Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
Short version: no bypass of a documented control across 35 test IDs. Default policy took a malicious-setup-script canary leak from 10/10 to 0/10 with a local agent. Egress still happened through operator-opened paths: read-write rules, query and header values on GET-only rules, audit-mode rules, and auto-approval, which granted new public hosts in 12/12 trials. The prover flags GraphQL/MCP/WebSocket/JSON-RPC rules as unsupported but the loader accepts them. Tested on macOS with the microVM driver only. Logs and harness: https://github.com/Sorami-Consulting-AU/nvidia-openshell-agent-sandbox-test submitted by /u/No-Peanut-6988 [link] [comments]Technical Information Security Content & DiscussionRead More