TrendWhat rose yesterday, every day at 07:30 KST · 한국어

GitHub · as of September 29, 2026

NVIDIA/OpenShell

Secure AI agent runtime

#2 on GitHub's daily trending, September 29, 2026 · first day trending · trending 1 of the last 30 days

How to secure data and networks when AI agents read files and call APIs

It prevents data and secret keys from leaking when AI agents open files, install packages, or call APIs. It provides an execution environment where you define what an agent can do in advance and immediately block any action that goes beyond that scope. By imagining the actual movements of the agent, you can clearly distinguish how far those movements are permitted.

New changes in version 0.1.x

OpenShell version 0.1.x adds a stable release cycle, new isolation primitives, an extended extension surface, and new APIs. Existing users should refer to the upgrade guide to check for changes. From this version onward, agent management becomes more systematic, and the verification process for policy changes is strengthened. To utilize new features, it is recommended to go through the update process along with the latest documentation.

Enforcing policies at the kernel level

OpenShell instruments the kernel inside the sandbox where the agent runs to inspect all file access, system calls, and network connections in real time. Each agent runs in an isolated environment, and unauthorized file access or system calls are blocked by kernel controls. Network connections must pass policy checks before leaving the sandbox. Agents cannot see actual credentials; OpenShell adds credentials only to requests directed at approved endpoints.

Pre-reviewing policy changes with formal verification

Before a policy change is approved, OpenShell uses formal verification to check if new access permissions are dangerous. For example, if a change involves accessing a new host using credentials or calling a new API method, these changes are held for human review. This helps block the possibility of unintended privilege escalation or data leakage in advance. Being able to predict the impact of policy changes before code execution helps prevent security incidents.

Installation environments and startup methods

It can be used in Linux, Apple Silicon-based macOS, or Windows with WSL 2 (experimental) environments. Docker, Podman, or host virtualization features are required. Running the installation script sets up the CLI and local gateway, and the default sandbox image is a minimal Ubuntu without agents installed. To run an actual agent, you must follow the first agent run guide using OpenCode and a free OpenRouter model. During this process, you can learn how to approve when an agent requests new access.

Things to check before use

OpenShell is licensed under the Apache License 2.0, and the software is provided 'AS IS' without any warranty. It automatically searches for and accesses external materials, but these materials are not distributed with this software and are governed by separate terms and licenses. It is the user's responsibility to verify the security, integrity, and suitability of the retrieved materials. Telemetry is collected anonymously, gathering only operational categories and counts; it does not collect sandbox names, file paths, prompts, or credentials. To disable telemetry, you can set OPENSHELL_TELEMETRY_ENABLED=false in the gateway or specify server.telemetryEnabled=false during Helm installation.

By the numbers

Language
Rust
Stars
10,300
Contributors
124
Forks
1,400
Days trending in the last 30
1 days
Latest release
v0.1.2 · September 28, 2026
Commits
1,563
Last commit
September 29, 2026
Open issues
298
Open pull requests
181

Written by AI from this repository's README. GitHub's original is the reference.

View on GitHub → · Homepage