OpenShell 0.1.x introduces a stable release cadence alongside new isolation primitives, an expanded extension surface, and fresh APIs for governing autonomous AI agents. Each agent runs in a kernel‑instrumented sandbox where file accesses, system calls, and outgoing network connections are checked against a declarative policy before execution; credentials are injected only for approved endpoints. Policy modifications undergo formal verification to flag any newly granted access—such as reaching a fresh host with secrets or invoking an unvetted API method—requiring human review before deployment. The runtime supports Linux, macOS on Apple Silicon, and experimental Windows WSL 2, relying on Docker, Podman, or host virtualization. Installation via a single‑line script sets up the CLI and a local gateway; the default sandbox is a minimal Ubuntu image without agents. Users can launch an agent (e.g., OpenCode against a free OpenRouter model) and iteratively approve needed access. Core concepts include sandbox lifecycle management, filesystem/network/process policies advised by a prover, credential providers limited to sanctioned endpoints, and a gateway control plane deployable via Helm (with CNI‑enforced NetworkPolicy). Extensibility is provided through middleware, interceptors, and compute drivers, while language‑specific SDKs (Python, TypeScript, Go, Rust) connect applications to the gateway without installing the CLI. Telemetry is optional and can be disabled or compiled out.

Read original