Player not loading? Watch on YouTube
NVIDIA's OpenShell team demonstrates a runtime for autonomous agents, starting with a Docker sandbox running Pi. The setup uses a YAML policy to restrict file access and initially deny general network access. Inference comes through an OpenRouter provider using GLM 5.3 Flash, so this demonstration does not run models locally.
The practical test asks Pi to count open GitHub issues. Its first attempt fails under the network restrictions. Johnny then updates the policy while the sandbox is running, granting read-only GitHub API access through curl. The retry succeeds. He also explains how provider profiles define endpoints and permitted binaries, with placeholder credentials inside the sandbox and real values supplied when needed.
The discussion separates an AI agent's own guardrails from runtime controls over files and network traffic. The team describes middleware for additional authorization or safety checks and formal verification work for detecting unintended access paths in complex policies. These are the speakers' descriptions of the security approach, rather than proof that every configuration prevents escape.
For local LLM use, the speakers say local inference can fit the provider system. They report running OpenShell on Raspberry Pi and stress that deployment depends on a supported compute driver. Windows support is still forthcoming in the discussion. Security also depends on the chosen isolation layers, environment, and policy configuration.