Nvidia puts AI agent permissions outside the agent
Nvidia detailed OpenShell 0.1.0 on September 28. The open-source software limits which files and services an agent can use. A separate supervisor checks each request against rules set by the operator.
Verified 10:28 AM PDT · 2 original sources
Nvidia says operators can let an agent query a service while blocking write requests to that same service. The public release history already lists version 0.1.1, which makes a network tunnel opt-in.
The cited sources explain the controls, but they do not include an independent security audit. The policy checker can enforce the permissions an operator sets. That alone does not prove the rest of the system remains secure while the agent runs.
Independent testers need to try blocked writes, child processes and network access. The restrictions need to hold even when an agent tries another route.
Audit the story
Original sources
Company claims remain company claims. Follow the reporting and judge the evidence directly.
- NVIDIAAdd runtime controls to AI agents with NVIDIA OpenShell ↗
- NVIDIA on GitHubOpenShell release history ↗
Continue the edition