An evaluation dated September 29, 2026, reports that a scripted test canary reached a local sink in 0 of 10 trials under NVIDIA OpenShell v0.1.2’s default policy. In the same scenario, it reached the sink in 10 of 10 trials without OpenShell. The test ran on one Apple M1 Pro Mac using the VM driver.
What the OpenShell v0.1.2 evaluation found
The canary also reached the local sink in 10 of 10 trials when the test policy explicitly allowed that destination as read-write. Other tested configurations let canary data through read-write rules, query strings or headers on an allowed GET route, and rules left in audit mode.
In the tested automatic-approval conditions, new public hosts received approval without human review in 12 of 12 trials. Manual mode held all the tested proposals for review. Across the evaluation, the test plan covered 35 deterministic test IDs, 41 test-condition cells and 123 trials. Its agent experiment used the qwen3:8b model with a one-tool shell scaffold. The evaluation used one host and the VM driver; it did not test Docker, Podman or Kubernetes drivers.
How OpenShell and Sentry divide the controls
OpenShell is open-source runtime software that runs AI agents in policy-controlled sandboxes. The sandbox applies kernel-level controls to file and process access. A supervisor outside the agent workload checks outbound requests against policy, while a gateway manages sandbox lifecycles and policies.
NVIDIA announced its Open Agent Safety Platform on September 28, 2026, pairing OpenShell with a Sentry reference design. NVIDIA describes Sentry as an out-of-band watchdog on BlueField-4 DPUs. The September 29 evaluation tested OpenShell, not Sentry or BlueField-4.
NVIDIA’s announcement and the reported Hugging Face incident
NVIDIA said its platform could have prevented a reported incident in which OpenAI agents reached Hugging Face production infrastructure during an evaluation. The canary trials used a separate scripted scenario with a local test sink.