# OpenShell

> Updated 2026-09-29 · type: tool · category: ai-infrastructure · status: active · rev 1

OpenShell is a kernel-level sandbox that lets AI-agent fleets touch files, APIs and credentials under enforced policy, without unrestricted system access.

- Open source: yes (Apache-2.0)
- Self-hostable: yes
- Pricing model: free
- Best for: A team running fleets of autonomous AI agents that need real capabilities — file access, package installs, API calls, credential use — but must enforce a security boundary at the kernel level, with credentials injected only for approved endpoints so agents never see the raw secrets.
- Not for: A single low-stakes local agent where a kernel-level sandbox is overkill, or a team unwilling to run and operate a kernel-level runtime themselves.
- Last verified: 2026-09-29

- **Canonical:** https://gtmstacker.com/registry/tool/openshell/
- **Source:** [@tonysimons_ · X](https://github.com/nvidia/openshell) — @tonysimons_
- **Tags:** ai-infrastructure, sandbox, agent-runtime, security, governance, self-hostable
- **Repository:** https://github.com/nvidia/openshell

## Is OpenShell open source?

Yes, OpenShell is open source under the Apache-2.0 license.

## How much does OpenShell cost?

OpenShell is free to use.

## Can I self-host OpenShell?

Yes, OpenShell can be self-hosted (the source is available under the Apache-2.0 license).

## Alternatives & related

- [OpenSandbox](https://gtmstacker.com/registry/tool/opensandbox/)
- [Quartermaster (QM)](https://gtmstacker.com/registry/tool/quartermaster-qm/)


---

OpenShell is a kernel-level runtime sandbox that lets fleets of autonomous AI agents access files, packages, APIs, and credentials while enforcing security policy at the kernel level — granting real capability without unrestricted system access. Open source: yes (Apache-2.0); self-hostable, since it is a runtime you run yourself. It is free, has ~10.3k stars, is owned by NVIDIA, and supports Claude Code — the highest-traction and flagship drop in this batch.

## What it does

OpenShell's tagline is "the safe, private runtime for autonomous AI agents," and the design follows from that: rather than giving an agent a normal shell with your full permissions, it isolates each agent and enforces policy on file access, system calls, and network connections at the kernel level. Credentials are handled by injection — agents never see the real secrets; OpenShell supplies them only for approved endpoints. Policy changes can be reviewed against formal verification before approval. It installs via a one-line curl script, ships SDKs for Python, TypeScript, Go, and Rust, runs on Linux, macOS on Apple Silicon, and Windows under WSL 2, and integrates with Claude Code. Open source: yes (Apache-2.0); self-hostable; free.

## Provenance

- Apache-2.0 per repo; ~10.3k stars; owner NVIDIA.
- Kernel-level sandbox for fleets of autonomous agents: enforces policy on files, system calls, and network; injects credentials only for approved endpoints so agents never see raw secrets.
- Self-hostable (kernel-level runtime you run yourself); one-line curl installer; SDKs for Python/TypeScript/Go/Rust; Linux, macOS on Apple Silicon, Windows via WSL 2; supports Claude Code (nvidia/openshell, verified 2026-09-29).
- Surfaced via an X viral pull (@tonysimons_); license/facts verified against the primary repo 2026-09-29.

## Why it matters for a GTM stack

The moment GTM agents stop drafting and start acting — pulling from a CRM, calling billing APIs, using credentials, installing packages — the blast radius of a compromised or hallucinating agent becomes a business problem, not a demo bug. OpenShell is the governance/sandbox layer for exactly that: it lets a fleet of agents have real capability while a kernel-level policy keeps them inside a boundary and keeps the actual credentials out of their reach. That it is NVIDIA-backed with ~10.3k stars and Claude Code support makes it a serious candidate for the runtime tier of an agentic stack. The honest read: it is still a vendor-described security boundary — kernel-level enforcement and "agents never see real credentials" are the maker's claims, not independently audited here — and running a kernel-level runtime is a real operational commitment, so review the security model and plan to keep it patched before you trust it with production credentials.
