Nvidia's OpenShell Sandboxes Agents, but Filesystem Rules Freeze at Creation
Software / explainer
Nvidia's OpenShell Sandboxes Agents, but Filesystem Rules Freeze at Creation
The Apache 2.0 runtime hides real credentials from Claude Code and Codex, and its own GitHub issues show macOS support is still being built.

Nvidia's OpenShell, an Apache 2.0 runtime that runs autonomous coding agents inside kernel-level sandboxes, has 11,867 stars and 1,499 forks on GitHub after a launch on Sept. 28. Its own documentation says filesystem and process limits are fixed when a sandbox is created, while network rules can change while the agent runs.
That split decides how much friction a developer meets on the first afternoon, so it is worth laying out before the star count. Nvidia's technical blog, by Alex Watson, senior director of product for NVIDIA AI, and Ali Golshan, senior director of AI software, describes OpenShell 0.1.0 and names Codex, Claude Code, Pi and Hermes as agents it can wrap without changes to the agent.

What runs where in OpenShell 0.1.x
The README describes three parts: a gateway that manages sandbox lifecycles, a supervisor that checks outbound requests, and the sandbox that applies the kernel controls. Policies are written in YAML and compiled to OPA/Rego, the policy language of the Open Policy Agent project, for evaluation on each connection.
The blog's worked example is a GitHub policy that names the endpoint, restricts which binaries may reach it and allows reads while blocking writes through the same API.
| Control | When it is set | Can it change mid-run |
|---|---|---|
| Filesystem access | At sandbox creation | No, needs a new sandbox |
| Process restrictions | At sandbox creation | No, needs a new sandbox |
| Network policy | Per outbound request | Yes, without restart |
The table is taken from the blog's limitations section. A developer who realises a build step needs one more directory has to recreate the sandbox.
Credentials the agent never holds
The design choice that separates OpenShell from a plain container is credential handling. Agents receive placeholder credentials, and the supervisor substitutes the real ones outside the workload, bound to approved endpoints only. The README puts it this way: "Agents never see real credentials; OpenShell adds them only to requests bound for approved endpoints."
The consequence is practical. A prompt injection that tells an agent to print its environment gets a placeholder, and a token valid for one service is not usable for another.
The README also lists a policy prover, which it says uses formal verification, mathematical checking of what a rule allows, before a policy change is approved. Nvidia says that in adversarial testing its agents spent up to two hours trying to talk reviewers into granting access, and that the prover's analysis held. That is a vendor account of vendor testing, with no independent run behind it.
What the issue tracker says about macOS
The README lists Linux, macOS on Apple Silicon, and Windows with WSL 2 (marked experimental) as supported, plus Docker, Podman or host virtualization. GitHub's API reports 510 open issues and pull requests combined, counted the way GitHub counts them.
Among the most recent are #3955, titled "Make OpenShell sandboxes reliable on macOS," and #3956, on native macOS process sandboxes on managed Macs. Both sit beside #3951, on checking and supplying MicroVM filesystem tools for a macOS compatibility case. Support is listed in the README. Reliability, by the project's own tracker, is still a work item.
The other install note is the quickstart itself. It pipes a script from the main branch of the repository into a shell, curl -LsSf from raw.githubusercontent.com. The latest tagged release is v0.1.2, dated Sept. 28 per the GitHub API, and the repository also publishes a dev build from every commit that passes CI, which it labels unstable.
Who is using it, and who is not
Quantum Zeitgeist, in its own write-up of the 0.1.0 launch, lists Cadence for chip design automation, Slack for on-demand agent platforms and Gecko Robotics for physical robot governance as adopters. That list comes from the launch material, and no adopter has been quoted on what it runs in production.
OpenShell is the software half of Nvidia's Open Agent Safety Platform. The hardware half is covered in Nvidia's Sentry piece, where only OpenShell could be downloaded. The need for a runtime like this is visible in Meta's Muse agent syncing 187,000 message rows after a user declined access.
The README carries a disclaimer that the software "automatically retrieves, accesses or interacts with external materials," and puts compliance on the user. Version 0.1.x carries an upgrade guide for 0.1.0 already, so the next thing to watch is whether the macOS reliability issues close before a 0.2 tag.
Sources
More in Software
- 01Ponytail Hits 151,400 GitHub Stars on a Claim of 54% Less Code, Measured by Its AuthorThe plugin tells coding agents to write the minimum. Its benchmark used Claude Haiku 4.5 on one FastAPI template, four runs per ticket, and its tracker has 98 open issues.
- 02OpenDLSS-NR Reimplements Nvidia's DLSS 5 Network in Vulkan, but You Supply the WeightsThe MIT-licensed repository claims byte-for-byte parity with Nvidia's network, yet ships no weights, so the claim cannot be reproduced from the repo alone.
- 03Mozilla Shuts Down Solo AI Website Builder; All Sites Deleted Nov. 30The export ZIP leaves out image source files, Pro subscribers get prorated refunds from Oct. 1, and Mozilla points users to Wix, Squarespace, WordPress, Bolt and Lovable.
- 04IANA Says Example.com's Animated Redesign Is About Bandwidth, Not LooksKim Davies told a Google engineer the page was split to save bytes on automated traffic. Commenters measured 713 bytes of HTML plus 2.15 kB of script and are not convinced.