NVIDIA OpenShell: Secure Runtime for Autonomous AI Agents
Key point
OpenShell enforces policy-based access controls and kernel-level isolation to prevent autonomous AI agents from unrestricted data or network access.
Details
NVIDIA OpenShell provides a safe, private runtime for fleets of autonomous AI agents. It enables agents to perform tasks like file reading, package installation, and API calls while blocking unlimited access to data, secrets, and networks. The system uses policy-based control to declare and enforce the exact scope of access for each agent.
Enforcement Mechanisms
OpenShell operates through two primary enforcement methods:
- Kernel-level enforcement: Agents run in isolated sandboxes where kernel controls restrict file access and system calls. All network connections must pass policy checks before leaving the sandbox. Agents cannot see actual credentials; OpenShell injects them only for approved endpoints.
- Formally verified policy changes: Before any policy change is approved, formal verification flags risky new access patterns (such as connecting to new hosts with credentials or calling new API methods) for human review.
Architecture and Installation
The system consists of a gateway, supervisor, and sandbox. It supports Linux, macOS (Apple Silicon), and Windows (WSL 2, experimental), requiring Docker, Podman, or host virtualization. The default sandbox image is minimal Ubuntu with no agent installed.
SDKs and Skills
SDKs are available for Python, TypeScript, Go, and Rust to connect applications to the OpenShell gateway. Public skills are also available to teach coding agents how to drive the OpenShell CLI, write sandbox policies, and debug gateways. The project is licensed under Apache License 2.0.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.