Overview
NVIDIA OpenShell™ is an open, secure runtime for agents. It governs agent execution, access, and where inference goes.
Security lives in the environment, not the model or the application. Nothing is permitted by default, permissions are granted based on policies, and enforcement happens outside the agent’s process, where it can’t be prompted away or bypassed. Every allow and deny is auditable.
Any model, any harness, any agent—across cloud, hybrid, on-prem, edge, and air-gapped infrastructure—under one policy layer.
Benefits
Run autonomous agents within boundaries you control, with consistent policy enforcement across models, harnesses, and deployment environments.
NVIDIA Open Agent Safety Platform is an open reference system design that combines the NVIDIA OpenShell secure runtime and NVIDIA Sentry with NVIDIA BlueField™-4 in-silicon security enforcement.
Each agent runs in its own isolated sandbox with no direct network access. OpenShell runs the agent without privileges and limits the files it can reach. It monitors and filters the agent's system calls in the kernel, blocking unsafe calls and brokering the agent's requests to the supervisor through a single secured channel for approval.
The policy prover is OpenShell’s policy verification engine. It uses formal verification to check whether policies stay within an allowed access boundary and whether proposed network rules add risky access compared with the sandbox’s current policy.
The gateway is OpenShell's control plane. It authenticates users, manages the sandbox lifecycle, and delivers policies, settings, and credentials to each sandbox's supervisor. It decides who can do what and brokers all access to sandboxes.
The supervisor runs outside the sandbox, oversees the agent at runtime, and connects the sandbox to the gateway. It evaluates every network request against policy at the binary, destination, method, and path levels and supplies credentials only where policy allows. Policy updates apply live, and every “allow” and “deny” decision is logged for a full audit trail.
Explore NVIDIA research on securing AI systems and strengthening cyber defense, including runtime controls for autonomous agents with OpenShell. Through open research and contributions to the Open Secure AI Alliance, NVIDIA shares methods and technical artifacts that help security teams validate findings and build stronger defenses.
Explore the full NVIDIA Open Agent Safety Platform, agent harness design, governing agents in enterprise AI factories, and more in the blogs and videos below.
Try OpenShell.
Access the open source OpenShell repository on GitHub.
Learn more about OpenShell by exploring the documentation.
The immediate users are developers building autonomous agents, platform teams enabling those developers, and security or IT teams that need a safer way to govern agent execution.
For developers, OpenShell provides a safer runtime for agents that use tools, write files, call APIs, or run for long periods. For enterprise IT and security teams, it provides a path to enable agent development without handing every agent broad access to the host, network, credentials, or model endpoints.
Learn more about NVIDIA Cybersecurity and NVIDIA AI Security Research.
OpenShell supports agent paths such as Claude Code, Codex, GitHub Copilot CLI, Hermes, LangChain Deep Agents, OpenClaw, OpenCode, and others. OpenShell is intended to be model-agnostic and harness-agnostic, so teams can also bring custom agents and custom sandbox images.
Developers and enterprises want the productivity of autonomous agents, but they need stronger controls over what those agents can access and change. OpenShell addresses that gap by putting policy enforcement, credential handling, sandboxing, and inference routing in a boundary outside of the agent.
No. OpenShell is not another agent framework. It is designed to sit underneath agent frameworks and harnesses, including Claude Code, Codex, OpenCode, OpenClaw, and custom agent stacks.
No. A sandbox isolates a process from the host for a bounded task. OpenShell is a runtime that governs agent actions across their lifetime.
That runtime includes sandboxing, but also gateway-brokered credentials, identity boundaries, policy-as-code, policy-enforced egress, inference routing, audit/state, and boundaries for multi-agent or sub-agent workflows. The distinction matters because autonomous agents need governance over time, not just one-time process isolation.
No. OpenShell integrates with the enterprise ecosystem rather than replacing it. Identity providers, secret stores, observability systems, security tooling, and governance platforms remain important surrounding systems.
OpenShell’s role is to provide the agent runtime boundary and enforce OpenShell policy consistently across the selected runtime.
Docker containers and Kubernetes pods are runtime substrates. OpenShell uses runtimes such as Docker, Podman, Kubernetes, and VM isolation, but adds agent-specific control: gateway coordination, sandbox supervision, policy-enforced egress, provider credential handling, inference routing, and logs.
The practical difference is that OpenShell is designed around the actions agents take, not just around starting a container or pod.
OpenShell is designed to run where developers run agents: local developer systems, on-prem environments, hybrid environments, and cloud infrastructure.
Supported compute paths include Docker, Podman, Kubernetes through Helm, and experimental VUM runtime.
Yes. OpenShell has a Helm chart that deploys the gateway into a Kubernetes cluster, and the Kubernetes runtime creates sandbox workloads through Kubernetes APIs.
Yes, via Podman, Docker, Kubernetes, or VM, OpenShell can run on NVIDIA DGX Spark™ or NVIDIA DGX Station™. DGX Spark and DGX Station are strong targets for local and private agent development because they let teams keep the agent runtime, data, and model access inside a controlled environment.
Yes. OpenShell includes a policy-aware inference router which forwards permitted requests to cloud model endpoints.