PluginBench
Skill
Review
Audit score 70

nvidia-nemoclaw

aradotso/trending-skills

Secure sandboxed OpenClaw AI assistants with NVIDIA Nemotron inference and policy-enforced isolation.

What is nvidia-nemoclaw?

NVIDIA NemoClaw is a TypeScript CLI plugin that installs and orchestrates OpenClaw always-on AI assistants within policy-enforced sandboxes using NVIDIA OpenShell. It routes all inference through NVIDIA cloud (Nemotron models) while governing network egress, filesystem access, syscalls, and API calls via declarative security policies.

  • Create and manage isolated sandboxes for OpenClaw agents with Landlock, seccomp, and network namespace isolation
  • Route all inference through NVIDIA cloud Nemotron models via secure gateway
  • Define and enforce declarative security policies for network egress, filesystem access, and syscalls
  • Connect interactively to sandboxes and chat with agents via TUI or CLI
  • Monitor sandbox health, logs, and policy state in real time
  • Deploy agents to remote GPU instances via Brev integration

How to install nvidia-nemoclaw

npx skills add https://github.com/aradotso/trending-skills --skill nvidia-nemoclaw
Prerequisites
  • Linux Ubuntu 22.04 LTS or later
  • Node.js 20+ and npm 10+ (Node.js 22 recommended)
  • Docker installed and running
  • NVIDIA OpenShell installed
  • NVIDIA API key from build.nvidia.com
Claude Code
Cursor
Windsurf
Cline

How to use nvidia-nemoclaw

  1. 1.Run the one-line installer: curl -fsSL https://nvidia.com/nemoclaw.sh | bash
  2. 2.Set NVIDIA_API_KEY environment variable with your API key from build.nvidia.com
  3. 3.Run nemoclaw onboard and follow the interactive wizard to configure sandbox name, model, and policies
  4. 4.Connect to the sandbox with nemoclaw <name> connect
  5. 5.Chat with the agent using openclaw tui (interactive) or openclaw agent CLI commands inside the sandbox
  6. 6.Monitor sandbox health with nemoclaw <name> status and logs with nemoclaw <name> logs --follow

Use cases

Good for
  • Set up a secure always-on AI assistant that can only access approved external APIs and local directories
  • Run multiple isolated OpenClaw agents on a single host with independent policies and models
  • Deploy an OpenClaw agent to a remote GPU instance with automatic sandbox configuration
  • Monitor and audit all network and filesystem activity of a sandboxed AI assistant
  • Develop custom integrations using the TypeScript NemoClawClient API
Who it's for
  • DevOps engineers deploying secure AI assistants
  • AI/ML teams running OpenClaw agents in production
  • Security-conscious organizations requiring policy-enforced isolation
  • Developers building custom agent orchestration systems

nvidia-nemoclaw FAQ

What models are available for inference?

NemoClaw routes inference through NVIDIA cloud Nemotron models. The default is nvidia/nemotron-3-super-120b-a12b, but you can override it via the NEMOCLAW_MODEL environment variable or during onboarding.

Can I run multiple sandboxes on one host?

Yes. Each sandbox is isolated via OpenShell with independent policies, names, and configurations. Use nemoclaw onboard multiple times to create separate sandboxes.

How do I control what the agent can access?

NemoClaw uses declarative policies to govern network egress (allowedEgressHosts, blockUnlisted), filesystem access (allowedPaths, readOnly), and syscalls. Configure these during onboarding or programmatically via SandboxConfig.

Is NemoClaw production-ready?

NemoClaw is in Alpha status—interfaces and APIs may change without notice. Use for development and testing; production deployments should monitor release notes.

Can I use the TypeScript API to build custom integrations?

Yes. Import NemoClawClient from @nvidia/nemoclaw to programmatically create sandboxes, connect sessions, send messages, check status, and stream logs.

Full instructions (SKILL.md)

Source of truth, from aradotso/trending-skills.


name: nvidia-nemoclaw description: NVIDIA NemoClaw plugin for secure sandboxed installation and orchestration of OpenClaw always-on AI assistants via OpenShell triggers:

  • "set up NemoClaw for OpenClaw"
  • "install NVIDIA NemoClaw sandbox"
  • "run OpenClaw in a secure sandbox"
  • "configure NemoClaw inference with NVIDIA cloud"
  • "manage NemoClaw sandboxed agent"
  • "nemoclaw onboard and deploy agent"
  • "OpenShell sandbox with NemoClaw"
  • "secure OpenClaw installation with NVIDIA"

NVIDIA NemoClaw

Skill by ara.so — Daily 2026 Skills collection.

NVIDIA NemoClaw is an open-source TypeScript CLI plugin that simplifies running OpenClaw always-on AI assistants securely. It installs and orchestrates the NVIDIA OpenShell runtime, creates policy-enforced sandboxes, and routes all inference through NVIDIA cloud (Nemotron models). Network egress, filesystem access, syscalls, and model API calls are all governed by declarative policy.

Status: Alpha — interfaces and APIs may change without notice.


Installation

Prerequisites

  • Linux Ubuntu 22.04 LTS or later
  • Node.js 20+ and npm 10+ (Node.js 22 recommended)
  • Docker installed and running
  • NVIDIA OpenShell installed

One-Line Installer

curl -fsSL https://nvidia.com/nemoclaw.sh | bash

This installs Node.js (if absent), runs the guided onboard wizard, creates a sandbox, configures inference, and applies security policies.

Manual Install (from source)

git clone https://github.com/NVIDIA/NemoClaw.git
cd NemoClaw
npm install
npm run build
npm link  # makes `nemoclaw` available globally

Environment Variables

# Required: NVIDIA cloud API key for Nemotron inference
export NVIDIA_API_KEY="nvapi-xxxxxxxxxxxx"

# Optional: override default model
export NEMOCLAW_MODEL="nvidia/nemotron-3-super-120b-a12b"

# Optional: custom sandbox data directory
export NEMOCLAW_SANDBOX_DIR="/var/nemoclaw/sandboxes"

Get an API key at build.nvidia.com.


Quick Start

1. Onboard a New Agent

nemoclaw onboard

The interactive wizard prompts for:

  • Sandbox name (e.g. my-assistant)
  • NVIDIA API key ($NVIDIA_API_KEY)
  • Inference model selection
  • Network and filesystem policy configuration

Expected output on success:

──────────────────────────────────────────────────
Sandbox      my-assistant (Landlock + seccomp + netns)
Model        nvidia/nemotron-3-super-120b-a12b (NVIDIA Cloud API)
──────────────────────────────────────────────────
Run:         nemoclaw my-assistant connect
Status:      nemoclaw my-assistant status
Logs:        nemoclaw my-assistant logs --follow
──────────────────────────────────────────────────
[INFO]  === Installation complete ===

2. Connect to the Sandbox

nemoclaw my-assistant connect

3. Chat with the Agent (inside sandbox)

TUI (interactive chat):

sandbox@my-assistant:~$ openclaw tui

CLI (single message):

sandbox@my-assistant:~$ openclaw agent --agent main --local -m "hello" --session-id test

Key CLI Commands

Host Commands (nemoclaw)

CommandDescription
nemoclaw onboardInteractive setup: gateway, providers, sandbox
nemoclaw <name> connectOpen interactive shell inside sandbox
nemoclaw <name> statusShow NemoClaw-level sandbox health
nemoclaw <name> logs --followStream sandbox logs
nemoclaw startStart auxiliary services (Telegram bridge, tunnel)
nemoclaw stopStop auxiliary services
nemoclaw deploy <instance>Deploy to remote GPU instance via Brev
openshell termLaunch OpenShell TUI for monitoring and approvals

Plugin Commands (openclaw nemoclaw, run inside sandbox)

Note: These are under active development — use nemoclaw host CLI as the primary interface.

CommandDescription
openclaw nemoclaw launch [--profile ...]Bootstrap OpenClaw inside OpenShell sandbox
openclaw nemoclaw statusShow sandbox health, blueprint state, and inference
openclaw nemoclaw logs [-f]Stream blueprint execution and sandbox logs

OpenShell Inspection

# List all sandboxes at the OpenShell layer
openshell sandbox list

# Check specific sandbox
openshell sandbox inspect my-assistant

Architecture

NemoClaw orchestrates four components:

ComponentRole
PluginTypeScript CLI: launch, connect, status, logs
BlueprintVersioned Python artifact: sandbox creation, policy, inference setup
SandboxIsolated OpenShell container running OpenClaw with policy-enforced egress/filesystem
InferenceNVIDIA cloud model calls routed through OpenShell gateway

Blueprint lifecycle:

  1. Resolve artifact
  2. Verify digest
  3. Plan resources
  4. Apply through OpenShell CLI

TypeScript Plugin Usage

NemoClaw exposes a programmatic TypeScript API for building custom integrations.

Import and Initialize

import { NemoClawClient } from '@nvidia/nemoclaw';

const client = new NemoClawClient({
  apiKey: process.env.NVIDIA_API_KEY!,
  model: process.env.NEMOCLAW_MODEL ?? 'nvidia/nemotron-3-super-120b-a12b',
});

Create a Sandbox Programmatically

import { NemoClawClient, SandboxConfig } from '@nvidia/nemoclaw';

async function createSandbox() {
  const client = new NemoClawClient({
    apiKey: process.env.NVIDIA_API_KEY!,
  });

  const config: SandboxConfig = {
    name: 'my-assistant',
    model: 'nvidia/nemotron-3-super-120b-a12b',
    policy: {
      network: {
        allowedEgressHosts: ['build.nvidia.com'],
        blockUnlisted: true,
      },
      filesystem: {
        allowedPaths: ['/sandbox', '/tmp'],
        readOnly: false,
      },
    },
  };

  const sandbox = await client.sandbox.create(config);
  console.log(`Sandbox created: ${sandbox.id}`);
  return sandbox;
}

Connect and Send a Message

import { NemoClawClient } from '@nvidia/nemoclaw';

async function chatWithAgent(sandboxName: string, message: string) {
  const client = new NemoClawClient({
    apiKey: process.env.NVIDIA_API_KEY!,
  });

  const sandbox = await client.sandbox.get(sandboxName);
  const session = await sandbox.connect();

  const response = await session.agent.send({
    agentId: 'main',
    message,
    sessionId: `session-${Date.now()}`,
  });

  console.log('Agent response:', response.content);
  await session.disconnect();
}

chatWithAgent('my-assistant', 'Summarize the latest NVIDIA earnings report.');

Check Sandbox Status

import { NemoClawClient } from '@nvidia/nemoclaw';

async function checkStatus(sandboxName: string) {
  const client = new NemoClawClient({
    apiKey: process.env.NVIDIA_API_KEY!,
  });

  const status = await client.sandbox.status(sandboxName);

  console.log({
    sandbox: status.name,
    healthy: status.healthy,
    blueprint: status.blueprintState,
    inference: status.inferenceProvider,
    policyVersion: status.policyVersion,
  });
}

Stream Logs

import { NemoClawClient } from '@nvidia/nemoclaw';

async function streamLogs(sandboxName: string) {
  const client = new NemoClawClient({
    apiKey: process.env.NVIDIA_API_KEY!,
  });

  const logStream = client.sandbox.logs(sandboxName, { follow: true });

  for await (const entry of logStream) {
    console.log(`[${entry.timestamp}] ${entry.level}: ${entry.message}`);
  }
}

Apply a Network Policy Update (Hot Reload)

import { NemoClawClient, NetworkPolicy } from '@nvidia/nemoclaw';

async function updateNetworkPolicy(sandboxName: string) {
  const client = new NemoClawClient({
    apiKey: process.env.NVIDIA_API_KEY!,
  });

  // Network policies are hot-reloadable at runtime
  const updatedPolicy: NetworkPolicy = {
    allowedEgressHosts: [
      'build.nvidia.com',
      'api.github.com',
    ],
    blockUnlisted: true,
  };

  await client.sandbox.updatePolicy(sandboxName, {
    network: updatedPolicy,
  });

  console.log('Network policy updated (hot reload applied).');
}

Security / Protection Layers

LayerWhat it protectsHot-reloadable?
NetworkBlocks unauthorized outbound connections✅ Yes
FilesystemPrevents reads/writes outside /sandbox and /tmp❌ Locked at creation
ProcessBlocks privilege escalation and dangerous syscalls❌ Locked at creation
InferenceReroutes model API calls to controlled backends✅ Yes

When the agent attempts to reach an unlisted host, OpenShell blocks the request and surfaces it in the TUI for operator approval.


Common Patterns

Pattern: Minimal Sandbox for Development

const config: SandboxConfig = {
  name: 'dev-sandbox',
  model: 'nvidia/nemotron-3-super-120b-a12b',
  policy: {
    network: { blockUnlisted: false },   // permissive for dev
    filesystem: { allowedPaths: ['/sandbox', '/tmp', '/home/dev'] },
  },
};

Pattern: Production Strict Sandbox

const config: SandboxConfig = {
  name: 'prod-assistant',
  model: 'nvidia/nemotron-3-super-120b-a12b',
  policy: {
    network: {
      allowedEgressHosts: ['build.nvidia.com'],
      blockUnlisted: true,
    },
    filesystem: {
      allowedPaths: ['/sandbox', '/tmp'],
      readOnly: false,
    },
  },
};

Pattern: Deploy to Remote GPU (Brev)

nemoclaw deploy my-gpu-instance --sandbox my-assistant
await client.deploy({
  instance: 'my-gpu-instance',
  sandboxName: 'my-assistant',
  provider: 'brev',
});

Troubleshooting

Error: Sandbox not found

Error: Sandbox 'my-assistant' not found

Fix: Check at the OpenShell layer — NemoClaw errors and OpenShell errors are separate:

openshell sandbox list
nemoclaw my-assistant status

Error: NVIDIA API key missing or invalid

Error: Inference provider authentication failed

Fix:

export NVIDIA_API_KEY="nvapi-xxxxxxxxxxxx"
nemoclaw onboard  # re-run to reconfigure

Error: Docker not running

Error: Cannot connect to Docker daemon

Fix:

sudo systemctl start docker
sudo usermod -aG docker $USER  # add current user to docker group
newgrp docker

Error: OpenShell not installed

Error: 'openshell' command not found

Fix: Install NVIDIA OpenShell first, then re-run the NemoClaw installer.

Agent blocked on outbound request

When you see a blocked request notification in the TUI:

openshell term        # open TUI to approve/deny the request
# OR update policy to allow the host:
nemoclaw my-assistant policy update --allow-host api.example.com

View Full Debug Logs

nemoclaw my-assistant logs --follow
# or with verbose flag
nemoclaw my-assistant logs --follow --level debug

Documentation Links