OpenShell setup with LangChain DeepAgents and Nemotron

Learn how an OpenShell sandbox runs LangChain DeepAgents with local Nemotron inference, YAML access policies and a DuckDuckGo network allowlist.

Player not loading? Watch on YouTube

This tutorial explains OpenShell through a LangChain DeepAgents setup using a local Nemotron model on a DGX Spark. The speaker discloses NVIDIA's sponsorship of the hardware. He describes NemoClaw as a blueprint combining an agent harness, a model and a runtime, with OpenShell handling sandboxing and policy enforcement. OpenClaw and Hermes appear as alternative harnesses.

DeepAgents supplies planning, subagents, file access and a structured task list. The project walkthrough contrasts an NVIDIA cloud API backend with an Ollama backend for the local LLM setup. External search uses DuckDuckGo through an explicit network allowlist, so the demonstrated agent still has approved network access.

The main explanation concerns enforcement outside the AI agent process. According to the speaker, a supervisor prepares the sandbox and applies policies before launching the agent as a restricted child process. He describes controls for network connections, filesystem access, inference routing through inference.local and credentials handled outside the agent. These are the tutorial's security claims, rather than an independent assessment of protection against every attack.

The closing walkthrough covers creating and reconnecting to a sandbox, then applying a YAML policy. Network and inference policies can hot reload, the speaker says, while changing filesystem permissions requires recreating the sandbox.