The test in NVIDIA’s OpenShell 0.1.0 guide is small: put a program in a sandbox, deny its network request, then change the policy so it can read from GitHub but cannot post to the same API. Developers can inspect the decisions without running a language model or supplying an API key.
Published September 28, 2026, the guide is a practical follow-up to OpenShell’s broader platform story, not a new model release. NVIDIA says the runtime can place controls around existing agents, including Codex and Claude Code, without rewriting them. The walkthrough uses curl to demonstrate the policy boundary; NVIDIA says the same controls apply when an agent makes the request. The demo has not been independently reproduced here.
An instruction telling an agent to “only read GitHub” depends on the agent following it. OpenShell puts the restriction outside the agent’s workload and checks what its programs try to do.
Start With a Sandbox That Cannot Reach the Network
NVIDIA’s example begins after installing OpenShell 0.1.0 and downloading the guide’s no-network.yaml and github-readonly.yaml files into an examples directory. The first command creates a sandbox named policy-demo using the no-network policy:
openshell sandbox create --name policy-demo \
--no-auto-providers \
--policy examples/no-network.yaml
According to the guide, the command opens a shell inside the sandbox. A request to GitHub’s public /zen endpoint should then fail:
curl -sS --max-time 10 https://api.github.com/zen
The endpoint requires no GitHub credential, keeping the test focused on network permission. The request is blocked before authentication could complicate the result. From a second terminal on the host, the operator can inspect the recorded decision:
openshell logs policy-demo --since 5m
The initial failure establishes what the sandbox cannot do before access is granted. If a developer began with unrestricted networking, a successful GitHub request would say little about whether the intended rule was working.
The separate host terminal lets an operator check whether OpenShell denied the request and which program made it. An agent may report that a command failed, but a network error alone would not identify the cause.






