Skip to content
AI HOT (Curated Pool)

NVIDIA open-sources OpenShell 0.1.0 to add runtime permissions and sandboxing for AI agents

NVIDIA 发布开源运行时 OpenShell,为 AI Agent 提供权限管控与安全沙箱

NVIDIA released OpenShell 0.1.0, an open-source runtime that enforces which systems and data an AI agent can access without rewriting the agent. It bundles sandboxed execution, controlled service access, credential management, and formal policy analysis so teams can restrict API operations and protect credentials outside the agent workload. Cadence, Slack, and Gecko Robotics are already adopting it for chip design, enterprise automation, and physical robot governance. Three components—Gateway, Supervisor, and Sandbox—manage agent fleets, inspect outbound requests against policy, and apply kernel-level filesystem and process controls. A policy prover uses formal logic to verify that permissions stay within defined boundaries. It supports Codex, Claude Code, Pi, Hermes, and runs on Docker and Kubernetes.

Why it matters: NVIDIA open-sources an Agent security runtime with three-layer architecture and formal verification — a real need for teams deploying agents. Score held back because it's v0.1.0 with no perf data or real deployment cases in the post; treat as substantive but unproven.

Read the original ↗Export Markdown