SDSignal Desk

Add Runtime Controls to AI Agents with NVIDIA OpenShell

Sep 28, 2026, 1:55 AM · NVIDIA Developer

Image: NVIDIA Developer

OpenShell 0.1.0 wraps existing agents in sandboxes, credential proxies, and a formal policy prover—without forcing teams to rewrite the agent.

Why it matters

Agents that can write code, call tools, and run for days need workspaces, credentials, and external APIs. Broader access is what makes them useful—and what makes a bad day consequential: production writes, leaked secrets, or work that drifts past the assigned task.

NVIDIA’s OpenShell 0.1.0 tutorial shows the runtime half of its Open Agent Safety Platform: Gateway, Supervisor, and Sandbox enforcing permissions outside the workload. Codex, Claude Code, Pi, Hermes, and future frameworks are in scope. Cadence, Slack, and Gecko Robotics are named as early adopters across chip design, enterprise automation, and physical robots.

Runtime controls that don’t require a rewrite are how useful agents survive contact with real systems. We’re watching whether this becomes the default harness or stays a niche NVIDIA stack.

From the desk

I’m reading OpenShell as the practical answer to a problem labs keep rediscovering in evals: you cannot ask the agent to police itself when tools, time, and ambiguous goals pull it off course. Kernel-level filesystem and process limits, a supervisor that inspects HTTP/GraphQL/MCP traffic, and credentials that never enter the workload—those are browser-era lessons applied to agents.

The credential-binding model is the part enterprises should care about first. The agent sees a placeholder; the supervisor substitutes the real key only for authorized endpoints and programs. Read-only API policy can still block a write even when the underlying credential could do more. That separation is how you keep useful model access without handing the agent the keys to the kingdom.

The policy prover is the sharper edge. Formal checks on what a YAML-to-OPA/Rego policy actually grants—including provider-contributed access—mean an agent’s persuasive explanation cannot rewrite the math. NVIDIA cites long-horizon adversarial tests where frontier agents spent up to two hours trying to talk an AI reviewer into permissions that would modify a protected GitHub repo; combined review plus runtime controls, they say, allowed useful access and no protected writes. That’s the kind of result we want more of—if independent teams can reproduce it.

Policy advisor lets an agent propose narrowly scoped network or file changes when blocked, pending human review by default, with no self-approval. That’s the right default for long-running work. The risk if this scales: operators rubber-stamp proposals under deadline pressure, or multi-agent permission composition (which NVIDIA flags as ongoing work) opens a path no single policy intended. Useful AI with teeth still needs humans who actually read the prover output.

Context

NVIDIA developer tutorial by Alex Watson and Ali Golshan, September 28, 2026, covering OpenShell 0.1.0. Companion piece describes the broader Open Agent Safety Platform with BlueField Sentry. Code and CNCF Slack #openshell-dev are pointed to for contributors.

Who feels it

Agent platform builders
Sandbox + supervisor + gateway lets teams wrap Codex/Claude Code-class tools without forking the agent loop.
Security and governance teams
OCSF audit trails, formal policy proofs, and third-party governance hooks give reviewers evidence that isn’t the agent’s narrative.
Physical AI / robotics
Gecko’s use case underscores why out-of-band permissioning matters when agents touch machines, not just tickets.
Infra operators
Docker, Podman, MicroVM, and Kubernetes drivers plus multi-tenant workspaces point at shared fleets, not only laptop demos.

What to watch

  1. Independent reproductions of the GitHub adversarial policy-prover tests
  2. How Cadence, Slack, and Gecko report failure modes once OpenShell is in production paths
  3. Whether multi-agent composed-permission analysis ships beyond the ‘ongoing work’ note

Read the original

Continue at the source.

NVIDIA Developer

Companies: NVIDIA