Add Runtime Controls to AI Agents with NVIDIA OpenShell
NVIDIA announced OpenShell 0.1.0, described as an open-source runtime for defining and enforcing which systems and data an AI agent can access without rewriting the agent. The release combines sandboxed execution, controlled service access, credential management and formal policy analysis, according to the company.
The runtime is positioned as the runtime layer of the broader NVIDIA Open Agent Safety Platform. NVIDIA said OpenShell supports Codex, Claude Code, Pi, Hermes and future frameworks, and covers enterprise applications, frontier research and physical AI.
NVIDIA said Cadence uses OpenShell for chip design with its ChipStack Autonomous RTL Design Engineer, Slack is building an on-demand agent platform on OpenShell to automate tasks, and Gecko Robotics uses it to govern agents making decisions on physical robots.
Three components provide control, per NVIDIA. OpenShell Gateway manages the lifecycles and policies of many sandboxes; OpenShell Supervisor runs outside the agent workload and checks outbound requests against policy; OpenShell Sandbox runs the workload with kernel-level controls over filesystem and processes and no network path except through the supervisor.
The supervisor can inspect configured HTTP, GraphQL and Model Context Protocol traffic, NVIDIA said, allowing a data query while blocking a write through the same API. OpenShell records policy decisions in an Open Cybersecurity Schema Framework audit trail.
Credentials are kept outside the agent workload through provider profiles that define credentials, endpoints and permitted programs. Policy is authored in YAML and compiled to OPA/Rego for evaluation on each outbound request. Filesystem and process restrictions are established at sandbox start and require a new sandbox to change.
The OpenShell policy prover uses formal logic to check permissions granted by a policy, including provider-contributed access, NVIDIA said. The company reported that in long-horizon adversarial experiments, frontier agents with reduced safeguards spent up to two hours trying to persuade an AI reviewer to grant permissions to modify a protected GitHub repository; it said no protected repository writes occurred in those tests.
Ongoing work extends policy analysis across multiple agents, where one agent's access can combine with another's. Compute drivers connect OpenShell to Docker, Podman, MicroVM and Kubernetes.
Based on reporting from the original publisher. Visit the source for full context and later updates.
Publisher excerpt
AI agents can be given a goal, write code, use tools, and keep working as new information becomes available. This opens the door to applications that...