NVIDIA OpenShell tested: 10/10 secret leaks without it, 0/10 with default policy — but auto-approve leaked in 12/12

No-Peanut-6988 · reddit · 2026-09-29

Sorami Consulting tested NVIDIA's open-source agent sandbox OpenShell (released Sept 28, Apache 2.0) with a qwen3:8b agent on Apple Silicon. Across 35 test IDs and 123 trials, every documented control held: with a malicious setup script, a canary secret leaked in 10/10 runs without OpenShell and 0/10 under default policy (default-deny egress, binary matching, Landlock rules all worked). Data still escaped only via operator settings: read-write rules, query strings/headers on GET-only rules, audit-mode leftovers, and automatic approval — which granted new public hosts in 12/12 trials, including rules OpenShell drafted itself. No documented-control bypasses found; the policy prover flags GraphQL/MCP/WebSocket/JSON-RPC as unsupported yet the loader accepts them anyway.

Related event: NVIDIA's Open-Source OpenShell Blocks Exfiltration by Default but Fails Under Auto-Approval(2 posts)→

Original post →

More from coding & agent

coding & agent channel →