Modern CLI Agents
The agents compared below wrap the same handful of capabilities:
- a working directory
- a tool palette
- a memory
- optional ways to run without a person actively typing, such as cron, long tasks, or queued jobs
- a network
Their security profiles depend on which capabilities are open by default and whether unattended execution is enabled. The runtime underneath must also catch a bad call.
Module 4a separated application decisions from operating-system enforcement. Application wrappers sit above that boundary. You will compare them before building a browser-based CLI agent of your own.
Shared loop, different application defaults
Each product runs a model in a loop with tools. Defaults and built-in capabilities differ. Implementation detail varies too. Their combined cost and convenience form the harness weight used below.
- Claude Code uses
CLAUDE.mdinstructions. Tool rules, permission mode, and sandbox settings determine which actions run or require approval. - Codex CLI uses
AGENTS.mdinstructions. Sandbox settings limit access; approval policy controls review. Workspace edits and commands can run automatically within those limits. - Cursor uses
.cursor/rules/*.mdc. Workspace edits generally run without approval; terminal commands require approval by default. Modes and settings can change those checks. - Hermes provides skills, persistent memory, scheduled jobs, and configured messaging integrations. Its approval mode and terminal backend determine command handling and isolation.
- OpenClaw uses workspace files such as SOUL.md and AGENTS.md, gateway sessions, and scheduled triggers. In this course it runs inside OpenShell. Inspect the active policy and gateway permissions to assess its reach.
The degrees of freedom are the attack surface
These axes describe capabilities an operator can grant or withhold. The reference configuration below gives you questions to compare with the policy and command evidence you collected in Module 4a.
| Degree of freedom | The knob | NemoClaw reference configuration |
|---|---|---|
| Filesystem | which paths are readable / writable | write only /tmp, /sandbox/.openclaw, /sandbox/.nemoclaw, and the workdir; system paths read-only. Enforced by Landlock (best_effort). |
| Network egress | host + port + HTTP method/path, per binary | deny by default; a short allowlist (NVIDIA inference, inference.local, clawhub/npm), each scoped to one HTTP shape and bound to a specific binary. |
| Process identity | which user the agent runs as | non-root sandbox user; ptrace, mount, setuid blocked by seccomp. |
| Binary identity | which executable may use a grant | resolved by exe path plus an ancestor walk with a trust-on-first-use hash; argv[0] is distrusted because it is spoofable. |
| Persistence | cron, skills, and the SOUL.md persona | Workspace permissions and host-managed file protection determine whether persona files can change. Verify the running configuration. |
| Inference routing | which model endpoint calls leave through | routed through the managed inference.local gateway; the Privacy Router decides what context may leave on the operator's policy, not the agent's. |
Try it · the same task, weighed across harnesses
The artifact compares harness weight along these axes:
- Abstractions the harness hides, so you write less code and also see less of what runs.
- Assumptions and defaults it bakes in, which decide how far it reaches before you ask.
- First-class features it ships built in, against the same capability left for you to hand-roll.
Describe a task and compare how much machinery each harness supplies. The editable cell exposes its system prompt and response logic. It also shows the examples. Rerun the cell after an edit to rebuild the artifact.
Build an agent around the browser runtime?
Build a CLI agent whose shell is this browser
The browser agent has one js tool that runs JavaScript in this page. It can read the DOM, call fetch, and use course helpers within browser permissions. Stop cancels model requests and prevents later tool calls; it cannot interrupt synchronous JavaScript already executing or undo a completed action.
Module 4c returns to this browser form factor. Its interactive web surface has visible state and controls that can be reused with another host. Authentication, storage, network access, and tool adapters depend on that host.
Open the launchable shell and sandbox shortcut?
Open a real shell on your launchable
Your NemoClaw launchable gives you a real host shell over the same /ws/terminal
connection Module 4a's policy probes use. That host carries the openshell CLI, the
operator tool that manages your sandboxed agent. Every line you type below runs on the launchable, and
the output is its own.
Connect your launchable on Module 3a first. Type a command, click a
chip, or press Tab to autocomplete. On the host, openshell sandbox list shows your agent
and openshell status reports the gateway. Your agent runs inside a sandbox, so prefix a
command with agent to run it there: agent ls lists its files through
openshell sandbox exec. Each command runs in its own short-lived shell, so to chat with the
agent interactively, use the panel below rather than the openclaw tui.
Chat with your agent
The openclaw tui is an interactive, full-screen chat that a one-shot terminal cannot hold
open. The panel below talks to the same live agent over the OpenClaw gateway, the
/cli/gateway connection Modules 3b and
3c use, so you can chat with it without leaving the page. It streams the agent's
reply and shows each tool or command the agent runs. Connect your launchable on
Module 3a first (its URL and token). Ask it anything, click a prompt,
or press Tab to autocomplete.
The terminal above is the operator plane. The host shell manages the sandboxed agent. Commands sent with agent <cmd> run inside that agent environment; host commands use operator permissions. Inspect both boundaries as in Module 4a.
- Setup. This runtime is already provisioned. A separate CLI needs its own installation and configuration.
- Reach. File, network, and process permissions depend on the environment. Inspect the actual grants.
- Blast radius. Prompt injection may cause harm through allowed capabilities. Compare available actions, enforcement, and audit evidence.