OpenShell enforces AI agent permissions outside the running task
NVIDIA announced OpenShell 0.1.0, an open-source runtime that limits an AI agent’s access to files, processes, networks and credentials while it works. A control outside the agent can allow reads but block writes to the same service. The software is available on GitHub as part of a wider safety platform. No independent results establish how it performs against real attacks.
Artificial Intelligence··Evening
Rules outside the agent set its permissions
NVIDIA announced OpenShell 0.1.0, an open-source runtime for limiting the files, processes, network services and credentials an AI agent can reach. The Next Web also reported that the software became broadly available on GitHub as part of NVIDIA’s September 28 Open Agent Safety Platform announcement. Its rules operate outside the agent’s own workload rather than residing in its prompt. An operator can therefore allow data to be read from a service while blocking writes to that same service. NVIDIA says an existing agent can run inside this environment without rewriting the agent’s code. The release concerns permissions enforced during execution, separately from whatever task the agent has been asked to perform.[1], [2]
Gateway, supervisor and sandbox divide the work
OpenShell splits control among three components. Gateway manages the life cycle and policy for multiple sandboxes. A Supervisor paired with each sandbox sits outside the agent and examines outbound requests; network traffic passes through that component. Sandbox applies operating-system kernel limits to file and process activity. In NVIDIA’s example, every request to a GitHub API is initially blocked. A policy change then permits reads while writes remain blocked. The company says it can inspect configured HTTP, GraphQL and MCP calls. Credentials can remain outside the workload and be attached only to authorized requests, while policy decisions can leave an audit record. This design aims to distinguish a request’s action from merely the address of the service it contacts.[1]
OpenShell is one layer of the wider safety design
OpenShell is intended to run across CPU and GPU workloads in containers, virtual machines and Kubernetes environments. NVIDIA lists existing agent frameworks including Codex, Claude Code, Pi and Hermes as examples. The wider platform described by The Next Web adds a distinct Sentry component designed to monitor and quarantine an agent from a BlueField-4 network processor. Releasing OpenShell as software does not mean that every deployment has that hardware layer. NVIDIA names organizations adopting the platform, but its announcement does not provide independent measurements of attacks stopped in those deployments. Blocking a sample write request demonstrates the stated policy mechanism; it does not establish that every route around the boundary is closed in production.[1], [2]