awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
NVIDIA avatar

NVIDIA/OpenShell

0
View on GitHub↗
7,276 stars·886 forks·Rust·Apache-2.0·12 viewsdocs.nvidia.com/openshell/latest↗

OpenShell

OpenShell is a security framework and sandboxed execution runtime for autonomous AI agents. It provides isolated environments using containers and virtual machines to protect host infrastructure and sensitive data from unauthorized access during agent execution.

The system distinguishes itself by combining hardware-accelerated passthrough for host GPU access with a security gateway that intercepts model API calls. This gateway manages credentials by stripping caller information and injecting backend secrets, ensuring sensitive API keys remain off the local filesystem.

The platform covers broad capability areas including declarative policy enforcement for filesystem and network restrictions, agent credential management, and real-time activity monitoring. It supports the provisioning of environments through custom container images, local directories, or community catalogs.

Features

  • Agent Execution Environments - Provides isolated runtimes using containers and virtual machines specifically configured to execute autonomous AI agents securely.
  • Container-Based Sandboxes - Implements isolated execution environments using containers to protect the host system from autonomous agent activity.
  • Agent Gateways - Provides a secure API gateway to manage credentials and prevent data exfiltration for AI agent workflows.
  • AI Execution Sandboxes - Provides secure execution environments specifically designed for running autonomous AI coding agents.
  • Autonomous AI Agent Frameworks - Provides a functional framework for running autonomous AI agents within secure, isolated sandboxes.
  • Inference API Proxies - Provides a proxy to intercept model API calls for secure credential management and request routing.
  • Runtime Credential Injection - Injects sensitive secrets into containerized environments as runtime variables to keep keys off the local filesystem.
  • Security Policy Enforcers - Uses declarative YAML rules to enforce mandatory access control policies on filesystem and system calls.
  • Declarative Policy Managers - Enforces filesystem and network restrictions on autonomous agents via predefined declarative security rules.
  • Sandboxed Execution Environments - Provisions isolated runtime environments that restrict AI agent access to host system resources.
  • Agent Action Guardrails - Implements security mechanisms and declarative rules that restrict autonomous agent operations via sandboxing and access controls.
  • Declarative Policy Enforcers - Enforces filesystem and network restrictions and blocks dangerous system calls using declarative security rules.
  • Request Interception Middleware - Implements architectural middleware to intercept model API requests for credential stripping and secret injection.
  • AI Security Orchestrators - Manages isolated connections and enforces security boundaries between AI agents and external services.
  • AI Request Routing - Secures and manages the flow of requests to AI services through a controlled routing layer.
  • Hardware Acceleration - Exposes host GPU resources to containerized sandboxes to enable hardware-accelerated AI workloads.
  • GPU Accelerated Sandboxes - Provides isolated execution environments equipped with GPU hardware for AI model inference.
  • Sandbox - Provides a real-time dashboard for streaming logs and terminal data to monitor sandbox environment status and gateway health.
  • Real-Time Monitoring Dashboards - Provides a centralized dashboard for real-time observation of logs and terminal data from sandboxed environments.
  • Security and Sandboxing - Private runtime for autonomous agents.

Star history

Star history chart for nvidia/openshellStar history chart for nvidia/openshell

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to OpenShell

Similar open-source projects, ranked by how many features they share with OpenShell.
  • qwibitai/nanoclawqwibitai avatar

    qwibitai/nanoclaw

    29,956View on GitHub↗

    Nanoclaw is an LLM agent orchestrator and multi-platform chat gateway designed to deploy and manage isolated AI agents. It provides a containerized runtime that executes agents within sandboxed Linux containers, ensuring filesystem and state isolation through dedicated workspaces and host bind-mounts. The project distinguishes itself through a unified routing pipeline that connects agents to diverse messaging platforms, including WhatsApp, Discord, Slack, Telegram, Signal, and iMessage. It integrates the Model Context Protocol to extend agent capabilities via managed external data and functio

    TypeScriptai-agentsai-assistantclaude-code
    View on GitHub↗29,956
  • yaoapp/yaoYaoApp avatar

    YaoApp/yao

    7,544View on GitHub↗

    Yao is an LLM agent framework and low-code web app builder designed for orchestrating autonomous AI agents. It provides a platform to design, deploy, and coordinate agents with specialized personas that can plan tasks, utilize external tools, and execute multi-stage pipelines. The project distinguishes itself through a Model Context Protocol server for connecting assistants to external binaries and HTTP services, and a gRPC remote execution engine that allows agents to manage remote servers and devices. It includes a model-agnostic provider bridge that supports dynamic switching between vario

    Goagentagentic-aiagents
    View on GitHub↗7,544
  • microsoft/agent-governance-toolkitmicrosoft avatar

    microsoft/agent-governance-toolkit

    4,522View on GitHub↗

    The agent-governance-toolkit is a framework for enforcing security policies, managing zero-trust identities, and sandboxing the execution of autonomous AI agents. It provides a governance layer designed to control the behavior of agents through the use of a security policy engine, cryptographic identity management, and a runtime execution sandbox. The project distinguishes itself through a multi-tier privilege ring system and a cryptographic identity mesh that secures communication between autonomous entities. It implements a decay-based trust scoring mechanism to track entity reliability and

    Python
    View on GitHub↗4,522
  • nvidia/nemoclawNVIDIA avatar

    NVIDIA/NemoClaw

    21,237View on GitHub↗

    NemoClaw is an LLM agent orchestrator and sandboxed execution environment designed to deploy and manage the lifecycles of large language model agents. It provides a secure runtime that isolates persistent agents from the underlying host system to ensure operational security. The system includes a secure LLM inference gateway that acts as a managed routing layer, securing communication between AI agents and inference engines to prevent unauthorized access. It also integrates with NVIDIA OpenShell to run specialized agents within a secure shell environment. Operational control is provided thro

    TypeScriptai-agentsnvidiaopenclaw
    View on GitHub↗21,237
See all 30 alternatives to OpenShell→

Frequently asked questions

What does nvidia/openshell do?

OpenShell is a security framework and sandboxed execution runtime for autonomous AI agents. It provides isolated environments using containers and virtual machines to protect host infrastructure and sensitive data from unauthorized access during agent execution.

What are the main features of nvidia/openshell?

The main features of nvidia/openshell are: Agent Execution Environments, Container-Based Sandboxes, Agent Gateways, AI Execution Sandboxes, Autonomous AI Agent Frameworks, Inference API Proxies, Runtime Credential Injection, Security Policy Enforcers.

What are some open-source alternatives to nvidia/openshell?

Open-source alternatives to nvidia/openshell include: qwibitai/nanoclaw — Nanoclaw is an LLM agent orchestrator and multi-platform chat gateway designed to deploy and manage isolated AI… yaoapp/yao — Yao is an LLM agent framework and low-code web app builder designed for orchestrating autonomous AI agents. It… microsoft/agent-governance-toolkit — The agent-governance-toolkit is a framework for enforcing security policies, managing zero-trust identities, and… nvidia/nemoclaw — NemoClaw is an LLM agent orchestrator and sandboxed execution environment designed to deploy and manage the lifecycles… zenml-io/zenml — ZenML is an orchestration platform designed for building, deploying, and monitoring reproducible machine learning… kortix-ai/suna — Suna is an orchestration platform designed for the deployment, management, and governance of autonomous AI agents. It…