最后更新:10/4/2026最后核验:2026-09-29
广告
<p>NVIDIA OpenShell 面向需要让智能体真正使用文件、安装依赖、调用 API,却不能任意接触本地数据、密钥和网络的团队。它会把智能体放入独立沙箱,在内核层约束文件访问、系统调用和每条出网连接;权限通过声明式 YAML 策略授予,未写入规则的访问默认拒绝。凭据不直接暴露给智能体,只会注入至策略许可的服务端点。OpenShell 还会在应用策略变更前检查新增授权范围,帮助团队审查可能增加的风险。项目采用 Apache-2.0 开源许可;官方支持 Linux、Apple Silicon Mac(Docker Desktop)及实验性的 Windows WSL 2 环境。</p><ul><li>在隔离沙箱中运行自主智能体,控制文件、进程与网络访问</li><li>以 YAML 声明式策略默认拒绝未授权操作,并保留审计记录</li><li>将凭据保留在智能体进程外,仅向获批端点提供</li><li>对策略变更进行形式化检查,协助人工审查新增权限</li></ul>
详情
平台
macOSWindowsLinux
功能特性
- Runs autonomous agents in isolated sandboxes with kernel-level controls for files, processes, and network connections
- Uses declarative YAML policies that deny access unless an explicit rule allows it
- Keeps provider credentials outside the agent process and releases them only to approved endpoints
- Checks policy changes with formal verification and keeps allow and deny decisions auditable
支持语言
en
适合人群
Teams running coding or operations agents that need enforceable filesystem, network, and credential boundariesSecurity-conscious developers who want policy-as-code and auditable controls around existing agent harnessesOrganizations deploying agents across local, cloud, hybrid, or air-gapped environments
已知限制
- The supported macOS host path requires Apple Silicon and Docker Desktop
- Windows support is experimental and requires WSL 2 with Docker Desktop
- Agents need a compatible sandbox image plus explicitly configured provider, filesystem, and network access before they can work
- Filesystem and process policy settings are fixed at sandbox startup, so changes to them require creating a new sandbox
替代工具
DeepSeek Harness — Local-first framework for composing agent runtimes, tools, sandboxes, and workflows
OpenWorker — Local-first desktop AI coworker with approval-gated actions rather than infrastructure-level sandbox enforcement
Universal Managed Agents API — Managed API that provisions agent environments rather than a self-hosted policy runtime






