Pimp My IDE / garage dispatch
Back to garage
September 28, 2026 | agent containment / OpenShell 0.1.2

Put the bouncer outside the agent.

A model cannot be its own permission boundary. Keep the workload untrusted. Put file, process, network, and credential decisions on the other side of a wall the agent cannot rewrite.

The useful safety unit is not another warning in the prompt. It is a request that must cross a separate enforcement path.

Nvidia is selling a boundary, not better manners.

CNBC reports that Nvidia announced an Open Agent Safety Platform on September 28. The report names two parts. OpenShell limits agent capabilities on central processors. Sentry monitors agent activity on network chips. Nvidia calls the broader package a reference design for partners, so the announcement is not one finished box that operators can buy and trust by default.[1]

The concrete artifact is OpenShell. Nvidia's public repository published version 0.1.2 on September 28. The release has checksummed Linux and macOS command-line binaries, gateway builds, sandbox components, and a standalone policy prover. We downloaded the x86-64 Linux command-line archive, matched its published SHA-256 checksum, and ran openshell --version and openshell --help. Both reported version 0.1.2.[2]

The agent asks. A different process decides.

The supervisor belongs across the wall.

OpenShell's architecture puts the agent workload inside a sandbox and the supervisor on the trusted side. The workload may connect only to that supervisor. The supervisor checks requests against policy, resolves approved destinations, adds credentials for approved providers, and opens approved connections. The agent does not receive the real credential.[3]

That separation matters more than the product name. A rule inside the agent's context competes with every other instruction the model reads. An outer fence does not need the model to agree. The model can propose a destination, method, file access, or policy change. The trusted side can deny it.

Monitoring and enforcement are different jobs.

A network observer can show where traffic went. It cannot prove that an earlier file read was allowed, that a system call stayed inside policy, or that a credential reached only its intended endpoint. OpenShell's documentation describes separate controls for files, system calls, network egress, credentials, and policy changes. Each claim needs evidence from the control that owns it.[3]

CNBC's description of Sentry is useful but thin. The article says it runs on network chips and monitors agents. It does not publish a complete threat model, enforcement contract, bypass analysis, or independent evaluation. Treat that part as an announced monitoring component. Do not turn it into proof that an agent deployment is contained.

Accountability still has names.

One same-day essay argues that the people who build and deploy an agent still own the outcome. It uses the Swiss cheese model to argue for several controls instead of one perfect guard. That is opinion, not a technical specification, but the ownership point is sound. An agent does not approve its own budget, place itself on a production network, or decide which credentials the host makes available.[4]

Name the person or team that owns the policy. Name the system that enforces it. Name the log that records the decision. If those answers collapse into "the agent decided," there is no boundary to inspect after an incident.

Wire the release test around denied work.

  1. Run the workload as untrusted code. Keep policy evaluation outside its writable environment.
  2. Deny network egress except through one mediated path.
  3. Bind credentials to approved destinations and methods. Do not place reusable secrets inside the workload.
  4. Review policy expansion as a release change. Test the denied case before the approved case.
  5. Record the requester, rule, decision, destination, method, credential class, and result without logging the secret.
  6. Test teardown and revocation. A clean approval path says nothing about a stale sandbox or orphaned credential.
Interactive makeover / boundary relay cutaway

Rehearse the request path

Traditional purpose replaced: one broad "agent access" switch. Better version: select a request case, close four independent boundary requirements, watch the packet stop at the responsible station, and copy a test card.

Set the boundary contract

These controls write a test plan. They do not configure OpenShell, a network chip, or the host.

Request rehearsal
Boundary requirements
Boundary draft1 of 4 requirements selected
Display-only request path

Boundary relay cutaway

The boundary contract needs three more requirements.

One requirement is selected. The route diagram shows the chosen rehearsal case, not a live network decision.

What this component proves. It keeps the workload, fence, supervisor, destination, credential rule, and receipt requirement distinct in one test-card structure. It does not inspect a host, enforce policy, send traffic, inject credentials, or prove containment.

Sources and limits

Open the source log
  1. CNBC, "Nvidia releases software platform to stop AI agents from misbehaving", September 28, 2026. This report supplies the Open Agent Safety Platform announcement, Nvidia quotes, partner list, and the description of OpenShell and Sentry. It does not provide a complete threat model or independent evaluation.
  2. NVIDIA OpenShell 0.1.2 release, September 28, 2026. The release supplies the downloadable command-line artifact and published checksums. We verified the checksum for the x86-64 Linux musl archive and exercised its version and help commands. We did not deploy a gateway or claim an end-to-end containment result.
  3. NVIDIA OpenShell architecture documentation, version 0.1.2, read September 28, 2026. It documents the workload, outer network fence, supervisor, policy, provider, prover, gateway, mediated channel, and credential path. These are first-party design claims.
  4. Herman Groenbroek, "Who should be held accountable when an AI Agent accidentally acts maliciously?", September 28, 2026. This is an opinion essay about operator responsibility, layered controls, and human supervision. It does not verify Nvidia's implementation.
  5. Hacker News discussion of the CNBC report, September 28, 2026. The thread is a discovery and discussion source. Claims above come from the article, release artifact, and architecture documentation.

Evidence boundary. OpenShell 0.1.2 is a real, downloadable artifact. A command-line smoke check proves only that the published binary runs and identifies itself. Nvidia's broader platform and Sentry claims remain announcement-level here. The interactive cutaway is a planning tool, not telemetry.