Last updated: 10/4/2026Last verified: 2026-09-29
AD
<p>Open-source runtime for running autonomous AI agents in policy-controlled sandboxes. OpenShell enforces filesystem, process, network, and credential boundaries outside the agent process, with auditable controls and formally checked policy changes.</p><ul><li>Runs autonomous agents in isolated sandboxes with kernel-level controls for files, processes, and network connections</li><li>Uses declarative YAML policies that deny access unless an explicit rule allows it</li><li>Keeps provider credentials outside the agent process and releases them only to approved endpoints</li><li>Checks policy changes with formal verification and keeps allow and deny decisions auditable</li></ul>
Details
Platform
macOSWindowsLinux
Features
- Runs autonomous agents in isolated sandboxes with kernel-level controls for files, processes, and network connections
- Uses declarative YAML policies that deny access unless an explicit rule allows it
- Keeps provider credentials outside the agent process and releases them only to approved endpoints
- Checks policy changes with formal verification and keeps allow and deny decisions auditable
Languages
en
Best for
Teams running coding or operations agents that need enforceable filesystem, network, and credential boundariesSecurity-conscious developers who want policy-as-code and auditable controls around existing agent harnessesOrganizations deploying agents across local, cloud, hybrid, or air-gapped environments
Known limitations
- The supported macOS host path requires Apple Silicon and Docker Desktop
- Windows support is experimental and requires WSL 2 with Docker Desktop
- Agents need a compatible sandbox image plus explicitly configured provider, filesystem, and network access before they can work
- Filesystem and process policy settings are fixed at sandbox startup, so changes to them require creating a new sandbox
Alternatives
DeepSeek Harness — Local-first framework for composing agent runtimes, tools, sandboxes, and workflows
OpenWorker — Local-first desktop AI coworker with approval-gated actions rather than infrastructure-level sandbox enforcement
Universal Managed Agents API — Managed API that provisions agent environments rather than a self-hosted policy runtime






