Andrew Ng says OpenWorker will use Nvidia OpenShell for sandboxed AI agents
Original titleThe OpenAI-Hugging Face hack was enabled by weak sandboxing. It is great that Nvidia is releasing open source tools for sandboxing AI age...
AISummary
Andrew Ng says OpenWorker, his open-source agent harness for cybersecurity workflows, will run each agent's commands inside a sandbox built on Nvidia OpenShell.
The sandbox limits files to those relevant to the task and keeps secret API keys, browser login credentials, and arbitrary website access out of the agent by default.
Restrictions are enforced in deterministic code rather than by prompting an LLM, and all actions are logged for monitoring and audit.
Source: Andrew Ng · x.com