NVIDIA OpenShell puts runtime guards around AI agents
OpenShell 0.1.0 enforces what an agent may touch — credentials, services and files — from outside the agent itself, and Cadence, Slack and Gecko Robotics are already running it.

NVIDIA has open-sourced the layer that decides what an AI agent is allowed to touch. OpenShell 0.1.0, published on the company's developer blog, sits outside the agent and enforces permissions on its behalf, so a team can hand over the access a task needs without handing over everything else as well.
The reasoning is straightforward. Agents are being pointed at long-horizon work — investigating failures, running experiments, acting on business systems over days or weeks — and useful agents need workspaces, compute, data, credentials and outside services to do any of it. Every one of those is also a failure mode: production data changed by accident, confidential material exposed, or an agent quietly acting past the task it was given.
What OpenShell actually enforces
The runtime bundles four things: sandboxed execution, controlled service access, credential management and formal policy analysis. Its Gateway, Supervisor and Sandbox components run agent fleets, inspect outbound requests against policy and apply kernel-level controls on filesystems and processes. Credentials are held outside the agent's own workload rather than inside it, which means a compromised or confused agent has nothing useful to leak.
The policy prover is the unusual part. It uses formal logic to check that modelled permissions stay inside the boundaries a team defined, and to flag actions that would cross them — answering a question that ordinary allow-lists answer badly, which is whether a set of rules is actually airtight or merely long. Teams can build locally against a sandbox and deploy into shared infrastructure through workspaces, with compute drivers for Docker and Kubernetes and middleware for identity services.
Who is already running it
NVIDIA says OpenShell supports Codex, Claude Code, Pi, Hermes and later frameworks, and that adoption is coming from outside the usual demo circuit. Cadence is using it for chip design work around its ChipStack Autonomous RTL Design Engineer, Slack is building an on-demand agent platform on it, and Gecko Robotics is using it to govern agents making decisions on physical robots. OpenShell also forms the runtime layer of NVIDIA's Open Agent Safety Platform, which stretches the same idea across applications and infrastructure.
Our opinion
Most agent safety talk is written as though the danger is a rogue model. It is usually a perfectly obedient model holding a credential it should never have been given. OpenShell is interesting because it takes the boring, correct position: the place to solve this is the runtime, not the prompt, and the enforcement has to belong to something the agent cannot edit.
Putting the controls outside the agent is also the only version of this that survives contact with real deployments. Anyone who has watched a framework upgrade invalidate a carefully tuned prompt guard will recognise the appeal of a layer that does not need the agent rewritten to work.
The open question is the policy prover. Formal verification is a genuine differentiator if it holds up on real permission sets, and a very expensive way to draw a diagram if it does not. Cadence in chip design and Gecko on physical robots are the right first customers to find out — both are environments where an agent doing something unplanned is not an inconvenience but a defect. OpenShell has picked a sensible layer of the stack to own.