How to secure data and networks when AI agents read files and call APIs
It prevents data and secret keys from leaking when AI agents open files, install packages, or call APIs. It provides an execution environment where you define what an agent can do in advance and immediately block any action that goes beyond that scope. By imagining the actual movements of the agent, you can clearly distinguish how far those movements are permitted.
New changes in version 0.1.x
OpenShell version 0.1.x adds a stable release cycle, new isolation primitives, an extended extension surface, and new APIs. Existing users should refer to the upgrade guide to check for changes. From this version onward, agent management becomes more systematic, and the verification process for policy changes is strengthened. To utilize new features, it is recommended to go through the update process along with the latest documentation.
Enforcing policies at the kernel level
OpenShell instruments the kernel inside the sandbox where the agent runs to inspect all file access, system calls, and network connections in real time. Each agent runs in an isolated environment, and unauthorized file access or system calls are blocked by kernel controls. Network connections must pass policy checks before leaving the sandbox. Agents cannot see actual credentials; OpenShell adds credentials only to requests directed at approved endpoints.
Pre-reviewing policy changes with formal verification
Before a policy change is approved, OpenShell uses formal verification to check if new access permissions are dangerous. For example, if a change involves accessing a new host using credentials or calling a new API method, these changes are held for human review. This helps block the possibility of unintended privilege escalation or data leakage in advance. Being able to predict the impact of policy changes before code execution helps prevent security incidents.
Installation environments and startup methods
It can be used in Linux, Apple Silicon-based macOS, or Windows with WSL 2 (experimental) environments. Docker, Podman, or host virtualization features are required. Running the installation script sets up the CLI and local gateway, and the default sandbox image is a minimal Ubuntu without agents installed. To run an actual agent, you must follow the first agent run guide using OpenCode and a free OpenRouter model. During this process, you can learn how to approve when an agent requests new access.
Things to check before use
OpenShell is licensed under the Apache License 2.0, and the software is provided 'AS IS' without any warranty. It automatically searches for and accesses external materials, but these materials are not distributed with this software and are governed by separate terms and licenses. It is the user's responsibility to verify the security, integrity, and suitability of the retrieved materials. Telemetry is collected anonymously, gathering only operational categories and counts; it does not collect sandbox names, file paths, prompts, or credentials. To disable telemetry, you can set OPENSHELL_TELEMETRY_ENABLED=false in the gateway or specify server.telemetryEnabled=false during Helm installation.