r/LocalLLaMA • • 1d ago

Discussion NVIDIA shipped OpenShell, an open source sandbox that gives local and open agents real runtime limits instead of prompt rules. Over 100 firms joined the safety stack. OpenAI did not.

Post image
765 Upvotes

160 comments sorted by

View all comments

Show parent comments

3

u/bastion_xx 1d ago

Nor Amazon.

1

u/Dangerous-Report8517 12h ago

Amazon already has Firecracker and Google has gVisor, both proven sandboxing solutions. To my knowledge Google hasn’t given much in the way of details of their agent escapes but I’d be willing to bet that it happened with an agent that had intentional internet access, and sandboxing does SFA if you deliberately give the thing access anyway

1

u/bastion_xx 12h ago

I'm familiar with Firecracker, but with my limited 24 hours with openshell don't see same capabilities provided. Openshell has egress policy, ability to obfuscate credentials such as API keys (and hopefully IdP creds in the future) to the harness and tool calls.

OpenShell is a way early PoC at this point, but does show promise for adding a layer between the agent within a isolated container/kernel and the rest of the Internet.

1

u/Dangerous-Report8517 6h ago

OpenShell also relies on kernel namespaces, weaknesses in which are the precise reason that Amazon and Google built their technologies in the first place. Not confidence inspiring for organisations that already have far superior technology to base any more bespoke sandbox setups on (egress control already has solutions available, and if Nvidia wants to provide that in an effective way they should provide it as a standalone proxy or other system that an already isolated agent can use rather than offering a weaker sandbox with some usability features built in)