Ross ROSS = Recommend OSS · open-source software intelligence for agents

NVIDIA/OpenShell

OpenShell is the safe, private runtime for autonomous AI agents. observed · 2026-08-28

github.com/NVIDIA/OpenShell · homepage · Rust · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

78/100

  • Activity 99
  • Release rhythm 87
  • Longevity 13
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 1
  • age_days: 190
  • days_rel: 8
  • days_push: 7
  • n_releases_24m: 92

Full methodology

Adoption not part of the score

8378 stars · 1231 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

NVIDIA OpenShell is an open-source runtime for executing autonomous AI agents (Claude Code, Codex, OpenCode, Copilot CLI) inside sandboxed environments with kernel-level isolation. It combines a CLI, a gateway control plane, and an in-sandbox supervisor that enforce declarative YAML policies over filesystem access, network egress, and credentials to prevent data exfiltration and unauthorized actions.

Use cases

  • run AI coding agents in a sandbox without giving them unrestricted file or network access
  • prevent AI agents from exfiltrating credentials or data
  • enforce declarative security policies on autonomous agent execution
  • isolate agent workloads with microvms, Docker, Podman, or Kubernetes
  • route agent LLM inference through controlled providers like Vertex AI
  • audit and log agent network and filesystem activity
  • deploy a secure agent gateway to a Kubernetes or OpenShift cluster

When to choose

  • you run autonomous AI agents (Claude Code, Codex, OpenCode, Copilot CLI) and need kernel-level isolation and egress control
  • you want declarative YAML policies governing what agents can access
  • you need a self-hosted gateway with observability, mTLS, and Kubernetes/OpenShift deployment

When to avoid

  • you need a production-hardened solution - the project is explicitly alpha with breaking changes expected
  • you only need simple container isolation without agent-specific policy enforcement
  • you cannot run Docker, Podman, MicroVMs, or Kubernetes as a compute driver

Facets

application · maturity experimental

security agent-framework configuration-management monitoring logging cli container-runtime secrets-management networking security developer-tools self-hosted privacy infrastructure-as-code windows cli self-hosted rust python sandbox ai-agent-security microvm policy-enforcement data-exfiltration-prevention kernel-isolation gateway supervisor yaml-policies claude-code codex opencode copilot-cli helm-chart mtls sandboxing ai-agents containers linux macos docker kubernetes

9 sources

Member repositories

RepositoryRoleHealth v2
NVIDIA/OpenShellmain78

For agents

markdown · JSON · MCP: product_card(name="NVIDIA/OpenShell")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem