Skip to content
Navigation Menu
Toggle navigation
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Spark
Build and deploy intelligent apps
GitHub Models
Manage and compare prompts
MCP Registry
New
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
Accelerator
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search or jump to...
Search code, repositories, users, issues, pull requests...
Search syntax tips
Provide feedback
Saved searches
Use saved searches to filter your results more quickly
Sign in
Sign up
Appearance settings
Resetting focus
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
NVIDIA
/
OpenShell
Public
Notifications
You must be signed in to change notification settings
Fork
628
Star
5.5k
Code
Issues
112
Pull requests
29
Discussions
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Security and quality
Insights
Issues
Search Issues
is
:
issue
state
:
open
is:issue state:open
Search
Labels
Milestones
New issue
Search results
Open
Closed
feat: pre-register prometheus metrics at startup so /metrics is never empty
Status: Open.
#1119
In NVIDIA/OpenShell;
·
TaylorMutch
opened
on May 1, 2026
Bug: PATH override can hijack privileged
ip
and
nsenter
helpers
Status: Open.
#1113
In NVIDIA/OpenShell;
·
drew
opened
on May 1, 2026
feat(proxy): resolve policy-allow-listed TCP hostnames inside the sandbox so non-HTTP protocols are reachable
state:triage-needed
Opened without agent diagnostics and needs triage
Opened without agent diagnostics and needs triage
Status: Open.
#1107
In NVIDIA/OpenShell;
·
waterworthd-cim
opened
on May 1, 2026
feat(policy): suggest L7 scoping for known REST hosts
area:policy
Policy engine and policy lifecycle work
Policy engine and policy lifecycle work
area:sandbox
Sandbox runtime and isolation work
Sandbox runtime and isolation work
state:agent-ready
Approved for agent implementation
Approved for agent implementation
topic:l7
Application-layer policy and inspection work
Application-layer policy and inspection work
Status: Open.
#1099
In NVIDIA/OpenShell;
·
zredlined
opened
on Apr 30, 2026
feat(tui): render policy proposal inbox metadata
area:policy
Policy engine and policy lifecycle work
Policy engine and policy lifecycle work
area:tui
Terminal UI work
Terminal UI work
state:agent-ready
Approved for agent implementation
Approved for agent implementation
Status: Open.
#1098
In NVIDIA/OpenShell;
·
zredlined
opened
on Apr 30, 2026
feat(gateway): persist and validate agent policy proposal operations
area:gateway
Gateway server and control-plane work
Gateway server and control-plane work
area:policy
Policy engine and policy lifecycle work
Policy engine and policy lifecycle work
state:agent-ready
Approved for agent implementation
Approved for agent implementation
Status: Open.
#1097
In NVIDIA/OpenShell;
·
zredlined
opened
on Apr 30, 2026
feat(policy): add proposal provenance, operations, and guidance fields to proto
area:gateway
Gateway server and control-plane work
Gateway server and control-plane work
area:policy
Policy engine and policy lifecycle work
Policy engine and policy lifecycle work
state:agent-ready
Approved for agent implementation
Approved for agent implementation
Status: Open.
#1096
In NVIDIA/OpenShell;
·
zredlined
opened
on Apr 30, 2026
docs(agent): ship static sandbox policy advisor skill
area:docs
Documentation and examples
Documentation and examples
area:policy
Policy engine and policy lifecycle work
Policy engine and policy lifecycle work
area:sandbox
Sandbox runtime and isolation work
Sandbox runtime and isolation work
state:agent-ready
Approved for agent implementation
Approved for agent implementation
Status: Open.
#1095
In NVIDIA/OpenShell;
·
zredlined
opened
on Apr 30, 2026
feat(observability): enable OCSF JSONL for agent deny inspection
area:policy
Policy engine and policy lifecycle work
Policy engine and policy lifecycle work
area:sandbox
Sandbox runtime and isolation work
Sandbox runtime and isolation work
state:agent-ready
Approved for agent implementation
Approved for agent implementation
topic:observability
Logging, metrics, and observability work
Logging, metrics, and observability work
Status: Open.
#1093
In NVIDIA/OpenShell;
·
zredlined
opened
on Apr 30, 2026
feat(policy): return draft chunk ids from policy proposal submit
area:gateway
Gateway server and control-plane work
Gateway server and control-plane work
area:policy
Policy engine and policy lifecycle work
Policy engine and policy lifecycle work
state:agent-ready
Approved for agent implementation
Approved for agent implementation
Status: Open.
#1094
In NVIDIA/OpenShell;
·
zredlined
opened
on Apr 30, 2026
feat(policy): expose sandbox-local policy.local API
area:cli
CLI-related work
CLI-related work
area:policy
Policy engine and policy lifecycle work
Policy engine and policy lifecycle work
area:sandbox
Sandbox runtime and isolation work
Sandbox runtime and isolation work
state:agent-ready
Approved for agent implementation
Approved for agent implementation
Status: Open.
#1092
In NVIDIA/OpenShell;
·
zredlined
opened
on Apr 30, 2026
feat(policy): write effective sandbox policy for local agents
area:policy
Policy engine and policy lifecycle work
Policy engine and policy lifecycle work
area:sandbox
Sandbox runtime and isolation work
Sandbox runtime and isolation work
state:agent-ready
Approved for agent implementation
Approved for agent implementation
Status: Open.
#1091
In NVIDIA/OpenShell;
·
zredlined
opened
on Apr 30, 2026
You can’t perform that action at this time.