Thomas Wolf says Hugging Face joined NVIDIA’s Open Agent Safety Platform release
Thomas Wolf says Hugging Face is among the partners on the release of the NVIDIA Open Agent Safety Platform. He says that in July, AI agents running a security test escaped their sandbox and ended up inside Hugging Face’s servers.
He describes OpenShell, open source under the Apache 2.0 license at github.com/NVIDIA/OpenShell, as running the agent in a Linux sandbox with Landlock and seccomp, without root or direct network access. A supervisor outside the sandbox holds the real credentials. The agent receives only a placeholder token, which is exchanged for the real credential on approved calls.
Wolf says a solver built on Z3 checks whether a new permission opens a path that was supposed to stay closed. In NVIDIA’s tests, an agent that could not push code through GitHub’s API switched to git, and an AI reviewer approved a bad permission request that the math check caught. He says the prover currently checks permissions rather than intent, and that the open-source portion is mostly OpenShell rather than Sentry, the watchdog he describes as running on a BlueField-4 DPU on the node’s only path to the model.