Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
NemoClaw — Run agents like Hermes, LangChain Deep Agents, and OpenClaw more securely inside NVIDIA OpenShell with managed inference | Kitploit
Tools/GitHubGitHub/nvidia/nemoclaw
Container SecurityScripting & AutomationNetwork SecurityCloud SecurityDevSecOpsLearning & EducationAI Security
GitHubnvidia/nemoclaw

NemoClaw

Run agents like Hermes, LangChain Deep Agents, and OpenClaw more securely inside NVIDIA OpenShell with managed inference

View Repository
22.1k3.0k307h 53m agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

NVIDIA NemoClaw: Reference Stack for Sandboxed AI Agents in OpenShell

License Security Policy Discord

NVIDIA NemoClaw is an open source reference stack for running always-on AI agents more safely inside NVIDIA OpenShell sandboxes. It provides guided onboarding, a hardened blueprint, routed inference, network policy, and lifecycle management through a single CLI.

Supported agents:

  • OpenClaw (default)
  • Hermes
  • LangChain Deep Agents Code

For capabilities, architecture, security controls, and the full feature list, see the NemoClaw documentation.

Get Started

Start with Your Coding Agent

Use the starter prompt when you want Cursor, Claude Code, Codex, Copilot, or another local coding agent to install NemoClaw with you.

Copy the NemoClaw starter prompt.

The prompt tells your agent to use NemoClaw docs and skills, ask one question at a time, run commands only with your approval, and keep secrets out of chat.

Install Using the Interactive Installer in Your Terminal

Review Prerequisites before installing. For Hermes, set NEMOCLAW_AGENT=hermes before running the installer, or use the nemohermes alias after install. When connecting to a Hermes sandbox from a light terminal, NemoClaw may install a managed nemoclaw-light Hermes skin for readable assistant text; it removes that managed skin state again when the terminal no longer needs it and preserves any user-selected Hermes skin.

AgentGuide
OpenClaw (default)Quickstart with OpenClaw
HermesQuickstart with Hermes
LangChain Deep Agents CodeQuickstart with LangChain Deep Agents Code

Documentation

Refer to the following pages on the official documentation website for more information on NemoClaw.

PageDescription
OverviewWhat NemoClaw does and how it fits together.
Architecture OverviewHigh-level overview of Plugin, blueprint, sandbox lifecycle, and protection layers.
EcosystemHow OpenClaw, OpenShell, and NemoClaw form a stack and when to use NemoClaw versus OpenShell alone.
Architecture DetailsDetailed description of Plugin structure, blueprint lifecycle, sandbox environment, and host-side state.
PrerequisitesHardware, software, and supported platforms, with any platform-specific pre-setup.
Choose an Inference ProviderSupported providers, validation, and routed inference configuration.
Network PoliciesBaseline rules, operator approval flow, and egress control.
Customize Network PolicyStatic and dynamic policy changes, presets.
Security Best PracticesControls reference, risk framework, and posture profiles for sandbox security.
Sandbox HardeningContainer security measures, capability drops, process limits.
CLI CommandsFull NemoClaw CLI command reference.
TroubleshootingCommon issues and resolution steps.

Community

Join the NemoClaw community to ask questions, share feedback, and report issues. NemoClaw is an alpha project, so maintainers review issues, discussions, and pull requests on a best effort basis without guaranteed response timelines.

NeedChannel
Setup or usage questionsGitHub Discussions or Discord
Reproducible bugsGitHub Issues
Feature proposalsStart with GitHub Discussions, then open an issue when the scope is clear
Current prioritiesCurrent Priorities
Contribution helpCONTRIBUTING.md
Security vulnerabilitiesUse the private channels in SECURITY.md; do not open public issues

Contributing

We welcome contributions. See CONTRIBUTING.md for development setup, coding standards, and the PR process.

Prepare a source checkout without creating a runtime sandbox:

./scripts/dev-setup.sh

Or ask a compatible coding agent to use the repository's contributor-onboarding skill:

Set up this machine as a NemoClaw contributor and prepare it for a first PR.

The contributor path is separate from the end-user installer above. The default and --repair modes change only repository-local dependencies, builds, and hooks. Use ./scripts/dev-setup.sh --expose-cli only when you explicitly want a host-visible development CLI. Use ./scripts/dev-setup.sh --with-runtime only when your change needs sandbox validation; that approved flow also opts into CLI exposure.

Security

NVIDIA takes security seriously. If you discover a vulnerability in NemoClaw, DO NOT open a public issue. Use one of the private reporting channels described in SECURITY.md:

  • Submit a report through the NVIDIA Vulnerability Disclosure Program.
  • Send an email to [email protected] encrypted with the NVIDIA PGP key.
  • Use GitHub's private vulnerability reporting to submit a report directly on this repository.

For security bulletins and PSIRT policies, visit the NVIDIA Product Security portal.

Current Priorities

Download Tool