awesome-repositories.com
博客
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
NVIDIA avatar

NVIDIA/OpenShell

0
View on GitHub↗
7,276 星标·886 分支·Rust·Apache-2.0·12 次浏览docs.nvidia.com/openshell/latest↗

OpenShell

OpenShell 是一个用于自主 AI 智能体的安全框架和沙箱执行运行时。它提供使用容器和虚拟机的隔离环境,以保护宿主基础设施和敏感数据在智能体执行期间免受未经授权的访问。

该系统的独特之处在于将用于宿主 GPU 访问的硬件加速直通与拦截模型 API 调用的安全网关相结合。该网关通过剥离调用者信息并注入后端密钥来管理凭据,确保敏感 API 密钥保留在本地文件系统之外。

该平台涵盖了广泛的能力领域,包括针对文件系统和网络限制的声明式策略执行、智能体凭据管理以及实时活动监控。它支持通过自定义容器镜像、本地目录或社区目录来配置环境。

Features

  • Agent Execution Environments - Provides isolated runtimes using containers and virtual machines specifically configured to execute autonomous AI agents securely.
  • Container-Based Sandboxes - Implements isolated execution environments using containers to protect the host system from autonomous agent activity.
  • Agent Gateways - Provides a secure API gateway to manage credentials and prevent data exfiltration for AI agent workflows.
  • AI Execution Sandboxes - Provides secure execution environments specifically designed for running autonomous AI coding agents.
  • Autonomous AI Agent Frameworks - Provides a functional framework for running autonomous AI agents within secure, isolated sandboxes.
  • Inference API Proxies - Provides a proxy to intercept model API calls for secure credential management and request routing.
  • Runtime Credential Injection - Injects sensitive secrets into containerized environments as runtime variables to keep keys off the local filesystem.
  • Security Policy Enforcers - Uses declarative YAML rules to enforce mandatory access control policies on filesystem and system calls.
  • Declarative Policy Managers - Enforces filesystem and network restrictions on autonomous agents via predefined declarative security rules.
  • Sandboxed Execution Environments - Provisions isolated runtime environments that restrict AI agent access to host system resources.
  • Agent Action Guardrails - Implements security mechanisms and declarative rules that restrict autonomous agent operations via sandboxing and access controls.
  • Declarative Policy Enforcers - Enforces filesystem and network restrictions and blocks dangerous system calls using declarative security rules.
  • Request Interception Middleware - Implements architectural middleware to intercept model API requests for credential stripping and secret injection.
  • AI Security Orchestrators - Manages isolated connections and enforces security boundaries between AI agents and external services.
  • AI Request Routing - Secures and manages the flow of requests to AI services through a controlled routing layer.
  • Hardware Acceleration - Exposes host GPU resources to containerized sandboxes to enable hardware-accelerated AI workloads.
  • GPU Accelerated Sandboxes - Provides isolated execution environments equipped with GPU hardware for AI model inference.
  • Sandbox - Provides a real-time dashboard for streaming logs and terminal data to monitor sandbox environment status and gateway health.
  • Real-Time Monitoring Dashboards - Provides a centralized dashboard for real-time observation of logs and terminal data from sandboxed environments.
  • Security and Sandboxing - Private runtime for autonomous agents.

Star 历史

nvidia/openshell 的 Star 历史图表nvidia/openshell 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

OpenShell 的开源替代方案

相似的开源项目,按与 OpenShell 的功能重合度排序。
  • qwibitai/nanoclawqwibitai 的头像

    qwibitai/nanoclaw

    29,956在 GitHub 上查看↗

    Nanoclaw is an LLM agent orchestrator and multi-platform chat gateway designed to deploy and manage isolated AI agents. It provides a containerized runtime that executes agents within sandboxed Linux containers, ensuring filesystem and state isolation through dedicated workspaces and host bind-mounts. The project distinguishes itself through a unified routing pipeline that connects agents to diverse messaging platforms, including WhatsApp, Discord, Slack, Telegram, Signal, and iMessage. It integrates the Model Context Protocol to extend agent capabilities via managed external data and functio

    TypeScriptai-agentsai-assistantclaude-code
    在 GitHub 上查看↗29,956
  • yaoapp/yaoYaoApp 的头像

    YaoApp/yao

    7,544在 GitHub 上查看↗

    Yao is an LLM agent framework and low-code web app builder designed for orchestrating autonomous AI agents. It provides a platform to design, deploy, and coordinate agents with specialized personas that can plan tasks, utilize external tools, and execute multi-stage pipelines. The project distinguishes itself through a Model Context Protocol server for connecting assistants to external binaries and HTTP services, and a gRPC remote execution engine that allows agents to manage remote servers and devices. It includes a model-agnostic provider bridge that supports dynamic switching between vario

    Goagentagentic-aiagents
    在 GitHub 上查看↗7,544
  • microsoft/agent-governance-toolkitmicrosoft 的头像

    microsoft/agent-governance-toolkit

    4,522在 GitHub 上查看↗

    The agent-governance-toolkit is a framework for enforcing security policies, managing zero-trust identities, and sandboxing the execution of autonomous AI agents. It provides a governance layer designed to control the behavior of agents through the use of a security policy engine, cryptographic identity management, and a runtime execution sandbox. The project distinguishes itself through a multi-tier privilege ring system and a cryptographic identity mesh that secures communication between autonomous entities. It implements a decay-based trust scoring mechanism to track entity reliability and

    Python
    在 GitHub 上查看↗4,522
  • nvidia/nemoclawNVIDIA 的头像

    NVIDIA/NemoClaw

    21,237在 GitHub 上查看↗

    NemoClaw is an LLM agent orchestrator and sandboxed execution environment designed to deploy and manage the lifecycles of large language model agents. It provides a secure runtime that isolates persistent agents from the underlying host system to ensure operational security. The system includes a secure LLM inference gateway that acts as a managed routing layer, securing communication between AI agents and inference engines to prevent unauthorized access. It also integrates with NVIDIA OpenShell to run specialized agents within a secure shell environment. Operational control is provided thro

    TypeScriptai-agentsnvidiaopenclaw
    在 GitHub 上查看↗21,237
查看 OpenShell 的所有 30 个替代方案→

常见问题解答

nvidia/openshell 是做什么的?

OpenShell 是一个用于自主 AI 智能体的安全框架和沙箱执行运行时。它提供使用容器和虚拟机的隔离环境,以保护宿主基础设施和敏感数据在智能体执行期间免受未经授权的访问。

nvidia/openshell 的主要功能有哪些?

nvidia/openshell 的主要功能包括:Agent Execution Environments, Container-Based Sandboxes, Agent Gateways, AI Execution Sandboxes, Autonomous AI Agent Frameworks, Inference API Proxies, Runtime Credential Injection, Security Policy Enforcers。

nvidia/openshell 有哪些开源替代品?

nvidia/openshell 的开源替代品包括: qwibitai/nanoclaw — Nanoclaw is an LLM agent orchestrator and multi-platform chat gateway designed to deploy and manage isolated AI… yaoapp/yao — Yao is an LLM agent framework and low-code web app builder designed for orchestrating autonomous AI agents. It… microsoft/agent-governance-toolkit — The agent-governance-toolkit is a framework for enforcing security policies, managing zero-trust identities, and… nvidia/nemoclaw — NemoClaw is an LLM agent orchestrator and sandboxed execution environment designed to deploy and manage the lifecycles… zenml-io/zenml — ZenML is an orchestration platform designed for building, deploying, and monitoring reproducible machine learning… kortix-ai/suna — Suna is an orchestration platform designed for the deployment, management, and governance of autonomous AI agents. It…