# NVIDIA NemoClaw: a reference stack for sandboxed agents in OpenShell

> NemoClaw wraps OpenClaw, Hermes and LangChain Deep Agents Code in NVIDIA OpenShell sandboxes with managed inference and network policy. It is an alpha project, and the README points to the documentation site for most operational detail.

**NVIDIA/NemoClaw** — Run agents like Hermes, LangChain Deep Agents, and OpenClaw more securely inside NVIDIA OpenShell with managed inference.

- Repository: https://github.com/NVIDIA/NemoClaw
- Website: https://docs.nvidia.com/nemoclaw/latest/
- Stars: 22,538 · Forks: 3,109
- Language: TypeScript
- License: Apache-2.0
- Published: 2026-08-04 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/nvidia-nemoclaw

## The problem NemoClaw addresses: agent runtimes with no boundary

An agent such as OpenClaw or Hermes runs code, reaches the network and holds credentials. Left on a developer workstation it has the same reach as the person sitting at the keyboard. NemoClaw's answer is to put the agent inside an NVIDIA OpenShell sandbox and manage the surrounding concerns from a host-side CLI: guided onboarding, inference routing, network policy, integrations, snapshots and lifecycle operations. The README frames the project as a reference stack, which is a meaningful word choice. It is not a general agent framework and it does not try to be one. It assumes you have picked an agent already and want the containment and operations layer around it. The supported list is short and explicit: OpenClaw is the default, with Hermes and LangChain Deep Agents Code as the other two. If your agent is not on that list, the project has nothing for you. The audience is correspondingly narrow: teams running one of those three agents on a supported DGX or Windows Subsystem for Linux host, who want egress control and managed inference without assembling it themselves.

## How the host CLI, blueprint and sandbox fit together

The repository layout separates concerns in a way that is worth reading before you install anything. There is a `nemoclaw/` directory holding the plugin, a `nemoclaw-blueprint/` directory, a `managed-inference/` directory, a `skills/` directory, and host-side entry points `install.sh` and `uninstall.sh`. The documentation describes the architecture as a host CLI, an agent integration layer, a blueprint, sandbox lifecycle, and protection layers. The Dockerfile shows the sandbox image being assembled in two stages: a builder stage that compiles the TypeScript plugin from source on `node:22-trixie-slim`, layered on top of a pre-built base image pulled from `ghcr.io/nvidia/nemoclaw/sandbox-base:latest`. The comment in that file is direct about why: the base carries the expensive, rarely-changing layers (apt, setpriv, users, the openclaw CLI), and the second stage layers PR-specific code on top. That split matters operationally. It means the sandbox image is not a single monolith you rebuild from scratch, and it means local builds without GHCR access require building the base first with `Dockerfile.base`. The package exposes several binaries: `nemoclaw`, `nemoclaw-acp`, `nemoclaw-blueprint-runner`, `nemohermes` and `nemo-deepagents`. The agent-specific aliases are how the same stack is pointed at different agents.

## Installing NemoClaw and running a first OpenClaw sandbox

The README gives two install paths and they are not interchangeable. The first is the installer in your terminal. Review the Prerequisites page first, then on a supported DGX or WSL host press Enter at the express install prompt. Express mode installs OpenClaw by default, so if OpenClaw is what you want, this is the short path:

```bash
Run express install with these settings? [Y/n]:
```

Accepting takes you to the Quickstart with OpenClaw. Enter `n` instead and the installer walks you through choosing Hermes or LangChain Deep Agents Code, a sandbox name, an inference provider and a model interactively. That interactive path is the one to take if you are not on OpenClaw, because the express preset will not ask.

The second path is the starter prompt, aimed at people who would rather have a local coding agent drive the install. The README names Cursor, Claude Code, Codex and Copilot as examples. You copy the prompt from the documentation site and hand it to your agent. According to the README, the prompt instructs the agent to use NemoClaw docs and skills, ask one question at a time, run commands only with your approval, and keep secrets out of chat. That last constraint is the reason this path exists at all: an installer that needs an inference provider credential is exactly the kind of thing you do not want pasted into a chat window.

There is a third path, and it is not for end users. Contributors prepare a source checkout without creating a runtime sandbox:

```bash
./scripts/dev-setup.sh
```

The README is explicit that the default and `--repair` modes change only repository-local dependencies, builds and hooks. `--expose-cli` is the flag that makes a host-visible development CLI, and `--with-runtime` is for changes that need sandbox validation. If you run `dev-setup.sh` expecting a working sandbox, you will not get one, and the README says so before you try.

## Hermes and the managed light skin

Hermes gets a detail the other agents do not, and it is the kind of thing that reveals how much of this project is about terminal ergonomics rather than security. When connecting to a Hermes sandbox from a light terminal, NemoClaw may install a managed `nemoclaw-light` Hermes skin so assistant text is readable. It removes that managed skin state when the terminal no longer needs it, and it preserves any user-selected Hermes skin. The word managed is doing real work in that sentence: NemoClaw tracks what it installed so it can take it back out without touching your own configuration. It is a small feature, but it is also a signal. The project is willing to reach into the agent's presentation layer to fix a readability problem, and it accepts the state-tracking obligation that comes with doing so. If you run Hermes on a dark terminal, none of this applies to you. If you run it over SSH into a light-background session, expect NemoClaw to touch your skin configuration and then restore it.

## Network policy, sandbox hardening and what the README does not cover

The documentation site has pages for Network Policies (baseline rules, operator approval flow, egress control), Customize Network Policy (static and dynamic changes, presets), Security Best Practices (controls reference, risk framework, posture profiles) and Sandbox Hardening (container security measures, capability drops, process limits). Those titles tell you the shape of the controls, but the README itself does not reproduce the baseline rules, the preset names or the approval flow. Anyone evaluating NemoClaw for a regulated environment will have to read those pages directly rather than rely on the repository front page.

The more consequential gap is rollback. The README documents `install.sh` and `uninstall.sh` as top-level entries and describes the managed Hermes skin being removed when no longer needed, but it does not document what happens to sandbox state, snapshots or host-side configuration when you uninstall or when an upgrade goes wrong. Snapshots are listed as a capability, not explained. For a project whose entire premise is containment, the absence of a stated recovery path in the README is a real limitation, and it is the first thing to resolve from the docs before you put this in front of a team. The README also states plainly that NemoClaw is an alpha project and that maintainers review issues, discussions and pull requests on a best effort basis without guaranteed response timelines. That is an honest disclosure and it should shape your expectations more than any feature list.

## NemoClaw versus OpenShell alone, and versus running OpenClaw bare

The documentation has a dedicated Ecosystem page answering when to use NemoClaw versus OpenShell alone, which is the right comparison to make first. OpenShell is the sandbox. NemoClaw is the layer that onboards an agent into it and manages inference, network policy, integrations and lifecycle. If you are comfortable writing your own sandbox configuration and your inference routing, OpenShell alone is the smaller dependency and you are not signing up for an alpha CLI on top. What you give up is the guided onboarding and the agent-specific aliases, which means you own the integration work for OpenClaw, Hermes or Deep Agents Code yourself.

The second comparison is against running OpenClaw directly on the host with no sandbox. That is the fastest path to a working agent and it is the wrong one the moment the agent has network access and credentials, because the agent's blast radius equals your user account's. NemoClaw's value is entirely in that gap. If your agent runs against local files with no egress and no secrets, the sandbox buys you little and the installer, blueprint and policy layers are overhead you will maintain for no return. The comparison against Hermes is a category error: Hermes is one of the agents NemoClaw runs, not an alternative to it. The `nemohermes` binary in the package is the alias that points the stack at Hermes.

## Licence, upgrade cost and the alpha caveat

NemoClaw is Apache-2.0, and the package metadata and source headers both carry that identifier. Apache-2.0 is permissive and includes an express patent grant, which matters for a stack that touches NVIDIA inference. The repository also carries a SECURITY.md and asks that vulnerabilities go through private channels rather than public issues. Note that the sandbox image pulls a base from GHCR and that the Dockerfile pins integrity hashes for the Codex ACP artifacts, so an upgrade is not purely a matter of bumping a version number: the build arguments and their pinned digests move together. The package version is 0.1.0, which is consistent with the alpha label in the README. No release list appears in the repository, so upgrade cadence cannot be stated from what the project publishes. Treat the pinned digests and the two-stage image as the practical upgrade surface: when the base image changes, your local build arguments need to change with it. This is a description of the licence terms and the build layout, not legal advice.

## Conclusion

Adopt NemoClaw if you already run OpenClaw or Hermes and want the sandbox, network policy and inference routing handled by a single CLI on a supported DGX or WSL host. Do not adopt it if you need a stable API surface or a documented rollback path, since the README calls the project alpha and does not describe one. Before installing, verify your host against the Prerequisites page, decide whether you want the express preset (OpenClaw) or the interactive path for Hermes or Deep Agents Code, and confirm which inference provider you will route through.

## FAQ

### What does NemoClaw do?

It is an open source reference stack for running supported AI agents more safely inside NVIDIA OpenShell sandboxes, providing guided onboarding, managed inference, network policy, managed integrations, snapshots and lifecycle operations through the NemoClaw CLI and its agent-specific aliases.

### Is NVIDIA NemoClaw free?

The repository is licensed under Apache-2.0, which is a permissive open source licence with an express patent grant. The README describes no pricing or paid tier.

### Can I use NemoClaw with Claude Code?

The README lists Claude Code among the local coding agents you can hand the NemoClaw starter prompt to, so it can drive the install with you. That is different from running Claude Code as the sandboxed agent: the supported agents are OpenClaw, Hermes and LangChain Deep Agents Code.

### What are the key differences between OpenClaw and NemoClaw?

OpenClaw is one of the agents NemoClaw runs, and it is the default one installed by express install mode. NemoClaw is the surrounding stack that puts that agent inside an OpenShell sandbox and manages inference, network policy and lifecycle.

### How do I install NemoClaw?

Review the Prerequisites page, then on a supported DGX or Windows Subsystem for Linux host run the installer and press Enter at the express install prompt to accept the recommended preset settings, which installs OpenClaw by default. Enter n to choose Hermes or LangChain Deep Agents Code, a sandbox name, an inference provider and a model interactively.

### How do I use NemoClaw with Ollama?

The README does not name Ollama. It points to a Choose an Inference Provider page covering supported providers, validation and routed inference configuration, so that page is where to check whether your provider is supported.

## Sources

- [Official documentation](https://docs.nvidia.com/nemoclaw/latest/)
- [Official README](https://github.com/NVIDIA/NemoClaw#readme)
- [Project repository](https://github.com/NVIDIA/NemoClaw)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/nvidia-nemoclaw
