NVIDIA Releases OpenShell for AI Agent Security
Key point
Rust-based OpenShell controls agent access through kernel-level isolation and Z3-based policy proofs.
Details
NVIDIA has released OpenShell, an open-source sandbox runtime that restricts AI agents' access to files, networks, and credentials via declarative policies. Written in Rust, the tool leverages Linux kernel's Landlock and seccomp to enforce kernel-level isolation for system calls and network access.
Core Security Architecture
Agents receive only placeholders instead of actual API keys. Real credentials are injected by a trusted Supervisor outside the sandbox, exclusively for requests directed to policy-allowed endpoints, preventing agents from stealing keys. All external connections are blocked and routed only to the Supervisor via mutually authenticated HTTP/2 channels.
Formal Verification and Policy Management
Before changes, a 'Policy Prover' based on the Z3 SMT solver formally verifies YAML policies. Risky rule expansions (e.g., using new host credentials) are not auto-approved and require human review. GraphQL, MCP, WebSocket, etc., are currently unsupported, and a 'within_boundary' determination does not guarantee 'safety'.
Release and Compatibility
Version 0.1.0 was released on September 25, 2026 (UTC). In-place upgrades from 0.0.x to 0.1.0 are not supported, requiring sandbox regeneration. It supports Linux (amd64/arm64) and Apple Silicon macOS, with Windows in experimental WSL2 stage. Distributed under the Apache-2.0 license, it provides SDKs for Python, TypeScript, Go, and Rust.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.