…
Course home

Securing Agents with OpenShell and NemoClaw

Abstract

Modern agents are everywhere, and they’re conceptually simple: a model wired to tools, memory, and a routing decision that keeps running until the task is done. This course starts by building such a system from scratch, then connects those ideas to modern frameworks used by software engineers and non‑technical users alike. You’ll go from a single API call to agent coordination, grounded retrieval, deep planning, and safe deployment using NVIDIA OpenClaw and NVIDIA NemoClaw™.

1Confirm the model routes below. Chat and embeddings use models from build.nvidia.com by default. You can change each route's model and endpoint to suit your performance needs.
2Follow the modules in order for the default path, or jump to the task you need. Every page ends in a live browser artifact, with its JavaScript available for inspection and adaptation.
3Create a NemoClaw launchable to host the course's OpenClaw-in-OpenShell stack from the NemoClaw blueprint. This can be reproduced locally without GPU access using model endpoints.

Learning Objectives

Upon completion of this course, students will be able to:

  • Build a basic agent loop and identify its core components.
  • Implement reliable tool use and function calling within an agent system.
  • Design and coordinate multi-agent systems using structured routing patterns.
  • Utilize OpenShell to configure agent identities and ensure safe, sandboxed operations.
  • Deploy and manage autonomous agents while building persistent skill libraries.
A NemoClaw mascot holding the OpenShell shield beside a local AI workstation.
NemoClaw for OpenClaw in a local workstation setting.
Source: NVIDIA Build blueprint card.

Entering Your API Key

Your browser saves the chat and embedding routes across lessons and sends each key only to its selected endpoint. Use a custom route only when you have a reachable HTTPS endpoint.

How to use these lessons

Run the examples, inspect their output, then change an input and compare. JavaScript is available under each cell's code control; you can read and run the examples before editing it.

Click a section heading or its arrow to expand or collapse that section. Color reinforces the written label: blue marks information, amber marks a caution, and red marks an error. Read the text rather than relying on color alone.

Use Sections to find a section. Heading links can be bookmarked or shared. The Assistant can use the current section when you ask a question. Its model and session controls are optional; start by asking about the example you are reading.

If a model request fails

Stop cancels the current request. An aborted-request message by itself does not establish whether the cause was cancellation, navigation, or an interrupted connection. Keep the visible error and any partial output. A timeout means no response headers or stream data arrived within the configured wait.

For a read-only model example, check model access above, wait briefly, and rerun once. A repeated failure needs diagnosis: note the lesson and section link, cell label, selected model, error text, and time. Never include an API key. Before repeating a tool or command that changes files, schedules work, or creates a session, inspect whether the first attempt already performed that action.

HTTP 401 or 403 calls for checking credentials or access. HTTP 429 means the service is limiting requests; wait before trying again. A 5xx response can indicate a provider or relay failure. Request handling in setup controls waiting and optional retries before streaming begins. Longer waits or more retries will not fix invalid credentials. Report persistent failures through the support link at the bottom of this page.

Exploring the Material

The following modules can be taken as desired or in order. Feel free to skip around, but note that some modules build on earlier ones. Each module has a live artifact at the end, and the supporting code is available for inspection and adaptation. You can modify the examples in the browser, self-host them, or give this repository to a coding agent as context for a local deployment or application.

What this course runs on

The course uses these three systems from the browser. Each card shows what the system contributes and opens the relevant service or catalog.

The course interface runs on GitHub Pages. Model calls use your configured endpoint. Modules 3 and 4 connect to the NemoClaw Brev launchable, with a compatible local deployment as an alternative.