This is an early release preview. You may encounter bugs.
NemoClaw logo
Unclaimed

Harness security deployment

NemoClaw

NVIDIA reference stack running OpenClaw, Hermes, or Deep Agents inside OpenShell sandboxes with managed inference and network policy

Built by NVIDIA

A 82/100 GitHub score ? This grade is derived from GitHub signals, not user votes. Open for the full breakdown.
No votes yet

01 / About

What NemoClaw is.

NVIDIA NemoClaw is an open source reference stack for running AI agents inside NVIDIA OpenShell sandboxes. It adds guided onboarding, managed inference, network policy, managed integrations, snapshots, and lifecycle operations on top of OpenShell, exposed through the NemoClaw CLI and agent-specific aliases.

Supported agents are OpenClaw (the default), Hermes, and LangChain Deep Agents Code. An express install on a supported DGX or Windows Subsystem for Linux host applies preset settings and installs OpenClaw; an interactive install lets you choose the agent, sandbox name, inference provider, and model. A starter prompt lets a local coding agent such as Cursor, Claude Code, Codex, or Copilot drive the installation with you, running commands only on approval and keeping secrets out of chat.

The stack is organised as a host CLI, an agent integration layer, a blueprint, and a sandbox lifecycle with protection layers. Documentation covers inference routing across hosted, local, and custom endpoints, sandbox hardening (capability drops and process limits), credential storage and rotation, corporate CA trust, and headless server deployment. NemoClaw is an alpha project.

Features

  • Sandboxed agents: OpenClaw, Hermes, or Deep Agents Code run inside OpenShell with kernel-level isolation
  • Managed inference: a choice of hosted providers, local inference, or custom endpoints, with validation commands
  • Network policy: baseline egress rules, an operator approve/deny flow for requests, presets, and integration policy examples
  • Agent configuration: progressive tool disclosure, context compaction, heartbeats, memory search, task-specific sub-agents, and a declarative multi-agent manifest
  • Integrations: messaging channels, MCP servers, and OpenClaw plugins managed from the CLI
  • State and backups: snapshots and state management for sandboxes
  • Monitoring: sandbox activity monitoring and gateway lifecycle authority
  • Security controls: credential storage and rotation, corporate CA trust, and a documented trusted computing base

02 / Discussion CREDIBILITY-GATED

Discussion

Reading is open to everyone. Posting and voting need a verified identity or a GitHub grade of B or higher.

  • No discussions yet.

04 / Build

Build with NemoClaw.

Browse the catalogue for frameworks, tools, and harnesses, each scored on real GitHub credibility.

Get NemoClaw →

Browse the catalogue