NemoClaw / OpenShell: setup and governed scope
Limited coverage · Deployment profile · Reviewed 2026-09-07
A version-matched native tool gate and managed MCP recipe are implemented; full NVIDIA sandbox acceptance is pending.
Set up NemoClaw / OpenShell in your workspace Choose your first outcome
What is validated
Native MCP registration planner
Validation pending
Protected surfaces:
- planned MCP server registration
Authentication: operator-provided MCP bearer environment. Evidence capability: none; inspect each action's actual grade.
Setup instructions for this profile come from the SDK documentation your deployment operator provides.
Pinned OpenClaw tool gate with native OpenShell managed MCP
Limited coverage
Protected surfaces:
- native before_tool_call blocking for unrelated tools
- fixed managed MCP action via mcporter
- static native allowlist in matched image profile
Authentication: native OpenShell MCP credential replacement, operator-owned user-backed companion API credential, live runtime installation. Evidence capability: none; inspect each action's actual grade.
Setup instructions for this profile come from the SDK documentation your deployment operator provides.
Start free, then install and connect
After the sample, use the local SDK installation guide. Obtain a matching source checkout or release artifact from your deployment operator; these pages do not assert that a package or marketplace entry has been published.
- Create a free workspace and verify your email. In your dashboard, choose Run free sample. Review the local rule’s allowed and blocked texts, saved audit ID, and reported signature availability. No model key or external target is needed. This sample does not connect an agent or create a target receipt or verified proof bundle.
- Return to your saved runtime setup and register an agent. Use separate runtime and personal review credentials; keep credentials outside source control.
- Choose an explicitly supported managed tool path. An administrator must configure a registered HTTP target or managed MCP connection and confirm your access.
- In a disposable workflow, exercise allow, deny, and revoked-authority cases. Record the actual action ID; a configured connection alone is not execution evidence.
- Inspect the event sequence, outcome, and evidence grade in the workspace. Use the evidence guide for SDK reads and independent verification.
Start free with the local rule sample, registration, and the controls available to your plan. Protected actions require proof.actions and the corresponding permission; exports require additional access. Ask your workspace administrator if these are unavailable. Provider usage may have its own charges.
Limits to test
- NemoClaw is a deployment profile for separately integrated runtimes. Upstream alpha and platform restrictions apply.
- The planner uses native MCP registration commands; a configured token is not proof of successful authentication, transport, sandbox containment or protected execution.
- No NemoClaw/OpenShell sandbox was run in this acceptance environment.