Skip to content

Entry

OpenShell

Appears in 4 awesome lists

Open-source policy-driven sandbox runtime for autonomous AI agents, announced at GTC 2026. Enforces security constraints at the kernel level via Landlock LSM (filesystem), seccomp BPF (syscalls), and an OPA/Rego-evaluated HTTP CONNECT proxy (network) — constraints are enforced on the environment…

Open github.comnvidia/openshell

Found in these lists

Awesome AI Security Tools

Section: Runtime Protection & Enforcement · 🟢 — Policy-governed runtime for autonomous and coding agents with container or microVM-backed sandboxes, filesystem/process/network controls, endpoint-bound credential injection, and audit logs. (NVIDIA) — note: pre-release runtime whose effective isolation depends on the selected compute…

FreshScore 85

Awesome Harness Engineering

Section: Security, Sandbox & Permissions · Open-source policy-driven sandbox runtime for autonomous AI agents, announced at GTC 2026. Enforces security constraints at the kernel level via Landlock LSM (filesystem), seccomp BPF (syscalls), and an OPA/Rego-evaluated HTTP CONNECT proxy (network) — constraints are enforced on the environment…

FreshScore 88

Awesome local LLM

Section: Security and Sandboxing · the safe, private runtime for autonomous AI agents from NVIDIA

FreshScore 87

Awesome Open Source AI

Section: 4. Agentic AI & Multi-Agent Systems · Safe and private runtime for autonomous AI agents with policy-driven execution boundaries and CLI integration.

FreshScore 89

Bifrost

🟢🟠 — Apache-licensed AI and MCP gateway with multi-provider routing, virtual-key access controls, budgets, rate limits, MCP aggregation, OAuth, automatic fallbacks, and load balancing. (Maxim) — note: model-provider credentials and proxied request/response data are sensitive; restrict and…;…

In 8 listsDetails

E2B

Firecracker microVM sandboxes purpose-built for agent tool loops: ~150ms cold start, Python/JS SDKs, open source. The clearest reference implementation of "code execution as a harness primitive" rather than a CI system bolted on.

In 7 listsDetails

brood-box

🟢 — Experimental runner for coding agents in hardware-isolated microVMs with copy-on-write workspace snapshots, egress profiles, selective secret forwarding, and file-by-file review before applying changes. (Stacklok) — note: APIs and behavior are explicitly experimental; workspace-mode=direct…

In 6 listsDetails

NeMo Guardrails

NVIDIA's programmable guardrails toolkit: define input, dialog, retrieval, execution, and output rails that intercept the agent loop at five distinct layers using the Colang DSL. The execution rail layer specifically governs what tools the LLM can invoke and what their inputs/outputs may contain —…

In 6 listsDetails

Portkey AI Gateway

🟢🟠 — Open AI gateway with provider routing, fallback and retry controls, guardrail integrations, observability, and MCP traffic support for model and agent applications. (Portkey) — note: the gateway is general infrastructure rather than a standalone security scanner; model-provider…

In 6 listsDetails

Agent Governance Toolkit

🟢 — Multi-language toolkit for policy-enforced agent tool calls and audit records, with optional identity, MCP-gateway, sandboxing, reliability, and compliance components. (Microsoft) — note: official public preview; APIs and deployment patterns may change before general availability. · updated…;…

In 5 listsDetails

garak

The LLM vulnerability scanner. Probes models for hallucinations, data leakage, prompt injection, misinformation, toxicity, and jailbreaks. Extensive plugin-based architecture with 100+ vulnerability probes. Apache 2.0 licensed.

In 4 listsDetails

CubeSandbox

Tencent Cloud's production-validated microVM sandbox for AI agents: sub-60ms cold start via snapshot cloning, <5MB per-instance overhead, and true kernel-level isolation with eBPF-enforced network policies. E2B-compatible drop-in replacement that demonstrates how hyperscale cloud infrastructure…

In 4 listsDetails