NVIDIA OpenShell
Policy-governed agent runtime that blocks all outbound network traffic by default.
NVIDIA OpenShell is an Apache-2.0, Rust-based agent runtime that enforces default-deny network egress in every sandbox: outbound connections are blocked at a proxy unless explicitly allowlisted in a declarative YAML policy, and blocked attempts are logged with destination, binary and reason.
Caveat: The claim that OpenShell is the *only* open-source agent sandbox defaulting to deny-all egress is not independently verifiable and is not asserted here. OpenShell was labelled alpha as of mid-2026.
Key facts
| Category | Execution Sandbox |
|---|---|
| License | Apache-2.0 |
| Language | Rust |
| Self-hosted | Yes |
| GitHub stars | 14,749 (2026-10-04) |
| Last push | 2026-10-04 |
| Last verified | 2026-10-04 |
| Repository | https://github.com/NVIDIA/OpenShell |
Tools in this category
Daytona
Agent sandboxes with independent kernel per sandbox and sub-90ms snapshot resume.
Firecracker
AWS's open-source microVM monitor powering Lambda and Fargate.
gVisor
Google's user-space application kernel for workload isolation, delivered as the runsc OCI runtime.