{
  "$schema_doc": "https://gtmstacker.com/registry/schema/entry.schema.json",
  "stability": "emerging",
  "generator": "agentic-media-registry",
  "generated_at": "2026-09-29T00:00:00Z",
  "id": "com.gtmstacker.registry/tool/openshell",
  "type": "tool",
  "slug": "openshell",
  "canonical_url": "https://gtmstacker.com/registry/tool/openshell/",
  "title": "OpenShell",
  "description": "OpenShell is a kernel-level runtime sandbox that lets fleets of autonomous AI agents use files, packages, APIs, and credentials while enforcing security policy without granting unrestricted system access. Open source: yes (Apache-2.0); self-hostable (kernel-level runtime you run yourself). Free; ~10.3k stars; maker NVIDIA; supports Claude Code.",
  "category": "ai-infrastructure",
  "tags": [
    "ai-infrastructure",
    "sandbox",
    "agent-runtime",
    "security",
    "governance",
    "self-hostable"
  ],
  "status": "active",
  "revision": 1,
  "content_hash": "34340c5b741ebf47ab79b8fca9280c179acd47feb67d29d6c28c786bb15373c9",
  "date_published": "2026-09-29T00:00:00Z",
  "date_modified": "2026-09-29T00:00:00Z",
  "source": {
    "name": "@tonysimons_ · X",
    "url": "https://github.com/nvidia/openshell",
    "author": "@tonysimons_"
  },
  "license": "Apache-2.0",
  "one_liner": "OpenShell is a kernel-level sandbox that lets AI-agent fleets touch files, APIs and credentials under enforced policy, without unrestricted system access.",
  "open_source": "yes",
  "self_hostable": "yes",
  "pricing_model": "free",
  "who_its_for": "A team running fleets of autonomous AI agents that need real capabilities — file access, package installs, API calls, credential use — but must enforce a security boundary at the kernel level, with credentials injected only for approved endpoints so agents never see the raw secrets.",
  "who_its_not_for": "A single low-stakes local agent where a kernel-level sandbox is overkill, or a team unwilling to run and operate a kernel-level runtime themselves.",
  "aliases": [
    "openshell",
    "nvidia/openshell"
  ],
  "alternatives": [
    "opensandbox",
    "quartermaster-qm"
  ],
  "secondary_categories": [
    "mcp-agents"
  ],
  "last_verified": "2026-09-29",
  "evidence": {
    "claim_type": "vendor-claim",
    "source_id": "https://github.com/nvidia/openshell",
    "note": "Apache-2.0 per repo; ~10.3k stars; owner NVIDIA. A safe, private runtime sandbox that lets fleets of autonomous AI agents access files, packages, APIs and credentials while enforcing security policy at the kernel level without unrestricted system access. Self-hostable (kernel-level runtime you run yourself); one-line curl installer; SDKs for Python/TypeScript/Go/Rust; Linux, macOS on Apple Silicon, and Windows via WSL 2; supports Claude Code (nvidia/openshell, verified 2026-09-29)."
  },
  "caveats": "Verified from the primary repo (2026-09-29); no independent security testing here. Tagline and the kernel-level enforcement / 'agents never see real credentials' claims are the vendor's own (vendor-claim) — a security boundary is only as good as its audited implementation, so do not treat the sandbox as proven-safe without your own review. It is a kernel-level runtime, which means real operational commitment to run and keep patched.",
  "lead": "OpenShell is a kernel-level runtime sandbox that lets fleets of autonomous AI agents access files, packages, APIs, and credentials while enforcing security policy at the kernel level — granting real capability without unrestricted system access. Open source: yes (Apache-2.0); self-hostable, since it is a runtime you run yourself. It is…",
  "chunks": [
    {
      "index": 0,
      "heading_path": [],
      "est_tokens": 116,
      "text": "OpenShell is a kernel-level runtime sandbox that lets fleets of autonomous AI agents access files, packages, APIs, and credentials while enforcing security policy at the kernel level — granting real capability without unrestricted system access. Open source: yes (Apache-2.0); self-hostable, since it is a runtime you run yourself. It is free, has ~10.3k stars, is owned by NVIDIA, and supports Claude Code — the highest-traction and flagship drop in this batch."
    },
    {
      "index": 1,
      "heading_path": [
        null,
        "What it does"
      ],
      "est_tokens": 265,
      "text": "security policy at the kernel level — granting real capability without unrestricted system access. Open source: yes (Apache-2.0); self-hostable, since it is a runtime you run yourself. It is free, has ~10.3k stars, is owned by NVIDIA, and supports Claude Code — the highest-traction and flagship drop in this batch.\n\nOpenShell's tagline is \"the safe, private runtime for autonomous AI agents,\" and the design follows from that: rather than giving an agent a normal shell with your full permissions, it isolates each agent and enforces policy on file access, system calls, and network connections at the kernel level. Credentials are handled by injection — agents never see the real secrets; OpenShell supplies them only for approved endpoints. Policy changes can be reviewed against formal verification before approval. It installs via a one-line curl script, ships SDKs for Python, TypeScript, Go, and Rust, runs on Linux, macOS on Apple Silicon, and Windows under WSL 2, and integrates with Claude Code. Open source: yes (Apache-2.0); self-hostable; free."
    },
    {
      "index": 2,
      "heading_path": [
        null,
        "Provenance"
      ],
      "est_tokens": 228,
      "text": "approved endpoints. Policy changes can be reviewed against formal verification before approval. It installs via a one-line curl script, ships SDKs for Python, TypeScript, Go, and Rust, runs on Linux, macOS on Apple Silicon, and Windows under WSL 2, and integrates with Claude Code. Open source: yes (Apache-2.0); self-hostable; free.\n\n- Apache-2.0 per repo; ~10.3k stars; owner NVIDIA.\n- Kernel-level sandbox for fleets of autonomous agents: enforces policy on files, system calls, and network; injects credentials only for approved endpoints so agents never see raw secrets.\n- Self-hostable (kernel-level runtime you run yourself); one-line curl installer; SDKs for Python/TypeScript/Go/Rust; Linux, macOS on Apple Silicon, Windows via WSL 2; supports Claude Code (nvidia/openshell, verified 2026-09-29).\n- Surfaced via an X viral pull (@tonysimons_); license/facts verified against the primary repo 2026-09-29."
    },
    {
      "index": 3,
      "heading_path": [
        null,
        "Why it matters for a GTM stack"
      ],
      "est_tokens": 335,
      "text": "endpoints so agents never see raw secrets. - Self-hostable (kernel-level runtime you run yourself); one-line curl installer; SDKs for Python/TypeScript/Go/Rust; Linux, macOS on Apple Silicon, Windows via WSL 2; supports Claude Code (nvidia/openshell, verified 2026-09-29). - Surfaced via an X viral pull (@tonysimons_); license/facts verified against the primary repo 2026-09-29.\n\nThe moment GTM agents stop drafting and start acting — pulling from a CRM, calling billing APIs, using credentials, installing packages — the blast radius of a compromised or hallucinating agent becomes a business problem, not a demo bug. OpenShell is the governance/sandbox layer for exactly that: it lets a fleet of agents have real capability while a kernel-level policy keeps them inside a boundary and keeps the actual credentials out of their reach. That it is NVIDIA-backed with ~10.3k stars and Claude Code support makes it a serious candidate for the runtime tier of an agentic stack. The honest read: it is still a vendor-described security boundary — kernel-level enforcement and \"agents never see real credentials\" are the maker's claims, not independently audited here — and running a kernel-level runtime is a real operational commitment, so review the security model and plan to keep it patched before you trust it with production credentials."
    }
  ],
  "alternates": {
    "markdown": "https://gtmstacker.com/registry/tool/openshell/index.md",
    "html": "https://gtmstacker.com/registry/tool/openshell/",
    "json": "https://gtmstacker.com/registry/tool/openshell/index.json",
    "server_json": "https://gtmstacker.com/registry/tool/openshell/server.json"
  },
  "jsonld": {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "WebSite",
        "@id": "https://gtmstacker.com/#website",
        "url": "https://gtmstacker.com/",
        "name": "GTM Stacker Agent Registry",
        "description": "A daily-updated, agent-native registry of open-source tool discoveries, tool updates, and curated news for the go-to-market / RevOps engineering niche. Machine-readable first: agents can discover, parse, page, and delta-sync it without scraping HTML.",
        "inLanguage": "en",
        "publisher": {
          "@id": "https://gtmstacker.com/#organization"
        }
      },
      {
        "@type": "Organization",
        "@id": "https://gtmstacker.com/#organization",
        "name": "GTM Stacker",
        "url": "https://gtmstacker.com",
        "description": "The growth-systems practice of Theo Popov: AI-native enrichment, outbound, content engines and internal tooling for startups and venture programs. Its agent-native media property, the GTM Stacker Agent Registry, maintains a daily-updated catalog of open-source go-to-market and RevOps tools that both people and AI engines can discover, compare, and cite.",
        "foundingDate": "2024-08",
        "knowsAbout": [
          "go-to-market engineering",
          "RevOps",
          "sales automation",
          "marketing operations",
          "open-source software",
          "AI agents"
        ],
        "founder": {
          "@type": "Person",
          "@id": "https://gtmstacker.com/#founder",
          "name": "Theo Popov",
          "jobTitle": "Growth Operations & GTM Systems",
          "url": "https://gtmstacker.com/about/",
          "sameAs": [
            "https://www.linkedin.com/in/theo-popov",
            "https://x.com/Theo_Popov",
            "https://github.com/theopopov"
          ],
          "worksFor": {
            "@id": "https://gtmstacker.com/#organization"
          }
        },
        "sameAs": [
          "https://www.linkedin.com/company/gtmstacker",
          "https://www.youtube.com/@gtmstacker",
          "https://www.instagram.com/gtmstacker/",
          "https://www.tiktok.com/@gtmstacker"
        ],
        "mainEntityOfPage": "https://gtmstacker.com/registry/about/"
      },
      {
        "@type": "SoftwareApplication",
        "@id": "https://gtmstacker.com/registry/tool/openshell/#software",
        "name": "OpenShell",
        "identifier": "nvidia/openshell",
        "description": "OpenShell is a kernel-level runtime sandbox that lets fleets of autonomous AI agents use files, packages, APIs, and credentials while enforcing security policy without granting unrestricted system access. Open source: yes (Apache-2.0); self-hostable (kernel-level runtime you run yourself). Free; ~10.3k stars; maker NVIDIA; supports Claude Code.",
        "applicationCategory": "DeveloperApplication",
        "url": "https://gtmstacker.com/registry/tool/openshell/",
        "datePublished": "2026-09-29T00:00:00Z",
        "dateModified": "2026-09-29T00:00:00Z",
        "isPartOf": {
          "@id": "https://gtmstacker.com/#website"
        },
        "license": "https://spdx.org/licenses/Apache-2.0.html",
        "codeRepository": "https://github.com/nvidia/openshell",
        "keywords": "ai-infrastructure, mcp-agents, sandbox, agent-runtime, security, governance, self-hostable",
        "author": {
          "@type": "Organization",
          "name": "nvidia",
          "url": "https://github.com/nvidia",
          "sameAs": [
            "https://github.com/nvidia/openshell"
          ]
        },
        "offers": {
          "@type": "Offer",
          "price": 0,
          "priceCurrency": "USD"
        },
        "isSimilarTo": [
          {
            "@type": "SoftwareApplication",
            "name": "OpenSandbox",
            "url": "https://gtmstacker.com/registry/tool/opensandbox/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          },
          {
            "@type": "SoftwareApplication",
            "name": "Quartermaster (QM)",
            "url": "https://gtmstacker.com/registry/tool/quartermaster-qm/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "@id": "https://gtmstacker.com/registry/tool/openshell/#breadcrumb",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "GTM Stacker Registry",
            "item": "https://gtmstacker.com/registry/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "AI Infrastructure",
            "item": "https://gtmstacker.com/registry/category/ai-infrastructure/"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "OpenShell",
            "item": "https://gtmstacker.com/registry/tool/openshell/"
          }
        ]
      }
    ]
  },
  "tool": {
    "name": "nvidia/openshell",
    "repository": {
      "url": "https://github.com/nvidia/openshell",
      "source": "github"
    }
  }
}
