NVIDIA OpenShell Explained: Sandboxes and Credential Protection
NVIDIA's open-source OpenShell (Sept 28, 2026) runs each AI agent in a sandbox, limits it by policy and keeps real keys away. Official claims and caveats.
Data checked: September 29, 2026. This article is based on NVIDIA's press release, the OpenShell GitHub project (README and releases) and the official docs. We have not installed or used it ourselves, so everything described as "official" is NVIDIA's own description.
Once an AI agent can read files, install packages, call APIs and use your credentials, the question stops being whether it is smart enough and becomes whether you dare give it access. On September 28, 2026 NVIDIA announced the "Open Agent Safety Platform". Its software core, OpenShell, is an open-source runtime for agents, meant to keep agents useful without giving them unrestricted access.

Image: official OpenShell brand asset (source: docs/brand/assets in NVIDIA/OpenShell, Apache-2.0 licensed project; OpenShell and NVIDIA marks belong to NVIDIA).
The short version
- What it is: an open-source (Apache-2.0) agent runtime. Each agent runs in its own sandbox, you declare in a policy what it can touch, and OpenShell enforces it.
- How keys are handled: the official README says agents never see real credentials. OpenShell adds them only to requests bound for approved endpoints.
- You can try it now: the code is on GitHub with about 9,500 stars as of the check date. v0.1.0 shipped on September 25 and v0.1.2 on September 28. NVIDIA says the software is broadly available as open source from September 28.
- Keep two things apart: the press release also introduces Sentry, a hardware watchdog running on NVIDIA BlueField-4 DPUs. That is a separate layer and needs specific hardware. OpenShell itself is software, and the official docs list Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman or host virtualization.
- Independent validation is thin: most coverage we found restates the press release, without hands-on testing or third-party security validation.

Image: an illustration we drew from the official docs and README. It is not an NVIDIA diagram.
How OpenShell works (per NVIDIA)
According to the README and docs:
- One sandbox per agent. Kernel-level controls confine which files the agent can access and which system calls it can make, and every network connection passes a policy check before it leaves the sandbox. The docs name filesystem (Landlock), network, process and provider-credential layers.
- Permissions declared in YAML policies. Policies are declarative files you can keep in version control.
- Credentials added only at approved endpoints. The agent never sees the real key. OpenShell adds credentials only to requests going to approved endpoints.
- Policy changes are verified first. Before a policy change is approved, OpenShell uses formal verification to flag risky new access, such as reaching a new host with credentials or calling a new API method, and those changes wait for human review.
- SDKs and extension points. There are Python, TypeScript, Go and Rust SDKs. The docs give Claude Code, OpenCode, Codex and GitHub Copilot CLI as examples of agents to run inside a sandbox.
How to try it
The official README quickstart (needs Docker, Podman or host virtualization):
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demo
The installer sets up the CLI and a local gateway. The default sandbox image is minimal Ubuntu with no agent installed. To run a real agent, follow the official "Run Your First Agent" tutorial. Read any curl | sh script yourself before running it.
What it does not say, and what to watch
These are our notes, not NVIDIA's claims.
- It is very new. The v0.1.x releases landed within this one week. The README mentions a stable release cadence, but check the upgrade guide and known issues before using it in production.
- There is anonymous telemetry. The README says it collects anonymous operational categories and counts, and does not collect sandbox names, hostnames, file paths, prompts, credentials or model names. You can turn it off with an environment variable.
- A sandbox is not a silver bullet. One report notes that an agent that compromises the host OS can break out of software-level limits, which is where a hardware layer like Sentry comes in. Sentry needs BlueField-4 DPUs, which most individuals and small teams will not have.
- Permission design is still on you. A policy that is too broad makes a sandbox a formality. Irreversible actions such as paying, emailing externally or deleting data should still need human confirmation.
If you build AI agents into your own product
A sandbox governs what an agent can do in its runtime. Another layer is what you send into the model: sensitive personal data can be masked before a request goes out, and instructions hidden in outside messages can be intercepted first. See BazaarLink's content filter.
FAQ
Is OpenShell free?
Yes. It is open source under Apache-2.0, and NVIDIA says the software is available from its developer resources and GitHub. The press release gives no pricing.
Do I need NVIDIA hardware?
OpenShell itself is software, and the docs list Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental). The press release says overhead is minimal on NVIDIA Vera CPUs and that it can extend to Arm and Intel platforms. Only Sentry needs BlueField-4 DPUs.
Will an agent really never see my API keys?
The README says agents never see real credentials and OpenShell adds them only to requests bound for approved endpoints. That is the project's design claim. We have not verified it independently.
Which agents can I put in OpenShell?
The docs give Claude Code, OpenCode, Codex and GitHub Copilot CLI as examples of agents to run in a sandbox. See the official "Run Your First Agent" tutorial for steps. One report says wrapping an existing agent needs no changes to the agent's own code, which we have not confirmed.
Sources
- NVIDIA: NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment (2026-09-28)
- Project: NVIDIA/OpenShell (Apache-2.0), official docs
- Coverage: SiliconANGLE, Infosecurity Magazine, byteiota
TWD billing · Taiwan invoices · leading AI models · OpenAI-compatible API