🧩 Framework & Thư viện•Mã nguồn mở•Đang hoạt động

NemoClaw

NVIDIA's enterprise security wrapper cho OpenClaw, chạy trong OpenShell sandbox với policy-based network control và private inference routing. 18K stars.

#nemoclaw
Danh mục
🧩 Framework & Thư viện
Giá
Mã nguồn mở
GitHub Stars
⭐ 22,633
Ngôn ngữ
TypeScript
License
Apache-2.0
Ngày thêm
2026-04-01
Tóm tắt từ README GitHub
NVIDIA NemoClaw: Reference Stack for Sandboxed AI Agents in OpenShell NVIDIA NemoClaw is an open source reference stack for running supported AI agents more safely inside NVIDIA OpenShell sandboxes. It provides guided onboarding, managed inference, network policy, managed integrations, OpenShell-backed state persistence, and lifecycle operations through the NemoClaw CLI and its agent-specific aliases. Supported agents: - OpenClaw (default) - Hermes - LangChain Deep Agents Code For capabilities, architecture, security controls, and the full feature list, see the NemoClaw documentation. Get Started Start with Your Coding Agent Use the starter prompt when you want Cursor, Claude Code, Codex, Copilot, or another local coding agent to install NemoClaw with you. Copy the NemoClaw starter prompt . The prompt tells your agent to use NemoClaw docs and skills, ask one question at a time, run commands only with your approval, and keep secrets out of chat. Install Using the Installer in Your Terminal Review Prerequisites before installing. On a supported DGX or Windows Subsystem for Linux (WSL) host, press Enter at the prompt to use the recommended preset settings for that platf
Xem thêm từ README.md

Đánh giá chi tiết

Tổng quan

NemoClaw là reference stack từ NVIDIA giúp chạy OpenClaw (và các AI agent khác như Claude, Cursor) bên trong NVIDIA OpenShell, một runtime sandbox cách ly. Ra mắt tại GTC 2026, Apache 2.0 license. Mục tiêu: đưa AI agent vào enterprise bằng cách thêm lớp bảo mật và kiểm soát mà không giảm khả năng của agent.

Tính năng chính

  • Sandbox cách ly: agent không truy cập được file ngoài sandbox, không gọi network đến endpoint chưa được duyệt, không leo quyền. Deny-by-default.
  • Policy-based network control: định nghĩa declarative rules cho egress traffic. Agent muốn gọi endpoint mới phải được human approve real-time.
  • Private inference routing: model calls bị intercept trước khi rời sandbox. Dữ liệu nhạy cảm (PII, code) chạy qua local models (Nemotron, Llama, Qwen). Queries không nhạy cảm có thể route ra cloud (OpenAI, Claude, Gemini).
  • Multi-agent support: không chỉ OpenClaw, mà Claude và Cursor cũng chạy được trong sandbox riêng biệt.
  • Audit logs cho mọi inference call.
  • Cài đặt bằng một lệnh: curl -fsSL https://nvidia.com/nemoclaw.sh | bash

Stack kỹ thuật

JavaScript (plugin layer), NVIDIA OpenShell (sandbox runtime), blueprint execution layer. Apache 2.0 license.

Điểm mạnh

  • Từ NVIDIA, đội ngũ và hạ tầng enterprise-grade. 18K stars, 2.1K forks.
  • Giải quyết vấn đề thực: agent tự trị cần boundaries rõ ràng cho enterprise adoption.
  • Không thay đổi agent, chỉ wrap thêm lớp bảo mật bên ngoài.

Hạn chế

  • Early preview, chưa production-ready. 461 open issues.
  • Cần NVIDIA GPU infrastructure cho private inference routing tối ưu.
  • Phức tạp hơn đáng kể so với chạy OpenClaw trực tiếp.

Phù hợp khi nào

Tổ chức muốn deploy AI agent (OpenClaw, Claude, Cursor) trong môi trường enterprise với yêu cầu bảo mật, kiểm soát network, và private inference.

NemoClaw | Atlas for AI