signalGitHub Trending2026-10-02
NVIDIA/OpenShell
OpenShell is NVIDIA's open-source runtime for safely running fleets of autonomous AI agents. It enforces policies via kernel-level instrumentation and formal verification, isolating each agent in a sandbox and hiding real credentials except for approved endpoints. The article covers installation, policies, providers, gateways, and SDKs for Python, TypeScript, Go, and Rust.
- for who
- Developers and organizations deploying autonomous AI agents that need safe access to files, network, and credentials.
- why now
- NVIDIA's OpenShell 0.1.x release adds stable APIs and isolation, crucial for secure AI agent deployment now.
- what changes
- Developers shift from giving agents unrestricted access to enforcing granular, formally verified policies, enabling safer autonomy without manual oversight.
- to do
- Install OpenShell via the quickstart command and create a sandbox, then follow the first agent tutorial to run a real agent with policy approval.
key points
- Kernel-level enforcement and formal verification for every policy change
- Sandboxed agents with credential injection only for approved endpoints
- SDKs in Python, TypeScript, Go, and Rust; Kubernetes support via Helm
#NVIDIA#OpenShell#AI agent security#sandbox#open source
score
score 8 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source