to manipulate the reviewer,” the company reports, highlighting the transparency and accountability built into the platform. This level of oversight is critical for organizations deploying AI agents in sensitive environments or applications where data integrity and confidentiality are paramount.
OpenShell Architecture: Gateway, Supervisor, and Sandboxed Execution
OpenShell employs a tiered architecture to manage agent autonomy and security, beginning with the OpenShell Gateway which orchestrates the lifecycles and policies governing numerous sandboxes simultaneously. The Gateway’s function is critical as agentic AI expands into applications requiring prolonged operation, such as software investigation and extended research projects spanning days or weeks. Complementing the Gateway is the OpenShell Supervisor, a component paired with each individual sandbox and running entirely outside the agent’s workload.
This separation is deliberate; the Supervisor acts as a gatekeeper, meticulously examining all outbound requests against established policy before they are executed. When a request violates policy, OpenShell doesn’t simply deny access, but also logs the event for review by an operator or an AI agent approver, providing a detailed audit trail. The final component, the OpenShell Sandbox, is where the agent’s workload actually executes, benefiting from kernel-level controls over its filesystem and processes.
This sandbox environment severely restricts the agent’s ability to access or modify files and prevents it from escalating its system privileges, creating a robust barrier against malicious or unintended actions. Network access is similarly constrained, requiring all communication to pass through the Supervisor for inspection and authorization. This layered approach, combining filesystem restrictions, privilege control and network filtering, significantly reduces the attack surface and minimizes the risk of agent-driven security breaches.
Beyond simple restriction, OpenShell incorporates a policy advisor feature designed to facilitate adaptation and learning. If a policy blocks a request, the agent can propose a narrowly scoped change to the network or file access rules. However, this proposal does not automatically take effect. It remains pending human review by default, preventing the agent from self-authorizing potentially risky actions.
Once approved, OpenShell dynamically loads the new rule into the running sandbox, allowing the agent to retry its operation without requiring a full restart, maximizing efficiency and minimizing disruption, NVIDIA reports. “An agent can interpret instructions, choose tools, and evolve its approach over time,” the developers explain, emphasizing the system’s ability to balance security with agent flexibility. The system’s credential management further enhances security by keeping real credentials separate from the agent workload and binding them to authorized requests.
This prevents agents from directly accessing sensitive information, reducing the risk of credential theft or misuse. Organizations are already adopting OpenShell across diverse applications, from chip design with Cadence’s ChipStack Autonomous RTL Design Engineer, to automating tasks within Slack’s on-demand agent platform, and even in accelerated computing and physical AI. The open-source nature of OpenShell also encourages broad ecosystem participation, shaping the product itself through contributions from a growing community of partners and developers, accessible through the #openshell-dev channel and the project’s GitHub repository.
OpenShell Capabilities: Formal Policy Verification and Governance
OpenShell 0.1.0 introduces multi-tenant platform support, enabling operation of agent services for multiple teams or customers with separate workspaces, permissions and service access on shared infrastructure. This capability extends beyond isolated execution to address the complexities of managing numerous agents within a single system, an important step for scaling AI deployments across organizations. The system’s architecture allows for granular control over each agent’s environment, preventing interference and ensuring data security even when running concurrent workloads, the company’s account states.
OpenShell achieves this through a layered approach, managing agent lifecycles and policies independently for each sandbox instance. This is accomplished by using formal logic to analyze the permissions granted by a policy, identifying potential violations before they occur. The system doesn’t simply block actions. It provides a traceable audit trail and a clear explanation of why a request was denied, facilitating both debugging and compliance.
In adversarial testing, frontier agents attempted to persuade an AI reviewer to grant permissions allowing modification of a protected GitHub repository, but OpenShell’s analysis prevented unauthorized writes. Extensibility is a core design principle of OpenShell, allowing integration with third-party security services, governance systems and custom checks. This open architecture ensures the runtime can adapt to evolving security requirements and integrate with existing enterprise infrastructure. The Gateway manages the lifecycles and policies of multiple sandboxes, while the Supervisor, running outside the agent workload, enforces those policies by inspecting outbound requests.
Policies are authored in YAML and compiled to OPA/Rego, a declarative policy language, which OpenShell evaluates for each request. An example policy permitting read-only access to the GitHub REST API specifies the host, enforcement type and path for the /usr/bin/curl program.
Credential Protection and Service Access with OpenShell Runtime
Multi-tenant platform support is included within OpenShell 0.1.0. The system’s formal policy verification tools demonstrate to both human and AI reviewers whether requested permissions remain within defined security boundaries, identifying potential overreach before execution. Gecko Robotics uses OpenShell to govern agents that make decisions controlling physical robots, showing real-world application of the runtime’s governance features. Network access and credential binding both require permission for a request to proceed, preventing credential availability to unauthorized services and rejecting requests directed to unapproved destinations.
The receiving service still enforces its own permissions, but OpenShell adds an additional layer of control over how the agent uses those credentials. For example, a configured read-only API policy can block write requests even if the underlying credential possesses write access, providing a finer-grained level of security than traditional credential management.
A provider profile defines the credentials, endpoints and permitted programs for each service, and launching an agent like Codex with a pre-configured GitHub provider named “github” is accomplished through a single command line instruction: openshell sandbox create \. This allows for rapid deployment and configuration of agents within a secure environment. This granular control allows agents to function effectively without compromising system security. Current development efforts focus on extending this policy analysis to encompass interactions between multiple agents, assessing the combined permissions resulting from interactions between them.




See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
