Player not loading? Watch on YouTube
NVIDIA's Shawn introduces OpenShell 0.1 as a runtime boundary around an AI agent. He explains that policy controls sit outside the agent, so the agent cannot change its own permissions. The demonstration uses a long-running Hermes agent with access to internal NVIDIA systems.
The agent first reads email and produces a priority list. Shawn then simulates a compromised agent or mistaken request by asking it to publish that private list in a GitHub issue. The agent tries code and curl requests, but reports that it cannot complete the upload. In this demonstration, OpenShell permits read-only GitHub access and blocks writes and POST requests. This illustrates the configured policy rather than proving protection against every possible attack.
The terminal UI exposes sandbox policies and attempted network requests. A weather query shows how an operator can review requests and approve them. Shawn also describes agent-assisted policy writing with human review and work on formal verification of policy constraints.
For setup, the video describes a curl installer that downloads OpenShell, then lets users configure policies and select a harness. Dedicated VMs are one deployment option. For shared applications, Shawn describes multi-tenant Kubernetes SDKs used with Red Hat OpenShift. He says interceptors and middleware support additional enforcement and integration with Microsoft Entra for agent identity.