NVIDIA Open Agent Safety Platform Pairs OpenShell Sandboxes With BlueField-4 Sentry


NVIDIA announced its Open Agent Safety Platform on September 28, 2026, combining the open-source OpenShell agent runtime with an optional hardware enforcement layer called NVIDIA Sentry. OpenShell is broadly available and runs autonomous agents inside policy-controlled sandboxes; Sentry is a reference-system component designed to run out of band on BlueField-4 DPUs and quarantine agents that cross defined boundaries.

The architecture targets a practical problem created by increasingly autonomous coding and enterprise agents: they need access to files, processes, networks, APIs and credentials to complete useful work. OpenShell places those capabilities behind explicit runtime policy, while Sentry moves an additional monitoring and enforcement point outside the host environment.

NVIDIA says OpenShell is optimized for Vera CPUs. The project is open source and can be extended to third-party compute platforms, including Arm and Intel systems. Current OpenShell documentation lists Linux, Apple-silicon macOS and experimental Windows/WSL 2 support, with Docker, Podman and other supported compute backends depending on deployment.

OpenShell is the deployable software layer

OpenShell runs each agent in an isolated sandbox and applies declarative policy across four important domains: filesystem access, network egress, processes and provider credentials. Its current documentation describes kernel-level controls including Landlock filesystem restrictions and seccomp process restrictions, alongside network-policy enforcement and endpoint-bound credential handling.

For agent deployments, the credential design is particularly relevant. OpenShell can keep provider credentials outside the agent sandbox and resolve them only for profile-authorized endpoints. This reduces the amount of raw secret material available to an agent while preserving access to approved model APIs and services.

The current OpenShell documentation identifies v0.1.2 as the latest release line. The project is licensed under Apache 2.0, and NVIDIA publishes SDKs for Python, TypeScript, Go and Rust. Documented agent use cases include Claude Code, Codex, OpenCode and GitHub Copilot CLI.

OpenShell can therefore be evaluated independently of NVIDIA's complete reference hardware design. Teams can use its sandbox and policy controls on supported general-purpose systems while deciding separately whether an out-of-band hardware enforcement layer fits their threat model.

Sentry moves enforcement to BlueField-4

NVIDIA Sentry is the second major component in the September 28 architecture. It runs on BlueField-4 DPUs and uses NVIDIA DOCA to monitor agent activity from an isolated trust domain. NVIDIA describes Sentry as an optional layer that can inspect agent requests and responses, verify agent identity, produce attested telemetry and enforce access policies for data, tools, APIs and services.

In NVIDIA's Vera Rubin POD reference architecture, BlueField-4 sits on the node's path to the model. That position gives Sentry an observation and enforcement point outside the host CPU environment. NVIDIA says the DPU can quarantine and stop an agent in milliseconds when policy determines that it has moved outside its permitted boundary.

The distinction matters operationally: OpenShell supplies the software sandbox and policy runtime, while Sentry adds independent hardware-backed monitoring and enforcement. Deployments can use OpenShell without Sentry; NVIDIA presents the BlueField layer as an additional control for environments that need stronger separation between an agent and the system supervising it.

What the policy model controls

OpenShell's published controls map directly to common agent risks:

Control Deployment purpose
Filesystem policy Restrict reads and writes to declared paths
Network policy Permit approved destinations and block unauthorized egress
Process policy Limit privilege escalation and dangerous system calls
Provider credentials Bind credentials to approved endpoints instead of exposing raw secrets broadly
Logging and audit Record sandbox and policy activity for investigation and governance

NVIDIA's technical design also emphasizes verifiable policy changes. The project describes a policy prover that evaluates what a proposed policy change would permit before it is applied, helping operators review expanded privileges as agents request additional access.

Hardware support and deployment boundary

The September 28 announcement spans software that is available now and a broader reference architecture tied to NVIDIA's infrastructure roadmap. OpenShell and its skills are available now through NVIDIA developer resources and GitHub. The OpenShell repository provides the code under Apache 2.0 and documents supported local and infrastructure deployment paths.

Sentry is part of the Open Agent Safety Platform reference-system design and is associated with BlueField-4. NVIDIA's announcement describes the complete platform across Vera CPUs, BlueField-4 DPUs and Vera Rubin POD systems, while also stating that OpenShell can operate with third-party compute platforms. Organizations evaluating the announcement should therefore separate the deployable OpenShell software from the optional NVIDIA-specific hardware enforcement architecture when planning near-term deployments.

NVIDIA says more than 100 organizations are working with technologies in the platform ecosystem. Named participants include Anthropic, Cisco, CrowdStrike, Dell Technologies, Hugging Face, Microsoft, Red Hat, Salesforce, SAP and ServiceNow. Those ecosystem statements indicate integration and collaboration activity; they do not establish that every named organization has deployed the complete Vera/BlueField Sentry architecture in production.

Independent Reuters reporting on September 28 corroborated the OpenShell rollout, NVIDIA's work with Arm and Intel on CPU support, and Sentry's role as a separate hardware-backed containment layer. NVIDIA told Reuters that the new controls could have prevented the recent Hugging Face agent breach if they had been deployed during model evaluation; that counterfactual remains a vendor assessment rather than an independently demonstrated result.

Deployment implications

For teams already running autonomous coding agents, OpenShell is the immediately testable part of the release. It provides a way to move filesystem, network, process and credential permissions into explicit infrastructure policy instead of relying entirely on instructions inside the agent session.

The BlueField-4 Sentry design is aimed at higher-assurance environments where the monitoring layer should remain isolated from the host and agent it supervises. That model is most relevant to enterprise agent fleets, sensitive development environments and future agentic infrastructure where long-running agents receive broad tool authority.

The broader significance of NVIDIA's design is architectural: agent security is being pushed below the model and application harness into runtime and infrastructure controls. OpenShell makes that approach available as open-source software today, while Sentry shows how NVIDIA intends to extend the same policy boundary into DPU hardware.

Sources