StackMap
Subscribe
Explore / OpenShell
NVIDIA

OpenShell

NVIDIA's safe runtime for autonomous agents: kernel-enforced sandboxes with policy on every file, syscall and connection; credentials injected only for approved endpoints.

15,729 1,756 Rust Apache-2.0updated yesterday
View on GitHubDispute this mapping →
Curator's take

Reach for it when agents need real credentials and network but you want least privilege enforced below the agent — declarative policies, secrets the agent never sees, and a prover that flags risky new access for human review. More machinery than throwaway code execution needs; a microVM sandbox API is simpler there. On Kubernetes your CNI must enforce NetworkPolicy; Windows is WSL-only and experimental.

Mapped by ShipWithAI editors · links verified

Continue your stack

What teams reach for next — and why each earns a place beside OpenShell. Ranked by curator confidence.

pairs wellpairs wellalternativealternativeGuardrailsagentsightOpenSandboxagent-sandboxOpenShell
pairs wellalternativebuilt withpick a node for the why · open it from the panel
Weekly digest
README.md2 min read
OpenShell

License PyPI Security Policy Documentation

[!IMPORTANT] New in OpenShell 0.1.x: a stable release cadence, new isolation primitives, an expanded extension surface, and new APIs. Read the 0.1.0 upgrade guide.

OpenShell is the safe, private runtime for fleets of autonomous AI agents. Agents are most useful when they can read files, install packages, call APIs, and use credentials. OpenShell gives them that capability without giving them unrestricted access to your data, secrets, or network. You declare what each agent can touch in a policy, and OpenShell enforces it.

How It Works

OpenShell governs what agents can do in two ways: it instruments the kernel to enforce policy on every file access, system call, and network connection at runtime, and it uses formal verification to check what a policy change would allow before it is applied.

  • Kernel-level enforcement. Each agent runs in an isolated sandbox. Kernel controls confine which files it can access and which system calls it can make, and every network connection passes through a policy check before it leaves the sandbox. Agents never see real credentials; OpenShell adds them only to requests bound for approved endpoints.
  • Formally verified policy changes. Before a policy change is approved, OpenShell uses formal verification to flag risky new access it would grant, such as reaching a new host with credentials or calling a new API method, so those changes wait for human review.

See Architecture for how the gateway, supervisor, and sandbox fit together.

Quickstart

You need Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman, or host virtualization. See the Support Matrix for details.

curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demo

The installer sets up the CLI and a local gateway. The default sandbox image is minimal Ubuntu with no agent installed. To run a real agent, follow Run Your First Agent: it runs OpenCode against a free OpenRouter model and shows how to approve new access as the agent needs it.

Explore Further