NVIDIA's OpenShell Gained 2,503 Stars in a Day, and Its Sandbox Policy Cannot Read Intent
Software / news
NVIDIA's OpenShell Gained 2,503 Stars in a Day, and Its Sandbox Policy Cannot Read Intent
Three 0.1.x releases in four days, 337 open issues and a published exfiltration test explain what the star count does and does not measure.

NVIDIA's OpenShell, an Apache 2.0 runtime for confining autonomous AI agents, picked up 2,503 GitHub stars on the Oct. 1, 2026 trending list, the largest one-day gain of any repository on it. The repository showed 13,800 stars and 1,600 forks when The Terminal read it, and it is still labelled 0.1.x.
Stars measure attention, not deployment. What is verifiable from the repository is a project that changed shape three times in four days.
Three releases between Sept. 25 and Sept. 28
The release page lists v0.1.0 on Sept. 25, v0.1.1 on Sept. 26 and v0.1.2 on Sept. 28. The first of them is the one that matters: it moves sandbox authentication into drivers, adds first-party standalone drivers, splits the Helm charts into separate gateway and workspace charts, and makes provider profiles authoritative. The release notes call it a major architectural shift.
| Release | Date | Change that affects operators |
|---|---|---|
| v0.1.0 | Sept. 25 | Drivers own sandbox authentication; Helm charts split in two |
| v0.1.1 | Sept. 26 | WebSocket tunnel becomes opt-in; snap gateway requires mTLS |
| v0.1.2 | Sept. 28 | Supervisor network keeps workload bytes with a mediated CONNECT header |
The v0.1.1 change is the one a deployed user would notice. A gateway that relied on the WebSocket tunnel stops working until someone turns it on. Nothing in the three notes mentions a security fix.
What the runtime does
Per its README, OpenShell enforces policy on file access, system calls and network connections, and checks policy changes before they apply so that new permissions get flagged. It says agents "never see real credentials": the runtime adds them only to requests bound for approved endpoints. It runs on Linux, on macOS with Apple Silicon, and on Windows through WSL 2, and needs Docker, Podman or host virtualization.

The repository also holds a VM runtime release dated May 6, 2026, which ships kernel artifacts built on libkrunfw and libkrun for Linux x86_64, Linux ARM64 and macOS ARM64.
NemoClaw adds the agent layer
Most people meet OpenShell through NemoClaw, NVIDIA's reference stack that runs OpenClaw, Hermes or LangChain Deep Agents Code inside an OpenShell sandbox. NemoClaw shows 22,600 stars and describes itself as an alpha project: its maintainers review issues and pull requests "on a best effort basis without guaranteed response timelines."
- NemoClaw23K stars
- OpenShell14K stars
Source: github.com/NVIDIA/OpenShell and github.com/NVIDIA/NemoClaw, accessed 2026-10-01
Both READMEs carry a notice that the software retrieves external materials and that users take the risk.
Where the policy stops
On April 23, 2026, Noy Pearl of Lasso Security published two exfiltration scenarios against an OpenClaw agent in NVIDIA's sandbox. In one, a malicious npm package encodes credentials as emoji and pushes them out through the allowlisted git and gh binaries. In the other, a package installs a cron job that probes for open egress channels, sends out bash history and API keys, and edits the agent's SOUL.md instructions.
Lasso's conclusion: "OpenShell's binary-scoped egress policies are correctly enforced, but they cannot evaluate intent." The sandbox did what its policy said. The policy permitted npm, git and node because the agent needs them.
Lasso reports that NVIDIA replied the scenarios "fall outside the program's scope" and that NemoClaw "provides sandboxed execution environments to limit the impact of prompt injection scenarios." Lasso disagreed, writing that the sandbox "did not limit the impact" of its demonstrations. The Lasso post mentions no fix, and The Terminal did not find one in the three release notes above. This is a single-source account of the NVIDIA exchange, and NVIDIA's own reply was not available to read.
The maintenance load is visible too. The issue tracker shows 337 open issues, many flagged triage-needed, including a rootless RHEL HPC capability probe failure and an installer that ignores XDG_CONFIG_HOME. A draft task to align with CNCF security guidelines is still open.
Other open-source tooling in this space has had its own gap between stars and checking. PageIndex reached 38,142 stars on a benchmark its maker ran, and CISA's exploited-flaw list now includes AI gateway software.
Until the project leaves 0.1.x, the policy files, not the star count, are what an operator has to read.
Sources
More in Software
- 01Ponytail Hits 151,400 GitHub Stars on a Claim of 54% Less Code, Measured by Its AuthorThe plugin tells coding agents to write the minimum. Its benchmark used Claude Haiku 4.5 on one FastAPI template, four runs per ticket, and its tracker has 98 open issues.
- 02OpenDLSS-NR Reimplements Nvidia's DLSS 5 Network in Vulkan, but You Supply the WeightsThe MIT-licensed repository claims byte-for-byte parity with Nvidia's network, yet ships no weights, so the claim cannot be reproduced from the repo alone.
- 03Mozilla Shuts Down Solo AI Website Builder; All Sites Deleted Nov. 30The export ZIP leaves out image source files, Pro subscribers get prorated refunds from Oct. 1, and Mozilla points users to Wix, Squarespace, WordPress, Bolt and Lovable.
- 04IANA Says Example.com's Animated Redesign Is About Bandwidth, Not LooksKim Davies told a Google engineer the page was split to save bytes on automated traffic. Commenters measured 713 bytes of HTML plus 2.15 kB of script and are not convinced.