On 28 September, NVIDIA announced an Open Agent Safety Platform pairing OpenShell, an open-source runtime for controlling agent access, with Sentry, a reference system design for monitoring agents on BlueField-4 data-processing units.[1][5] NVIDIA says Sentry can quarantine agents in milliseconds, but neither the launch announcement nor TechCrunch’s report includes a public test of that claim.[1][2]
OpenShell came before the platform bundle
TechCrunch reports that NVIDIA introduced OpenShell in March; on 28 September the company announced a broader platform combining the runtime with Sentry.[1][2] The September announcement adds a named hardware reference design to software that had already been presented separately.[1][2]
By 29 September, GitHub marked the version-specific v0.1.2 release “Latest” and dated it 28 September.[8] NVIDIA’s technical walkthrough, also dated 28 September, describes OpenShell v0.1.0.[4] The two records refer to different versions: the walkthrough documents v0.1.0, while GitHub lists v0.1.2 as latest on the article date.[4][8]
The walkthrough describes v0.1.0 as open-source software combining sandboxed execution, controlled service access, credential management and policy analysis.[4] NVIDIA’s current documentation lists filesystem, network, process and provider-credential controls.[7] The product page presents OpenShell as model-agnostic, a compatibility claim made by NVIDIA rather than an independent evaluation.[3]
The public GitHub repository publishes OpenShell under the Apache License 2.0.[6] That states the project’s licence, not the security outcome of a deployment.
Sentry is a reference design, not a test result
NVIDIA describes OpenShell as the runtime layer and Sentry as an out-of-band watchdog on BlueField-4 DPUs.[1][5] The company says Sentry can quarantine an agent in milliseconds.[1] TechCrunch reports that NVIDIA chief executive Jensen Huang said the platform would have prevented recent agent breakouts; that is an attributed company assessment, not an independently reproduced result.[2]
NVIDIA says OpenShell can be extended to Arm and Intel compute platforms, while the Sentry reference design is built around BlueField-4.[1][5] Those statements describe different parts of the stack and do not establish that the complete platform runs across every processor or deployment.[1][5]
NVIDIA reports limited OpenShell tests
The technical walkthrough describes a curl policy example: an unauthorised outbound request is blocked, a configured read-only GitHub API request is allowed, and a POST is blocked under that policy.[4] NVIDIA presents these as examples of configured controls, not measurements across deployments.[4]
NVIDIA reports an adversarial experiment in which frontier agents with reduced safeguards spent up to two hours trying to persuade an AI reviewer to grant permissions to modify a protected GitHub repository.[4] The company says no protected repository writes occurred in those tests.[4] The page does not state a trial count, name the exact agents or models, provide per-trial results, or report independent replication.[4]
These are vendor-reported OpenShell results, not an independent security evaluation.[4] They do not test Sentry’s BlueField-4 design or the millisecond claim.[1][4][5] NVIDIA’s walkthrough warns that blocking one tool may leave another permitted tool or generated code able to make the same request.[4] It says filesystem and process restrictions are set when the sandbox starts.[4]
What a Sentry evaluation would need to show
An independent Sentry evaluation could identify the software and hardware versions, policies, models, agent frameworks and attack classes tested. It could report blocked and successful attempts, false alarms and response latency. These fields would let readers compare results across implementations and configurations.
The announcement and TechCrunch report do not provide independent Sentry measurements for detection, policy-bypass resistance or response time.[1][2] NVIDIA’s technical walkthrough documents OpenShell examples and a vendor-reported experiment, not a Sentry performance test.[4][5]
GitHub’s v0.1.2 release record was marked latest on 29 September.[8] NVIDIA describes Sentry as a BlueField-4 reference design.[1][5] The millisecond response figure remains NVIDIA’s claim.[1]
Sources
[1] NVIDIA launches Open Agent Safety Platform
[2] TechCrunch reports on Nvidia agent-safety platform
[3] NVIDIA OpenShell product documentation
[4] NVIDIA technical blog on OpenShell runtime controls
[5] NVIDIA technical blog on Sentry reference design
[6] NVIDIA/OpenShell public source repository