NVIDIA OpenShell Explained: A Safer Runtime for AI Agents NVIDIA released OpenShell, an open source runtime that isolates autonomous AI agents in per-agent sandboxes with kernel-level file and syscall controls and a policy gateway that checks every outbound network connection before it leaves the sandbox. The project requires Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental) plus Docker, Podman, or host virtualization, and ships SDKs for Python, TypeScript, Go, and Rust that connect to a gateway rather than installing the CLI. OpenShell's policy model lets operators declare which files, system calls, and hosts an agent may reach, with credentials attached by a provider so the agent never holds the token itself. NVIDIA OpenShell Explained: A Safer Runtime for AI Agents AI agents are getting genuinely useful. They can read your files, install packages, call APIs, and run shell commands. That is exactly what makes them risky. If you have ever pasted an API key into an agent's environment and then held your breath while it ran, this article is for you. NVIDIA has an AI agents are getting genuinely useful. They can read your files, install packages, call APIs, and run shell commands. That is exactly what makes them risky. If you have ever pasted an API key into an agent's environment and then held your breath while it ran, this article is for you. NVIDIA has an open source project called OpenShell that tries to solve this problem. Let's look at what it is, how it works, and whether it is worth your time. An agent is only useful if it can do things. But every capability you give it is also a capability that can go wrong: a prompt injection in a web page, a hallucinated rm -rf, a dependency that phones home, or a leaked token in a log. Most of us handle this today by running the agent in a Docker container and hoping for the best. That helps, but a container by default does not know the difference between "download a package from PyPI" and "send your credentials to a random server." According to the project, OpenShell is "the safe, private runtime for autonomous AI agents." In practical terms, it is: A CLI you use to create and manage sandboxes. A gateway that acts as the control plane for sandboxes, policies, and access. A sandbox where the agent actually runs, isolated from your host. A policy system where you declare what the agent can access. You write the rules. OpenShell enforces them. The agent does not get to negotiate. The README describes two main ideas. Each agent runs in its own isolated sandbox. Kernel-level controls restrict which files the agent can open and which system calls it can make. Every network connection goes through a policy check before it leaves the sandbox. Agents often need new access as they work. Maybe your agent suddenly wants to reach a new host. Normally you would either approve everything unsafe or approve each request by hand exhausting . Think of it like a building with a security desk. The sandbox is the room the agent works in. The policy is the visitor list and the set of doors the agent's badge opens. The provider is a mail clerk who attaches the real stamp your credential to an approved letter, so the agent never holds the stamp itself. The gateway is the security office that manages all of it. Requirements from the README: Linux, macOS on Apple Silicon, or Windows with WSL 2 marked experimental . You also need Docker, Podman, or host virtualization. Install and create a sandbox: curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh openshell sandbox create --name demo The installer sets up the CLI and a local gateway. The default sandbox image is a minimal Ubuntu with no agent installed, so you are starting with a clean, locked-down box. As always with a curl | sh installer, read the script before running it on a machine you care about. To run a real agent, the docs have a "Run Your First Agent" walkthrough. It runs OpenCode against a free OpenRouter model and shows how to approve new access as the agent asks for it. That walkthrough is the best way to see the policy loop in action. If you want to integrate OpenShell into your own application, there are SDKs that connect to a gateway: Language Install Python uv add openshell TypeScript npm install @nvidia/openshell-sdk Go go get github.com/NVIDIA/OpenShell/sdk/go@latest Rust cargo add openshell-sdk --git ... --tag