OpenShell is a private runtime that lets autonomous AI agents read files, install packages, call APIs, and use credentials under kernel-enforced policy isolation instead of unrestricted access. Policy changes are formally verified, with risky new access flagged for human review before approval.
Project overview
Rather than relying on perimeter controls, OpenShell enforces policy at the kernel on every file access, system call, and network connection, and it formally verifies proposed policy changes before they take effect — a distinctive approach to the agent-safety problem.
Project type
AI Agent · Infrastructure
Use cases
Automation
Deployment
Refer to project documentation
License
Apache-2.0
Best for
Developers and teams who want agents to perform real tasks while keeping data, secrets, and the network protected by explicit, enforced policies.
Users comfortable supplying their own LLM provider for the agent, since the default sandbox image ships no agent.
Key capabilities
Before a policy change is approved, formal verification flags risky new access it would grant, such as reaching a new host with credentials or calling a new API method, so those changes wait for human review.
Limitations and risks
Windows support is only available via WSL 2 and is experimental.
On Kubernetes, your CNI must enforce NetworkPolicy for the gateway deployment; otherwise the network policy enforcement cannot be assumed.
The end-to-end data boundary is unclear, and running a real agent requires connecting an external LLM provider, so inference involves a remote service.
Telemetry in OpenShell is optional.
Getting started
A single-command installer sets up the CLI and local gateway. Setup requires Linux, macOS Apple Silicon, or Windows WSL 2, plus Docker, Podman, or host virtualization for the sandbox runtime. Running a real agent additionally requires a model provider setup.
Evidence and sources
README: OpenShell is the safe, private runtime for fleets of autonomous AI agents. Agents are most useful when they can read files, install packages, call APIs, and use credentials. OpenS…
README: it instruments the kernel to enforce policy on every file access, system call, and network connection at runtime, and it uses formal verification to check what a policy change wou…
README: You need Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman, or host virtualization.
README: - [Sandboxes](https://docs.nvidia.com/openshell/latest/how-it-works/sandboxes/overview): images, runtimes, GPUs, and lifecycle.
README: The skills teach your agent to drive the OpenShell CLI, write sandbox policies, and debug gateways and inference routing.