Nvidia has published OpenShell, an open-source sandbox that decides which files, network destinations and logins an AI agent is allowed to touch. Nvidia’s GitHub page describes it as a runtime for fleets of autonomous agents, licensed under Apache 2.0.
Nvidia’s argument is that agents only become useful once they can install software, call outside services and use credentials, and that is exactly where the risk begins. Operators write a policy for each agent. Controls inside the operating system kernel then enforce it, and every outbound connection is checked before it leaves the sandbox. According to the repository, agents never see real credentials; the system attaches them only to requests headed for approved destinations.
A second feature screens proposed policy edits with formal verification, a mathematical method for proving what a rule set permits. Per Nvidia, a proposed edit that would let an agent present its logins to a host it could not previously contact gets held until a person signs off.
The page cites no independent security testing. It runs on Linux, Apple Silicon Macs, and Windows through an experimental WSL 2 layer. Teams handing coding agents production credentials now have a free baseline for their homegrown guardrails.
Reported from Nvidia’s OpenShell repository on GitHub. The page carries no publication date.