Agents are most useful when they can read files, install packages, call APIs and use credentials - the very capabilities that make them dangerous once they have unrestricted access to your data, secrets or network. NVIDIA's OpenShell, an Apache-2.0 runtime and sandboxing stack for fleets of autonomous agents, takes that trade-off head-on: you declare what each agent can touch in a policy, and OpenShell enforces it.

Enforcement runs deep. Each agent runs in an isolated sandbox; kernel controls confine which files it can access and which system calls it can make, and every network connection passes a policy check before it leaves the sandbox. Agents also never see real credentials - OpenShell adds them only to requests bound for approved endpoints.

The second piece is how policy changes are handled. Before a change is approved, OpenShell uses formal verification to flag risky new access it would grant - reaching a new host with credentials, for example, or calling a new API method - so those changes wait for human review. The documentation also describes a policy advisor that lets a running sandboxed agent request a narrow network policy change after OpenShell denies a request.

Installing sets up the CLI and a local gateway; the default sandbox image is a minimal Ubuntu with no agent installed, and the project's first-agent tutorial runs OpenCode against a free OpenRouter model so you can watch access requests arrive and be approved. Requirements are Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman or host virtualization. A gateway can be deployed to Kubernetes with Helm, where the CNI must enforce `NetworkPolicy`. SDKs are published for Python, TypeScript, Go and Rust.

The project ships in the 0.1.x line with what it calls a stable release cadence, new isolation primitives and an expanded extension surface. Attention is clearly there: a GitHub Trending snapshot on 30 September recorded roughly 990 new stars in a single day. OpenShell collects anonymous telemetry limited to operational categories and counts - not sandbox names, hostnames, file paths, prompts, credentials, or provider and model names - and it can be disabled with `OPENSHELL_TELEMETRY_ENABLED=false`.