openshell 0.1.2


pip install openshell

  Latest version

Released: Sep 28, 2026


Meta
Author: NVIDIA Inc.
Requires Python: >=3.11

Classifiers

Development Status
  • 3 - Alpha

Intended Audience
  • Developers
  • Science/Research
  • Information Technology

Programming Language
  • Python :: 3
  • Python :: 3.11
  • Python :: 3.12
  • Python :: 3.13
  • Python :: 3.14

Topic
  • Security
  • Scientific/Engineering
  • Scientific/Engineering :: Artificial Intelligence

Operating System
  • POSIX :: Linux
  • MacOS :: MacOS X
OpenShell

License PyPI Security Policy Documentation

[!IMPORTANT] New in OpenShell 0.1.x: a stable release cadence, new isolation primitives, an expanded extension surface, and new APIs. Read the 0.1.0 upgrade guide.

OpenShell is the safe, private runtime for fleets of autonomous AI agents. Agents are most useful when they can read files, install packages, call APIs, and use credentials. OpenShell gives them that capability without giving them unrestricted access to your data, secrets, or network. You declare what each agent can touch in a policy, and OpenShell enforces it.

How It Works

OpenShell governs what agents can do in two ways: it instruments the kernel to enforce policy on every file access, system call, and network connection at runtime, and it uses formal verification to check what a policy change would allow before it is applied.

  • Kernel-level enforcement. Each agent runs in an isolated sandbox. Kernel controls confine which files it can access and which system calls it can make, and every network connection passes through a policy check before it leaves the sandbox. Agents never see real credentials; OpenShell adds them only to requests bound for approved endpoints.
  • Formally verified policy changes. Before a policy change is approved, OpenShell uses formal verification to flag risky new access it would grant, such as reaching a new host with credentials or calling a new API method, so those changes wait for human review.

See Architecture for how the gateway, supervisor, and sandbox fit together.

Quickstart

You need Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman, or host virtualization. See the Support Matrix for details.

curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demo

The installer sets up the CLI and a local gateway. The default sandbox image is minimal Ubuntu with no agent installed. To run a real agent, follow Run Your First Agent: it runs OpenCode against a free OpenRouter model and shows how to approve new access as the agent needs it.

Explore Further

Agent Skills

Install the public OpenShell skills for your coding agent:

npx skills add NVIDIA/OpenShell

The skills teach your agent to drive the OpenShell CLI, write sandbox policies, and debug gateways and inference routing. They live in skills/ and work without an OpenShell source checkout.

SDKs

SDKs connect applications to an OpenShell gateway. They do not install the CLI. Use the same OpenShell release for the SDK and the gateway when possible.

Language Install Docs
Python uv add openshell README
TypeScript npm install @nvidia/openshell-sdk (GitHub Packages) README
Go go get github.com/NVIDIA/OpenShell/sdk/go@latest README
Rust cargo add openshell-sdk --git https://github.com/NVIDIA/OpenShell --tag <release-tag> Installation and usage

Community

OpenShell is built agent-first: it is developed with the same agent-driven workflows it enables. See CONTRIBUTING.md for development setup and the contribution workflow, and AGENTS.md for the contributor agent skills and workflow chains.

Telemetry

OpenShell collects anonymous telemetry, limited to operational categories and counts, to help improve the project. It does not collect sandbox names, hostnames, file paths, prompts, credentials, provider or model names, or user content. To disable it, set OPENSHELL_TELEMETRY_ENABLED=false on the gateway, or server.telemetryEnabled=false for Helm installs. You can also compile telemetry out entirely. See Telemetry for details and the community telemetry reports for published usage trends.

Notice and Disclaimer

This software automatically retrieves, accesses or interacts with external materials. Those retrieved materials are not distributed with this software and are governed solely by separate terms, conditions and licenses. You are solely responsible for finding, reviewing and complying with all applicable terms, conditions, and licenses, and for verifying the security, integrity and suitability of any retrieved materials for your specific use case. This software is provided "AS IS", without warranty of any kind. The author makes no representations or warranties regarding any retrieved materials, and assumes no liability for any losses, damages, liabilities or legal consequences from your use or inability to use this software or any retrieved materials. Use this software and the retrieved materials at your own risk.

License

This project is licensed under the Apache License 2.0.

0.1.2 Sep 28, 2026
0.1.1 Sep 26, 2026
0.1.0 Sep 25, 2026
0.0.116 Aug 28, 2026
0.0.115 Aug 27, 2026
0.0.113 Aug 25, 2026
0.0.111 Aug 21, 2026
0.0.110 Aug 20, 2026
0.0.109 Aug 19, 2026
0.0.106 Aug 14, 2026
0.0.105 Aug 13, 2026
0.0.104 Aug 12, 2026
0.0.103 Aug 11, 2026
0.0.102 Aug 10, 2026
0.0.101 Aug 07, 2026
0.0.99 Aug 05, 2026
0.0.98 Aug 04, 2026
0.0.97 Aug 03, 2026
0.0.96 Jul 31, 2026
0.0.92 Jul 27, 2026
0.0.91 Jul 24, 2026
0.0.90 Jul 23, 2026
0.0.89 Jul 22, 2026
0.0.88 Jul 21, 2026
0.0.86 Jul 17, 2026
0.0.85 Jul 16, 2026
0.0.83 Jul 14, 2026
0.0.82 Jul 13, 2026
0.0.80 Jul 09, 2026
0.0.79 Jul 08, 2026
0.0.78 Jul 07, 2026
0.0.77 Jul 06, 2026
0.0.76 Jul 03, 2026
0.0.75 Jul 02, 2026
0.0.74 Jul 01, 2026
0.0.73 Jun 30, 2026
0.0.72 Jun 29, 2026
0.0.71 Jun 26, 2026
0.0.70 Jun 25, 2026
0.0.69 Jun 24, 2026
0.0.68 Jun 23, 2026
0.0.67 Jun 22, 2026
0.0.66 Jun 18, 2026
0.0.65 Jun 17, 2026
0.0.63 Jun 15, 2026
0.0.62 Jun 12, 2026
0.0.59 Jun 09, 2026
0.0.58 Jun 08, 2026
0.0.57 Jun 05, 2026
0.0.56 Jun 04, 2026
0.0.55 Jun 03, 2026
0.0.54 Jun 02, 2026
0.0.53 Jun 01, 2026
0.0.52 May 29, 2026
0.0.51 May 28, 2026
0.0.50 May 27, 2026
0.0.47 May 22, 2026
0.0.46 May 21, 2026
0.0.45 May 20, 2026
0.0.44 May 19, 2026
0.0.42 May 15, 2026
0.0.41 May 14, 2026
0.0.40 May 13, 2026
0.0.39 May 12, 2026
0.0.38 May 11, 2026
0.0.37 May 08, 2026
0.0.36 Apr 23, 2026
0.0.35 Apr 22, 2026
0.0.34 Apr 21, 2026
0.0.33 Apr 20, 2026
0.0.32 Apr 17, 2026
0.0.31 Apr 16, 2026
0.0.30 Apr 15, 2026
0.0.29 Apr 14, 2026
0.0.28 Apr 13, 2026
0.0.26 Apr 09, 2026
0.0.25 Apr 08, 2026
0.0.24 Apr 07, 2026
0.0.23 Apr 06, 2026
0.0.22 Apr 03, 2026
0.0.21 Apr 02, 2026
0.0.20 Apr 01, 2026
0.0.19 Mar 31, 2026
0.0.16 Mar 25, 2026
0.0.15 Mar 24, 2026
0.0.14 Mar 23, 2026
0.0.13 Mar 21, 2026
0.0.12 Mar 20, 2026
0.0.11 Mar 19, 2026
0.0.10 Mar 18, 2026
0.0.9 Mar 17, 2026
0.0.7 Mar 17, 2026
0.0.6 Mar 16, 2026
0.0.0a0 Mar 10, 2026

Wheel compatibility matrix

Platform Python 3
any

Files in release

Extras: None
Dependencies:
cloudpickle (>=3.0)
grpcio (>=1.60)
googleapis-common-protos (>=1.63)
httpx (>=0.27)
protobuf (>=4.25)