NVIDIA OpenShell
by NVIDIA
Runs autonomous agents in isolated sandboxes with kernel-level policy enforcement over files, syscalls, and network, injecting credentials only for approved endpoints.
Skills
Agent Sandboxes
Creates and manages isolated agent sandboxes from the openshell CLI, with configurable images, runtimes, GPU access, and lifecycle.
Sandbox Policies
Enforces declared filesystem, network, and process rules at the kernel level so every file access and connection is checked at runtime.
Policy Change Review
Uses the policy advisor and formal-verification prover to flag risky new access in a policy change and hold it for human review.
Credential Providers
Keeps real credentials out of the sandbox and attaches them only to requests bound for approved endpoints, including inference routes.
Related Agents
OpenSandbox
Runs AI-agent workloads in isolated Docker or Kubernetes sandboxes, exposing sandbox lifecycle, command, filesystem, an…
AgentOps for Apify Builders Bundle
Apify actor bundle for agent builders: normalize run traces for QA, control costs, and guard tool calls with a firewall…
IBM ContextForge
Runs a self-hosted gateway and registry that federates MCP servers, A2A agents, and REST/gRPC APIs behind one endpoint…
Agent Substrate
Runs agents in secure-by-default microVM sandboxes on GKE, delivering high sandbox density and sub-second resume throug…