# NVIDIA OpenShell **Entity class:** Open-source secure runtime for AI agents **Developer:** [[wiki/NVIDIA|NVIDIA]] **License:** Apache 2.0 **As of:** 2026-09-28 ## Definition **NVIDIA OpenShell** is an open-source runtime that governs how autonomous AI agents execute, which files, processes, networks, tools, credentials and model endpoints they may reach, and where inference requests are sent. It places enforcement outside the agent process so that prompt content and model output cannot directly remove the boundary. OpenShell is model-agnostic and harness-agnostic rather than another agent framework; NVIDIA documents support for open and closed models and for agent paths including Claude Code, Codex, GitHub Copilot CLI, Hermes, LangChain Deep Agents, OpenClaw and OpenCode. ## Architecture Each agent runs in an isolated sandbox with kernel-level restrictions and no direct network access. A supervisor outside the sandbox evaluates outbound requests against policy, releases credentials only after authorization and records every allow-or-deny decision. A gateway manages identity, sandbox lifecycle, policy, settings and credentials across a fleet. A formal policy prover checks whether modeled permissions stay inside operator-defined boundaries and can identify a concrete action that would exceed them. OpenShell can run across local, cloud, hybrid, on-premises, edge and air-gapped environments. NVIDIA optimizes it for [[wiki/NVIDIA Vera CPU|NVIDIA Vera CPU]], while its open-source design can extend to third-party compute platforms including Arm and Intel. OpenShell does not require [[wiki/BlueField-4|BlueField-4]]; the hardware becomes relevant when [[wiki/NVIDIA Sentry|NVIDIA Sentry]] is added as an independent enforcement layer. ## Relationships - **core software component of:** [[wiki/NVIDIA Open Agent Safety Platform|NVIDIA Open Agent Safety Platform]]. - **paired with:** [[wiki/NVIDIA Sentry|NVIDIA Sentry]]. - **optimized compute path:** [[wiki/NVIDIA Vera CPU|NVIDIA Vera CPU]]. - **governs:** [[wiki/Agentic AI|agentic AI]] execution through externalized policy and audit. - **ecosystem relationship:** [[wiki/Open Secure AI Alliance|Open Secure AI Alliance]]. - **supported OpenAI harness:** Codex; support indicates technical compatibility and does not establish [[wiki/OpenAI|OpenAI]] as a launch-ecosystem participant. - **interpretive source article:** [[articles/Safety Discourse Is Transition Discourse|Safety Discourse Is Transition Discourse]]. ## Sources / Provenance - [NVIDIA — OpenShell](https://www.nvidia.com/en-us/ai/openshell/). - [NVIDIA OpenShell documentation](https://docs.nvidia.com/openshell/dev/about/overview). - [NVIDIA OpenShell repository](https://github.com/NVIDIA/OpenShell). - [NVIDIA Technical Blog — Open Agent Safety Platform reference design](https://developer.nvidia.com/blog/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring/).