NVIDIA OpenShell tested: 10/10 secret leaks without it, 0/10 with default policy — but auto-approve leaked in 12/12
No-Peanut-6988 · reddit · 2026-09-29
Sorami Consulting tested NVIDIA's open-source agent sandbox OpenShell (released Sept 28, Apache 2.0) with a qwen3:8b agent on Apple Silicon. Across 35 test IDs and 123 trials, every documented control held: with a malicious setup script, a canary secret leaked in 10/10 runs without OpenShell and 0/10 under default policy (default-deny egress, binary matching, Landlock rules all worked). Data still escaped only via operator settings: read-write rules, query strings/headers on GET-only rules, audit-mode leftovers, and automatic approval — which granted new public hosts in 12/12 trials, including rules OpenShell drafted itself. No documented-control bypasses found; the policy prover flags GraphQL/MCP/WebSocket/JSON-RPC as unsupported yet the loader accepts them anyway.
More from coding & agent
- A naive video transcription fixer pipeline: extract audio+frames, ASR, then correct with a frontier model — capetorch · 2026-09-29
- bdsqlsz is vibe-coding DLSS5 weight training for his in-development 3D game — bdsqlsz · 2026-09-29
- We Built an On-Call Agent That Failed the Right Way — Memory Can Learn the Wrong Lesson — Similar-Split7292 · 2026-09-29
- Extending Jev Mode to Images: Constrained llama.cpp Outputs as Image Selections — opUserZero · 2026-09-29
- Scraping Xiaohongshu hit posts with Codex + a wired Android phone — huangyun_122 · 2026-09-29
- Reverse-Engineering MW2, Minecraft and Skate 3 With Claude and DeepSeek Into One Playable Game — ericcalyborn · 2026-09-29