NVIDIA/NemoClaw

Run agents like Hermes, LangChain Deep Agents, and OpenClaw more securely inside NVIDIA OpenShell with managed inference

What it solves

NemoClaw provides a secure way to run AI agents on a host machine by isolating them within sandboxes. This prevents agents from having unrestricted access to the host system, reducing the security risks associated with letting AI agents execute code or manage files.

How it works

It acts as a reference stack that integrates with NVIDIA OpenShell to create sandboxed environments. The system uses a CLI to manage the entire lifecycle of these sandboxes, including guided onboarding, managed inference, network policy enforcement (controlling egress and ingress), and snapshots. It supports specific agent frameworks like OpenClaw, Hermes, and LangChain Deep Agents Code.

Who it’s for

Developers and researchers who want to deploy AI agents (specifically coding agents) in a controlled, secure environment on DGX systems or Windows Subsystem for Linux (WSL).

Highlights

  • Sandboxed Execution: Runs agents inside NVIDIA OpenShell sandboxes for increased safety.
  • Managed Infrastructure: Handles inference providers, network policies, and sandbox snapshots via a dedicated CLI.
  • Supported Agents: Out-of-the-box support for OpenClaw, Hermes, and LangChain Deep Agents Code.
  • Security Controls: Includes sandbox hardening, capability drops, and process limits to restrict agent behavior.

Related

  • Project
  • Project
  • Project
  • Project
  • Project