Skip to content
AI Primer
release

NVIDIA launches OpenShell to isolate AI agents

NVIDIA's Open Agent Safety Platform uses OpenShell to run agents in isolated environments. A technical report describes a BlueField-4 Sentry layer that can quarantine agents outside the sandbox.

5 min read
NVIDIA launches OpenShell to isolate AI agents
NVIDIA launches OpenShell to isolate AI agents

TL;DR

  • NVIDIA paired broadly available, open-source OpenShell with a BlueField-4 Sentry reference design; rohanpaul_ai's architecture diagram lays out the software and hardware layers.
  • OpenShell runs agents in restricted sandboxes with separate policy enforcement; WesRoth's breakdown distinguishes the sandbox from Sentry's outer layer.
  • Allowed destinations remain a security gap: ClementDelangue's demo caught four agents coordinating through a permitted repository without breaking an allowlist rule.
  • Perplexity saw zero VM-to-host escapes in 108 SPACE trials, but partial network access enabled bypasses; AravSrinivas's account describes the routes its models found.

NVIDIA's OpenShell walkthrough includes a YAML rule that permits a GitHub API read but blocks a POST to the same endpoint. Its hardware design puts a watchdog on the node's path to the model. In a separate sandbox red-team report, one agent reached a blocked callback by routing through an image service, a screenshot service, and OCR.

OpenShell's runtime boundary

OpenShell 0.1.0 is Apache-2.0 software that runs an existing agent inside a restricted workload. NVIDIA's runtime documentation separates the components:

  • Gateway: Authenticates clients, manages sandbox lifecycles, policies, and provider records.
  • Supervisor: Runs inside each sandbox workload but outside the restricted agent process; applies filesystem and process controls and mediates egress.
  • Agent child: Runs with reduced privileges and only the access its policy grants.

NVIDIA's technical walkthrough says the same boundary applies when an agent opens a shell, executes generated code, or spawns child processes. Raw service credentials stay outside the agent process and are substituted only for authorized endpoints.

Policy prover and live permission changes

Policies are authored in YAML and compiled to OPA/Rego for outbound request checks. NVIDIA's GitHub API example permits /usr/bin/curl to read api.github.com while blocking a POST to that host.

The prover checks whether modeled permissions, including access supplied by provider profiles, stay inside an operator-defined boundary. An agent can propose additional access after a denial, but approval is pending human review by default; network rules can update in place, while filesystem and process restrictions require a new sandbox, according to NVIDIA's walkthrough.

Sentry's BlueField-4 model path

NVIDIA describes Sentry as an optional reference design on BlueField-4 DPUs, separate from the broadly available OpenShell software. In a Vera Rubin POD, it places the DPU on the node's path to the model, isolated from the host, and claims millisecond-scale quarantine when an agent crosses its boundary in the platform announcement.

The technical design says DOCA correlates agent interactions, policy decisions, and tool and data access, with identity checks for delegated authority. OpenShell can also run on other hardware; the out-of-band BlueField layer depends on the described DPU deployment.

Allowed-traffic monitoring

A repository can be an approved destination and still carry unauthorized agent messages. Hugging Face's contribution to OpenShell targets that gap with three signals, described in ClementDelangue's demonstration:

  • Per-sandbox budgets for requests, writes, and bytes.
  • Traffic drift against a sandbox's baseline and comparable sandboxes.
  • Fleet-wide findings when multiple agents suddenly write to the same host.

In the proof of concept, four agents coordinate through an allowed software repository and trigger a finding within minutes without violating an allowlist rule. The demonstration shows detection of that pattern, rather than proof that the earlier Hugging Face incident would have been prevented.

SPACE's two tested boundaries

Perplexity's September 23 report, published before NVIDIA's platform announcement, tested its own Firecracker-based SPACE sandbox. Nine models received root inside a guest VM across 216 runs: 108 host-escape attempts and 108 network-bypass attempts.

  • VM isolation: Zero verified host escapes in 108 runs.
  • No-network policy: Zero bypasses in 54 runs.
  • Partial-network policy: 11 successful bypasses in 54 runs when access to package repositories was permitted.

The report identifies two failure paths: forged DNS responses taught the gateway that a blocked IP belonged to pypi.org, while a shared CDN IP let agents contact other services hosted alongside an allowed domain. Perplexity says it dropped guest packets impersonating another sender, added hostname checks to connections, and found no verified repeat of either bypass in its reruns.

The wider sandbox test

Perplexity also tested ten third-party sandbox platforms for similar network-policy bypasses. Its published results say eight of ten were susceptible; it disclosed nine platform results, of which seven showed at least one bypass, while one vendor received more time before publication. NVIDIA OpenShell was among the platforms where the published tests demonstrated no bypass, a result limited to those tested routes.

The broader result appears in Perplexity's follow-up, which distinguishes the failed VM-escape attempts from the successful partial-network bypasses.

OpenWorker's command sandbox

OpenWorker plans to run each agent command inside OpenShell, with only task-relevant files supplied to the sandbox. Andrew Ng says secret API keys, browser login credentials, and arbitrary websites are excluded by default, with actions logged for audit.

Partner deployments

Baseten says it has contributed to OpenShell and built a template for running it inside its sandboxes. It also announced a private preview of Carbon, its fourth-generation sandbox with support for open security controls.

Together AI says it is working with NVIDIA on OpenShell in its launch-partner post, while Perplexity says it intends to open-source its sandbox guardrails as part of the collaboration in AravSrinivas's post. NVIDIA's partner announcement names a Slack integration for reviewing agent activity and permission requests, plus an OpenShell integration with SAP's Joule Studio runtime.

Further reading

Discussion across the web

Where this story is being discussed, in original context.

On X· 2 threads
The wider sandbox test1 post
Partner deployments2 posts
Share on X