NVIDIA's OpenShell sandbox for AI agents uses Landlock, seccomp, and a Rego policy engine to contain agent behavior, but security researcher Oleg Sidorkin argues the containment relies on unproven memory safety across 767 external dependencies and the Linux kernel itself, with critical gaps like default-allow seccomp filters and fallback modes that disable protections entirely.