NVIDIA open-sources OpenShell 0.1.0 to sandbox AI agents without rewriting them
dl_weekly · x · 2026-10-07
NVIDIA released OpenShell 0.1.0, an open-source runtime that enforces which systems and data an AI agent can access — without rewriting the agent.
Highlights
- Combines sandboxed execution, controlled service access, credential management, and a formal policy prover that verifies permission boundaries and flags actions that cross them.
- Three components: Gateway (inspects outbound requests against policy), Supervisor (manages agent fleets), and Sandbox (kernel-level filesystem/process controls).
- Ships with Docker/Kubernetes compute drivers and trusted middleware; teams can build in a local sandbox and deploy to shared infrastructure via workspaces.
- Cadence, Slack, and Gecko Robotics are adopting it for chip design, enterprise automation, and physical robotics governance.
More from coding & agent
- What If AI Agents Remembered Like Living Systems? A Mycelial Framework for Agent Memory — repligate · 2026-10-07
- Tag a bot on X and it runs agents on your home computer while you scroll — ns123abc · 2026-10-07
- Developer releases PowerShell module wrapping OpenAI's Decisions API — dfinke · 2026-10-07
- Microsoft's PrisMem evolves agent memory per-capability, beats baselines by 10.5 points on BEAM-1M — microsoft · 2026-10-07
- No-LLM-agent SRE diagnosis pipeline passes 80/105 cases across 21 fault scenarios in 14.6s median — tianyin_xu · 2026-10-07
- Heavy agent user: after living with agents, every traditional UI feels frustrating — FrankFelixAI · 2026-10-07