OpenShell Policy Advisor

SkillDev tools

Lets your agent propose and get approval for network policy changes when a sandbox blocks a request.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the OpenShell Policy Advisor skill

About this capability

Use when an OpenShell sandbox returns policy_denied, mentions policy.local, or needs a narrow network policy proposal.

What this skill tells your AI

The instructions your AI receives, as published by nvidia/openshell in crates/openshell-supervisor-process/src/skills/policy-advisor/SKILL.md and read by ahel’s review.

When a request fails with policy_denied, do not treat the denial as final if the user task still needs the request. Read /etc/openshell/skills/policy_advisor.md, inspect http://policy.local/v1/policy/current, submit the narrowest proposal to http://policy.local/v1/proposals, wait on /v1/proposals/{chunk_id}/wait?timeout=300, and retry only after approval with policy_reloaded: true.

Signals

GitHub stars
9k
Forks
1k
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
openshell-policy-advisor
Source
github.com/nvidia/openshell