NVIDIA's OpenShell Agent Sandbox Hits 14,400 Stars: What It Enforces and What It Leaves Out
Security / explainer
NVIDIA's OpenShell Agent Sandbox Hits 14,400 Stars: What It Enforces and What It Leaves Out
The Apache 2.0 runtime confines agents with Landlock and seccomp, but its own issue tracker and an outside critique show where the boundary stops.

NVIDIA's OpenShell, a runtime that runs AI agents inside kernel-level sandboxes, has 14.4k GitHub stars, 347 open issues and 186 pull requests, and it gained 584 stars on the day it appeared on GitHub's trending list.
Stars measure attention, not deployment. This piece covers what the project says it enforces, what an outside critique says it does not, and what its issue tracker showed on October 1 and 2, 2026. Nothing here was run; it is built from the repository, NVIDIA's own page, a Tigera critique and the issue list.
What OpenShell enforces
NVIDIA licenses it under Apache 2.0 and describes it as an "open-source, secure-by-design runtime that executes autonomous AI agents inside kernel-level sandboxes governed by declarative policy". Agents named on NVIDIA's page are Claude Code, OpenClaw, Codex and OpenCode, with Ollama and vLLM as inference backends. These "run unmodified" inside it.
| Layer | Mechanism | Source |
|---|---|---|
| Filesystem | Landlock LSM, locked at sandbox creation | NVIDIA page, Tigera |
| Process | seccomp syscall filtering, unprivileged identity | NVIDIA page, Tigera |
| Network | Default-deny proxy, per-binary endpoint allowlists | NVIDIA page |
| Credentials | Injected by the gateway so agents never hold real API keys | NVIDIA page |
| Audit | Allow and deny decisions logged | NVIDIA page |
The README adds that the project uses "formal verification to check what a policy change would allow before it is applied". That is a vendor claim; no independent review of it was found.
Where the boundary stops
Alister Baroi of Tigera wrote on July 15, 2026 that OpenShell is a runtime for individual agents and deliberately leaves out agent identity, agent-to-agent communication and cross-sandbox traffic. His line: "It does not attempt to answer 'which of my two hundred agents called the payments MCP server last Tuesday, under whose authority, and using which model?'"
Disclosure matters here. Baroi's post goes on to propose three ways of pairing OpenShell with Tigera's Lynx product, so the critique has a commercial interest in the gap it describes. The gap itself is consistent with NVIDIA's documentation, which Baroi says excludes those topics.
On maturity the sources disagree. Baroi called it alpha in July and said the experimental Kubernetes Helm chart is unsuitable for production. The repository text read for this piece describes 0.1.x as a release with "a stable release cadence". The label has moved or one description is out of date; the sources do not say which.
What the issue tracker showed on October 1 and 2
Titles only, since the issue bodies were not read:
- #4097: "bug(sandbox): child processes cannot add restrictive seccomp filters".
- #4098: "bug(sandbox): namespace hardening prevents Chromium's guest sandbox from starting".
- #4133: "bug: openshell doctor check doesn't verify Docker Desktop prerequisites (Landlock kernel, host networking)".
- #4062: "bug(policy): advance sandbox resource version for every policy revision".
Taken together, the first two describe the strictness cutting both ways: a confined agent cannot run a browser that wants its own sandbox, and a child process cannot tighten the filters further. The third is the one worth a reader's attention. Landlock needs kernel support, and a health check that does not verify it on Docker Desktop is a hole in the checking, though the title alone does not show whether the sandbox then runs without it.

Requirements and the install line
OpenShell runs on Linux, on macOS with Apple Silicon, and on Windows through WSL 2, where support is labelled experimental, and it needs Docker, Podman or virtualization. Our report on WSL containers going generally available covers the Windows side of that stack.
The README's install command pipes a script from the repository's main branch into sh. That is how many tools ship, and it is the opposite of reviewing a sandbox before trusting it with credentials. Pin a release and read the script first.
The agent tooling it protects is spreading fast: see our piece on the Ponytail agent plugin. What OpenShell would need to prove next is that a confined agent cannot reach the credentials it is injected with, and no source fetched for this piece reports an independent test of that.
Sources
More in Security
- 01Linux Kernel Nears 2,000 CVEs Per Release as AI Bug Reports Pile UpGreg Kroah-Hartman's figures show a fourfold jump from the 6.x series, while one vendor's count puts real exploitation signal at 1 in 400.
- 02Apple Says macOS Full Disk Access Will Require 'Very Explicit User Action'An October 2 developer post cites AI agents as the reason, but gives no macOS version, no date and no list of affected apps.
- 03Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 04Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.