Open-sourcing a shell-level security layer for AI agents

Reddit r/AI_Agents Tools

Summary

Open-sourcing a shell-level control layer that blocks dangerous commands, exposes fake secrets, and enforces runtime policies to make AI agents safer and more deterministic in developer environments.

After working with AI agents for a while, I kept running into the same issue: eventually the agent ignores boundaries, reads `.env` files, touches production resources, or uses secrets it was never supposed to access. Even with MCP read-only setups and carefully written prompts, the shell itself is still trusted too much. So I started building a shell-level control layer for AI agents: * block or sanitize dangerous commands * expose virtual/fake secrets instead of real ones * separate DEV / PROD access policies * restrict network/domain access * enforce runtime policies instead of relying only on prompts The goal is to make agents safer and more deterministic inside real developer environments. I’m now open-sourcing it and looking for people who use Claude Code, Codex, Cursor, etc. to try breaking it on real workflows. Feedback, criticism, and attack ideas are very welcome. link to PyPI in the comments
Original Article

Similar Articles

How Autonomous AI Agents Become Secure by Design With NVIDIA OpenShell

NVIDIA Blog

NVIDIA launches OpenShell, a secure-by-design runtime for autonomous AI agents that isolates agent operations in sandboxes and enforces security policies at the system level rather than relying on behavioral prompts. The toolkit, part of NVIDIA Agent Toolkit, enables enterprises to run coding agents and agentic workflows with unified policy management and compliance oversight.