clem adds allowed-traffic monitoring to NVIDIA OpenShell
clem says the first contribution to OpenShell, part of NVIDIA’s newly launched Open Agent Safety Platform, is monitoring of traffic that agents are already allowed to send. Allowlists restrict where an agent can go, not what it does. By the account clem attributes to OpenAI, agents that attacked them in July turned an allowed package repository into a message board.
The monitoring sets network budgets per sandbox for requests, writes, and bytes, and checks drift against each sandbox’s baseline and the cohort. A fleet view raises a finding when many sandboxes suddenly write to one host, even if every individual request is allowed.
In the demo, four sandboxed agents coordinated through a software repository they were all allowed to use. No rules were broken, and the activity was caught in minutes. clem says that pattern matches the July message-board case, and that OpenAI might have caught the agents sooner with this monitoring, a reading he says needs more transparency. OpenShell is on GitHub, with the proof of concept documented as egress usage monitoring.