Docs

OpenShell sandboxes

Experimental worker isolation through NVIDIA OpenShell: one task runs inside a MicroVM with Landlock, Shield masking, network policy, and verified patch export. Host CLI legs still use git worktrees only; OpenShell is a separate execution backend you name explicitly.

When to use it

  • You want edits and tests inside a VM boundary instead of a host subprocess with approvals off.
  • You run sandbox-only parallel or sequential workflows (/openshell A + /openshell B, or stages joined with > when every stage is sandbox-only).
  • You need /team /openshell for a director-planned sandbox team (tool-less director splits work into one parallel OpenShell stage).

Mixed host and sandbox stages are refused: sandbox output cannot safely feed a host agent, and host agents can read secrets the VM is meant to keep out.

How to run

EntryWhat it does
/openshell <task>TUI turn through the sandbox runner
captain with openshell "<task>"Shell one-shot on the same path
/team /openshell <task>Sandbox-only team planned by the director
captain openshell --resume <run-dir>Resume a checkpointed sequence after a stop or crash

Add gate: <cmd> like any workflow stage. /noslop applies plain-writing rules inside the sandbox too. After a successful sandbox workflow, an advisory Claude safe-mode review of the diff runs by default (CAPTAIN_OPENSHELL_ADVISORY_REVIEW=0 opts out).

Prepare the host

OpenShell is not on the auto-routing ladder. It needs operator-prepared env vars (pilot checkout, verification argv, allowed paths). Defaults and the full list live in the product tree as CONFIGURATION.md § OpenShell workers.

  • CAPTAIN_OPENSHELL_PREPARED, CAPTAIN_OPENSHELL_PILOT, CAPTAIN_OPENSHELL_ALLOWED, CAPTAIN_OPENSHELL_VERIFY — required before dispatch.
  • CAPTAIN_OPENSHELL_PROFILE — inference profile (default glm-cheap-z-ai-fp8).
  • captain openshell profiles — registry-generated ZDR profiles; captain openshell qualify — run the pilot fixture before trusting a profile.

See also workflows, security, and the features harness section.