Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
OpenShell — Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound credential injection. | Kitploit
Strumenti/GitHubGitHub/nvidia/openshell
Authentication & AuthorizationDefensive ToolsContainer SecurityConfiguration AuditingSecurity VirtualizationNetwork SecurityCloud SecurityDevSecOpsSecret DetectionAI Security
GitHub
12.4k1.5k1995 giorni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
nvidia/openshell

OpenShell

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound credential injection.

Vedi RepositorySito web
Contenuto non disponibile nella lingua richiesta. Visualizzazione della versione inglese.
OpenShell

License PyPI Security Policy Documentation

[!IMPORTANT] New in OpenShell 0.1.x: a stable release cadence, new isolation primitives, an expanded extension surface, and new APIs. Read the 0.1.0 upgrade guide.

OpenShell is the safe, private runtime for fleets of autonomous AI agents. Agents are most useful when they can read files, install packages, call APIs, and use credentials. OpenShell gives them that capability without giving them unrestricted access to your data, secrets, or network. You declare what each agent can touch in a policy, and OpenShell enforces it.

How It Works

OpenShell governs what agents can do in two ways: it instruments the kernel to enforce policy on every file access, system call, and network connection at runtime, and it uses formal verification to check what a policy change would allow before it is applied.

  • Kernel-level enforcement. Each agent runs in an isolated sandbox. Kernel controls confine which files it can access and which system calls it can make, and every network connection passes through a policy check before it leaves the sandbox. Agents never see real credentials; OpenShell adds them only to requests bound for approved endpoints.
  • Formally verified policy changes. Before a policy change is approved, OpenShell uses formal verification to flag risky new access it would grant, such as reaching a new host with credentials or calling a new API method, so those changes wait for human review.

See Architecture for how the gateway, supervisor, and sandbox fit together.

Quickstart

You need Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman, or host virtualization. See the Support Matrix for details.

curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demo

The installer sets up the CLI and a local gateway. The default sandbox image is minimal Ubuntu with no agent installed. To run a real agent, follow Run Your First Agent: it runs OpenCode against a free OpenRouter model and shows how to approve new access as the agent needs it.

Explore Further

  • Sandboxes: images, runtimes, GPUs, and lifecycle.
  • Policies: filesystem, network, and process rules, with the advisor and prover for reviewing changes.
  • Providers: credentials that work only at approved endpoints, including inference.
  • Gateways: the control plane for sandboxes, policy, and access.
  • Kubernetes: deploy the gateway with Helm. Your CNI must enforce NetworkPolicy.
  • Extensibility: middleware, interceptors, and compute drivers.
  • Tutorials: step-by-step policy and agent walkthroughs.
  • Prerelease and development builds: try an upcoming release or the latest commit on main.

Agent Skills

Install the public OpenShell skills for your coding agent:

npx skills add NVIDIA/OpenShell

The skills teach your agent to drive the OpenShell CLI, write sandbox policies, and debug gateways and inference routing. They live in skills/ and work without an OpenShell source checkout.

SDKs

SDKs connect applications to an OpenShell gateway. They do not install the CLI. Use the same OpenShell release for the SDK and the gateway when possible.

LanguageInstallDocs
Pythonuv add openshellREADME
TypeScriptnpm install @nvidia/openshell-sdk (GitHub Packages)README
Gogo get github.com/NVIDIA/OpenShell/sdk/go@latestREADME
Rustcargo add openshell-sdk --git https://github.com/NVIDIA/OpenShell --tag <release-tag>Installation and usage

Community

  • Questions and discussion: GitHub Discussions
  • Bug reports and feature requests: GitHub Issues, using the issue templates
  • Security vulnerabilities: follow SECURITY.md. Do not open a GitHub issue.
  • Roadmap: OpenShell Roadmap and the RFC board
  • Try it in the cloud: Brev Launchable

OpenShell is built agent-first: it is developed with the same agent-driven workflows it enables. See CONTRIBUTING.md for development setup and the contribution workflow, and AGENTS.md for the contributor agent skills and workflow chains.

Telemetry

OpenShell collects anonymous telemetry, limited to operational categories and counts, to help improve the project. It does not collect sandbox names, hostnames, file paths, prompts, credentials, provider or model names, or user content. To disable it, set OPENSHELL_TELEMETRY_ENABLED=false on the gateway, or server.telemetryEnabled=false for Helm installs. You can also compile telemetry out entirely. See Telemetry for details and the community telemetry reports for published usage trends.

Notice and Disclaimer

Scarica lo strumento