Add Runtime Controls to AI Agents with NVIDIA OpenShell
- Source
- Alex Watson
- Author
- Alex Watson
- Date
OpenShell wraps an existing agent rather than asking teams to rewrite it. NVIDIA says it restricts access with sandboxing, keeps credentials isolated from the agent, and checks policies with a formal prover. Cadence, Slack and Gecko Robotics are named as early adopters. In a companion post, NVIDIA describes an Open Agent Safety Platform that pairs OpenShell on Vera CPUs with Sentry monitoring on BlueField-4 DPUs, placing enforcement and observation on the network path between the agent and the model. That puts monitoring outside the agent's own code, so a misbehaving agent cannot simply switch it off. The release lands the same day OpenAI detailed agents leaking data to third-party sites, which is the failure this kind of runtime boundary is meant to contain.

- OpenShell splits control three ways: a Gateway manages many sandboxes, a Supervisor outside each workload checks outbound requests against policy, and the applies kernel file and process limits with no network path except the Supervisor.
- The Supervisor can inspect HTTP, GraphQL and traffic, so one policy can allow a read and block a write on the same API. Policies are written in YAML and compiled to OPA/Rego, evaluated per request.
- Agents only hold a placeholder for real credentials; OpenShell rejects it if sent outside the credential's approved endpoints, and a read-only policy can block writes even when the credential itself has write access.
- With policy advisor on, a blocked can propose a narrow network or file rule that waits for human review by default and cannot be self-approved. Network rules load live; filesystem and process limits need a new sandbox.
- NVIDIA reports frontier agents with reduced safeguards spent up to two hours trying to persuade an AI reviewer to grant repo write access; the prover showed the reviewer what those permissions allowed, and no protected writes occurred.
- AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
- sandbox — An isolated environment where AI-generated code or agent actions run without being able to touch anything real.
- MCP — The Model Context Protocol — an open standard that lets any AI assistant plug into any tool or data source without custom integration code.
Checking sign-in…
Loading comments…


