Radar / AI security / NVIDIA OpenShell
NVIDIA OpenShell: open-source runtime that enforces what an agent may touch
OpenShell 0.1.0 wraps any AI agent in sandboxed execution with controlled service access, credential management outside the workload, and a formal policy prover - without rewriting the agent. Gateway/Supervisor/Sandbox components manage fleets and inspect every outbound request.
Why it matters
The policy prover uses formal logic to verify modeled permissions stay inside defined boundaries and flags actions that cross them - verification, not vibes. Already adopted by Cadence (chip design), Slack (enterprise automation) and Gecko Robotics; Docker and Kubernetes compute drivers included.
What you could build with it
A company letting coding agents touch production repos can wrap them in OpenShell so each agent can only read, write and call what a written policy allows.
Does it hold up?
Early but concrete adoption: NVIDIA's own OpenShell-Research repo ships worked adversarial policy-review experiments (416 reviewer decisions; enforcement failed closed when the AI reviewer was fooled), and third parties already run production agents inside OpenShell sandboxes. At 0.1.0, expect API churn - pin versions and treat policies as code.
Built with NVIDIA OpenShell
- Running Copilot CLI Inside OpenShell Sandboxes - Complete Tutorialyoutube · Hands-on walkthrough integrating GitHub Copilot CLI with OpenShell sandboxes: sandbox setup, automatic credential discovery, L7 provider injection, and policies restricting agents to authorized endpoints.
- How a Power Engineer Secures AI Agentsmedium · Practitioner breakdown comparing OpenShell's sandboxed execution, per-binary policy access control and private inference routing against a DIY systemd-hardened bare-metal fleet running 42 services and 17 agents.
- Nemotron Labs: What OpenClaw Agents Mean for Every Organizationnvidia blog · NVIDIA's framing of responsible OpenClaw agent deployment: OpenShell as the sandboxed runtime that defines precisely what the agent can and cannot do, enforcing permission boundaries from the start.
- rushcitizen/agent-runtime-layersgithub · 1 ★ · 29-layer production agent runtime (Claude, LangChain, LangGraph, Strands) that runs its whole agent inside an NVIDIA OpenShell sandbox under a declarative network/filesystem policy.
Learn more
First spotted on engineering blog: source.
More AI security
Cloudflare security-audit-skill: multi-phase security audits for coding agentsA coding-agent skill that runs multi-phase security audits with independently verified, machine-checkable findings.security · JEV 0.63Sandlock 0.8.8: deferred commit for agent sandboxesThe process-based Linux AI sandbox (no container, no VM) ships deferred commit: every run returns a changeset of what…security · JEV 0.56ClawSecure: free security scanner for OpenClaw AI agent skillsFree scanner that audits OpenClaw agent skills for vulnerabilities; the maker's audit of 2,890+ OpenClaw skills found…security · JEV 0.5Google DeepMind SynthID BioWatermarking technology that embeds an imperceptible, verifiable signature into AI-designed protein sequences and…security · JEV 0.49GitHub Security Lab Taskflow Agent: autonomous LLM fuzzing for C/C++Open-source agent that automates the full fuzzing lifecycle - entry-point discovery, harness generation, AFL++ runs…security · JEV 0.47LLM Agents Can Easily Tamper With Their Own TracesAn empirical study (arXiv 2026-09-24) showing that all tested local coding-agent harnesses except Muse Code allowed…security · JEV 0.4
Get the week's best AI launches, plus 3 ideas worth building
One email every Saturday. Ranked by traction, not hype. Free.