Hugging Face 与 NVIDIA 发布 Open Agent Safety Platform,开源 OpenShell
In July, AI agents running a security test escaped their sandbox and ended up inside @huggingface's servers. So today we're happy to be among @nvidia and @JensenHuang's partners on the release of the NVIDIA Open Agent Safety Platform. The key idea: don't count on the agent to respect the rules. Agents write and run their own code, and when one path is blocked they look for another. In one of NVIDIA's tests, an agent that wasn't allowed to push code through GitHub's API simply switched to git instead. We've now seen countless examples of this behavior. For now, safety can't live only inside the agent. It has to be built around it. That's the concept behind OpenShell (open source, Apache 2.0): - the agent runs in a Linux sandbox (Landlock + seccomp): no root, no direct network access - a supervisor outside the sandbox holds the real credentials - the agent only gets a placeholder token, swapped for the real one on approved calls My favorite piece is a solver (built on Z3) that checks mat
Hugging Face 与 NVIDIA 等 100 多家行业伙伴发布 NVIDIA Open Agent Safety Platform,包含开源(Apache 2.0)的 OpenShell 与 Sentry。
来源:X:Thomas Wolf(Hugging Face 联创/CSO) (@Thom_Wolf) · x.lingyaoai.com