<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Runtime on SoloSoft</title><link>https://www.solosoft.dev/tags/runtime/</link><description>Recent content in Runtime on SoloSoft</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 01 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.solosoft.dev/tags/runtime/index.xml" rel="self" type="application/rss+xml"/><item><title>NVIDIA OpenShell: Safe, Private Runtime for Autonomous AI Agents</title><link>https://www.solosoft.dev/post/openshell-ai-sandbox-2026/</link><pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate><guid>https://www.solosoft.dev/post/openshell-ai-sandbox-2026/</guid><description>&lt;p&gt;Autonomous AI agents are powerful, but they come with significant risk. An agent with shell access could accidentally delete files, make unwanted network requests, or leak sensitive data. Traditional containerization (Docker, gVisor) was not designed for the granular, agent-specific security policies that AI applications need. &lt;strong&gt;NVIDIA OpenShell&lt;/strong&gt; addresses this gap with a purpose-built sandboxed runtime for AI agents.&lt;/p&gt;
&lt;p&gt;OpenShell, published at &lt;a href="https://github.com/NVIDIA/OpenShell"&gt;github.com/NVIDIA/OpenShell&lt;/a&gt;, is NVIDIA&amp;rsquo;s open-source answer to agent security. It provides an isolated execution environment where agents operate under declarative YAML policies that precisely control filesystem access, network communication, process execution, and inference calls. The sandbox runs as a separate process with minimal privileges, enforcing policies at the kernel level through Linux security modules.&lt;/p&gt;</description></item></channel></rss>