Three supported agents run inside one OpenShell boundary
NemoClaw wraps OpenClaw, Hermes, or LangChain Deep Agents Code in NVIDIA OpenShell. The host CLI guides installation and controls sandbox lifecycle, while integration code adapts each supported agent to managed inference, network policy, credentials, and snapshots. This is narrower than a generic agent platform. The value comes from having a defined stack whose host operations and sandbox permissions can be documented together.
OpenClaw is the express-install default. The interactive installer lets users choose Hermes or Deep Agents, a sandbox name, an inference provider, and a model. A separate starter prompt is written for Cursor, Claude Code, Codex, Copilot, and similar coding agents. It tells the assistant to use official documentation, ask one question at a time, request approval before commands, and keep secrets out of chat.
Our 36-second test run stopped on two unresolved modules
commit 60110b5 contained 5,970 files, about 1,499,822 source lines, and occupied 109.1 MB. Npm installed 387 packages in 47 seconds and used 436 MB on disk. Npm audit reported 0 known vulnerabilities at critical, high, moderate, and low severity. There was no standalone build script or target, so the lab skipped that step.
Tests ran for 36 seconds and ended with exit code 2. TypeScript reported that src/commands/migration-state.ts could not find json5 or tar, and src/security/snapshot-sanitizer.ts could not find json5. The log proves resolution failed in our installed checkout. It does not show whether the packages were omitted, generated elsewhere, or expected from another workspace state.
What happened when we ran it
Our sandbox completed the 387-package install in 47 seconds on 3 CPUs with 8 GB of RAM. The test command invoked clean, policy-boundary compilation, CLI generation work, and TypeScript builds before reaching the missing-module errors. It did not clear the full suite.
The repository scan found 42 CI workflow files, a Dockerfile, and a tests directory. Those are good source-level signals, but they do not override the measured failure at commit 60110b5. No runtime sandbox, agent, model, or provider was launched in the lab, so our result says nothing about inference speed or containment against an adversarial workload.
Network policy and credentials stay operator decisions
NemoClaw documents baseline network rules, approval flow, custom policies, sandbox hardening, capability drops, and process limits. Managed integrations route credentials into the sandbox rather than asking an agent to paste secrets into conversation. Snapshots and lifecycle commands give an operator a way to preserve or recover state. These controls address real risks in agents that browse, edit files, and run commands.
They are controls, not a proof of safety. A permissive egress rule can expose data, a broad credential can authorize damaging actions, and an approved installer command can still change the host. Review the policy generated for each agent and provider. Test denial paths as well as successful calls. Keep the inference key and connector credentials scoped, rotated, and absent from transcripts and shell history.
Contributor setup is deliberately separate from runtime setup
The repository's dev-setup.sh prepares local dependencies, builds, and hooks without creating a runtime sandbox. --expose-cli makes a development CLI visible on the host, while --with-runtime opts into sandbox validation and CLI exposure. That separation is sensible because editing TypeScript does not automatically authorize a new sandbox or host command surface.
End users follow the installer and platform prerequisites instead. The README names supported DGX and Windows Subsystem for Linux hosts for express setup. That leaves other Linux machines, macOS, and custom clusters outside the promise expressed on the front page. OpenShell itself is the better starting point if you need to integrate an agent that NemoClaw does not list.
Alpha status matches the pace of current work
GitHub showed 22,288 stars and 465 combined open issues and pull requests when fetched. There was no latest GitHub release returned by the API. The repository was pushed August 26, 2026, and pull requests updated that hour covered credential routes, sandbox authority, installer recovery, MCP adapter revisions, and end-to-end tests. That is intense development, not a settled release channel.
The README calls NemoClaw alpha and says maintainers review community work on a best-effort basis without guaranteed response times. Its priorities include installer reliability, sandbox hardening, credential handling, network defaults, provider validation, and documentation alignment, while warning that priorities are not delivery commitments. Buyers should take that wording literally and avoid turning an aspiration into a promised feature date.
The right trial tests the boundary, not just the agent
A useful evaluation starts with one supported agent and one low-privilege inference provider. Install on a disposable supported host, inspect every requested command, and capture the generated network rules. Then test blocked domains, revoked credentials, snapshot restore, installer repair, and removal. Agent task quality is secondary until the boundary behaves predictably.
NemoClaw's 47-second dependency install and clean npm audit make its source approachable, while the failed TypeScript step prevents a clean recommendation for this commit. The design is most relevant to NVIDIA and WSL operators who already want OpenClaw, Hermes, or Deep Agents. Everyone else should compare OpenShell directly with E2B or another sandbox API before adopting the extra layer.

