NVIDIA launches OpenShell 0.1.0 to secure AI agents
NVIDIA has released OpenShell 0.1.0, an open-source runtime that restricts what data and systems AI agents can access without requiring developers to rewrite their underlying code.

NVIDIA has introduced OpenShell 0.1.0, an open-source runtime designed to enforce strict security boundaries on autonomous AI agents. The software allows organizations to manage agent permissions externally, protecting sensitive credentials and restricting API operations without modifying the agent itself. OpenShell is built around three primary components: the OpenShell Gateway for managing sandbox lifecycles, the OpenShell Supervisor for inspecting outbound requests against policy, and the OpenShell Sandbox, which uses operating-system kernel controls to restrict filesystems and processes.
The runtime supports several popular models and frameworks, including Codex, Claude Code, Pi, and Hermes. Early adopters are already integrating OpenShell into diverse workflows. Cadence is using it to secure its ChipStack Autonomous RTL Design Engineer for chip design, Slack is leveraging it for an on-demand automation platform, and Gecko Robotics is employing the runtime to govern decision-making agents on physical robots. OpenShell supports both CPU and GPU execution across Docker, Podman, MicroVM, and Kubernetes environments.
Policies are written in YAML and compiled to OPA/Rego for real-time evaluation. OpenShell inspects HTTP, GraphQL, and Model Context Protocol traffic, allowing it to block write commands while permitting read queries. It also logs policy decisions in an Open Cybersecurity Schema Framework audit trail. To protect sensitive credentials, OpenShell binds them to authorized requests outside the agent workload, preventing agents from accessing the raw keys. If an agent requires new permissions mid-task, a policy advisor feature allows operators to review and approve proposed changes dynamically.
To prevent agents from bypassing restrictions, OpenShell features a policy prover that uses formal logic to verify security boundaries. In adversarial testing, frontier agents with reduced safeguards spent up to two hours attempting to manipulate an AI reviewer into granting write permissions for a protected GitHub repository. OpenShell's formal analysis successfully provided the evidence needed to block these attempts, resulting in zero unauthorized writes.
This is our own summary of reporting by NVIDIA Developer Blog



