
This is cool
OpenShell is a sandbox NVIDIA published. A tok/s on this desk is still a serving number. The shell does not change the weight.
Mikko Haapoja posted one line and a link. The link is NVIDIA OpenShell. It keeps an agent inside a policy. It does not serve a model, and this desk did not run it.
The pointer
The post is two words and a link, github.com/NVIDIA/OpenShell/. He did not publish a speed. The runtime is NVIDIA's. The pointer is his. The bio on the post says he builds AI at Opendoor, and before that at Shopify. That is a bio. It is not a review.
What NVIDIA printed
The repo calls OpenShell the safe, private runtime for fleets of autonomous AI agents. An agent may read files, install packages, call APIs, and use credentials. A policy says what it may touch. NVIDIA says the kernel enforces that policy on file access, system calls, and network connections, and a prover checks a policy change before it is applied. The agent does not hold the real credential. The credential is added only on a call the policy allows. Linux and Apple Silicon are listed. Windows is listed through WSL 2 and marked experimental. The license is Apache 2.0. Their architecture page names a gateway, a supervisor, and a sandbox: docs.nvidia.com/openshell/latest/about/architecture. This desk did not install the script and did not test those claims.
Still a serving number
A decode on Hardware is tokens per second after the prompt is in. Payback turns that number into months at a US street price. An agent sitting in a sandbox does not change either page. A file on Recipes is still how a named load is installed. OpenShell does not print a tok/s, and it does not replace the weight.
Two sentences about privacy
NVIDIA says the agent never sees the credential. Inference says the prompt is wiped when a machine takes the job, and the ledger keeps the count, not the words. Those are different sentences. One is their runtime. One is this desk. Neither one proves the other.