[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"readme:openshell":3},"\u003Cpicture>\n  \u003Csource media=\"(prefers-color-scheme: dark)\" srcset=\"docs\u002Fbrand\u002Fassets\u002Fopenshell-banner-dark.png\">\u003C\u002Fsource>\n  \u003Csource media=\"(prefers-color-scheme: light)\" srcset=\"docs\u002Fbrand\u002Fassets\u002Fopenshell-banner-light.png\">\u003C\u002Fsource>\n  \u003Cimg alt=\"OpenShell\" src=\"https:\u002F\u002Fraw.githubusercontent.com\u002FNVIDIA\u002Fopenshell\u002FHEAD\u002Fdocs\u002Fbrand\u002Fassets\u002Fopenshell-banner-light.png\" width=\"430\" \u002F>\n\u003C\u002Fpicture>\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FNVIDIA\u002FOpenShell\u002Fblob\u002Fmain\u002FLICENSE\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FLicense-Apache_2.0-blue\" alt=\"License\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fpypi.org\u002Fproject\u002Fopenshell\u002F\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FPyPI-openshell-orange?logo=pypi\" alt=\"PyPI\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FNVIDIA\u002Fopenshell\u002Fblob\u002FHEAD\u002FSECURITY.md\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FSecurity-Report%20a%20Vulnerability-red\" alt=\"Security Policy\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Findex.html\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Fdocs-latest-brightgreen\" alt=\"Documentation\" \u002F>\u003C\u002Fa>\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>[!IMPORTANT]\n\u003Cstrong>New in OpenShell 0.1.x:\u003C\u002Fstrong> a stable release cadence, new isolation primitives, an expanded extension surface, and new APIs. \u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fupgrade\u002F0-1-0\" rel=\"nofollow ugc noopener\">Read the 0.1.0 upgrade guide\u003C\u002Fa>.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>OpenShell is the safe, private runtime for fleets of autonomous AI agents. Agents are most useful when they can read files, install packages, call APIs, and use credentials. OpenShell gives them that capability without giving them unrestricted access to your data, secrets, or network. You declare what each agent can touch in a policy, and OpenShell enforces it.\u003C\u002Fp>\n\u003Ch2>How It Works\u003C\u002Fh2>\n\u003Cp>OpenShell governs what agents can do in two ways: it instruments the kernel to enforce policy on every file access, system call, and network connection at runtime, and it uses formal verification to check what a policy change would allow before it is applied.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Kernel-level enforcement.\u003C\u002Fstrong> Each agent runs in an isolated sandbox. Kernel controls confine which files it can access and which system calls it can make, and every network connection passes through a policy check before it leaves the sandbox. Agents never see real credentials; OpenShell adds them only to requests bound for approved endpoints.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Formally verified policy changes.\u003C\u002Fstrong> Before a policy change is approved, OpenShell uses formal verification to flag risky new access it would grant, such as reaching a new host with credentials or calling a new API method, so those changes wait for human review.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>See \u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fabout\u002Farchitecture\" rel=\"nofollow ugc noopener\">Architecture\u003C\u002Fa> for how the gateway, supervisor, and sandbox fit together.\u003C\u002Fp>\n\u003Ch2>Quickstart\u003C\u002Fh2>\n\u003Cp>You need Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman, or host virtualization. See the \u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fabout\u002Fsupport-matrix\" rel=\"nofollow ugc noopener\">Support Matrix\u003C\u002Fa> for details.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-shell\">curl -LsSf https:\u002F\u002Fraw.githubusercontent.com\u002FNVIDIA\u002FOpenShell\u002Fmain\u002Finstall.sh | sh\nopenshell sandbox create --name demo\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The installer sets up the CLI and a local gateway. The default sandbox image is minimal Ubuntu with no agent installed. To run a real agent, follow \u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fabout\u002Frun-your-first-agent\" rel=\"nofollow ugc noopener\">Run Your First Agent\u003C\u002Fa>: it runs OpenCode against a free OpenRouter model and shows how to approve new access as the agent needs it.\u003C\u002Fp>\n\u003Ch2>Explore Further\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fhow-it-works\u002Fsandboxes\u002Foverview\" rel=\"nofollow ugc noopener\">Sandboxes\u003C\u002Fa>: images, runtimes, GPUs, and lifecycle.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fhow-it-works\u002Fpolicies\u002Foverview\" rel=\"nofollow ugc noopener\">Policies\u003C\u002Fa>: filesystem, network, and process rules, with the \u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fhow-it-works\u002Fpolicies\u002Fadvisor\" rel=\"nofollow ugc noopener\">advisor\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fhow-it-works\u002Fpolicies\u002Fprover\" rel=\"nofollow ugc noopener\">prover\u003C\u002Fa> for reviewing changes.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fhow-it-works\u002Fproviders\u002Foverview\" rel=\"nofollow ugc noopener\">Providers\u003C\u002Fa>: credentials that work only at approved endpoints, including \u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fhow-it-works\u002Finference\" rel=\"nofollow ugc noopener\">inference\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fopenshell\u002Flatest\u002Fhow-it-works\u002Fgateways\u002Foverview\" rel=\"nofollow ugc noopener\">Gateways\u003C\u002Fa>:\u003C\u002Fli>\n\u003C\u002Ful>\n",1791678838941]