Let AI agents use files and passwords without ever seeing them
Made by NVIDIA Corporation
View profile on GitHub (opens in a new tab)OpenShell is NVIDIA’s open-source runtime for running AI agents safely: each agent gets an isolated workspace (a sandbox), and you write a policy saying what it may touch.
Enforcement happens at the kernel level — the operating system’s deepest layer — so every file access and network connection is checked against your rules, and agents never see your passwords: OpenShell adds credentials only to requests bound for destinations you approved. Installation is one command on Linux, Macs, or Windows via WSL2, plus Docker or a similar container tool. The team says policy changes pass formal verification, a proof-style check that flags risky new permissions for human review first.
Can I use this?
You'll need Linux, an Apple-Silicon Mac, or Windows with WSL2, plus Docker or similar · Setup needed
Worth knowing The project is young (0.1.x releases) and Windows support is experimental. A policy only protects what you configure — an overly broad policy still grants broad access. BuildTube has not run or verified this software.
Why it's here
- 3,162 people starred it on GitHub this week — 13,810 in total.
Numbers from the snapshot taken 1 October 2026; not refreshed since.
Behind it
See the code on GitHubBuildTube has not run or verified this project. Everything above is written from what the creator published.
Made this?