NVIDIA OpenShell sandbox blocked poisoned scripts, but auto-approval leaked in 12/12 trials
No-Peanut-6988 · reddit · 2026-09-29
A team stress-tested NVIDIA's OpenShell (v0.1.2), an open-source agent sandbox released Sept 28 with microVM isolation, default-deny egress, and Landlock filesystem rules, running a local qwen3:8b agent loop across 123 trials on Apple Silicon.
- Defaults held: across 35 test IDs, default-deny networking, binary execution controls, and Landlock blocked every unauthorized path.
- Malicious setup defense: a poisoned repo setup script exfiltrated a secret token in 10/10 runs without the sandbox; 0/10 under OpenShell defaults.
- But escapes remained: with auto-approval on, outbound traffic to new public hosts was granted 12/12 times without confirmation; agents can still exfiltrate via URL query strings or HTTP headers; audit mode logs but doesn't block; MCP, GraphQL, WebSocket and JSON-RPC rules are unsupported.
Conclusion: default-deny boundaries work, but operator settings like auto-approval can wipe out the protection. Full report, checklist, and test harness are public.
More from coding & agent
- Millions of person-hours wasted building AI harnesses, erased by new model releases — sebpaquet · 2026-09-29
- Unverified Claim: Anthropic Engineers Share All Claude Sessions, Teammates Can Steal Each Other's Tasks — YouJiacheng · 2026-09-29
- Open-source self-driving sim repo auto-galleries 38 demos, adds Claude Code PR review skill — 4310sy · 2026-09-29
- Celesto: open-source persistent microVM computers for AI agents, boots in 500ms — aniketmaurya · 2026-09-29
- A practical guide to adopting AI in your organization: management skills over prompt tricks — chribonn · 2026-09-29
- RSI Arena: 8 AI agents get 1,000 GPU-hours each to train a better model live — my_cat_can_code · 2026-09-29