… …
Module 4 · Part B of 3

Modern CLI Agents

The agents compared below wrap the same handful of capabilities:

Their security profiles depend on which capabilities are open by default and whether unattended execution is enabled. The runtime underneath must also catch a bad call.

Module 4a separated application decisions from operating-system enforcement. Application wrappers sit above that boundary. You will compare them before building a browser-based CLI agent of your own.

Shared loop, different application defaults

Each product runs a model in a loop with tools. Defaults and built-in capabilities differ. Implementation detail varies too. Their combined cost and convenience form the harness weight used below.

OpenShell can host this class of agent application; NemoClaw is the reference stack this course runs. The same OpenShell integration is documented by NVIDIA for Codex, Cursor, and OpenCode. The CLI you pick decides the starting defaults, while the OpenShell wrapper around it governs how far any of those defaults are permitted to reach.

The degrees of freedom are the attack surface

These axes describe capabilities an operator can grant or withhold. The reference configuration below gives you questions to compare with the policy and command evidence you collected in Module 4a.

Degree of freedomThe knobNemoClaw reference configuration
Filesystemwhich paths are readable / writable write only /tmp, /sandbox/.openclaw, /sandbox/.nemoclaw, and the workdir; system paths read-only. Enforced by Landlock (best_effort).
Network egresshost + port + HTTP method/path, per binary deny by default; a short allowlist (NVIDIA inference, inference.local, clawhub/npm), each scoped to one HTTP shape and bound to a specific binary.
Process identitywhich user the agent runs as non-root sandbox user; ptrace, mount, setuid blocked by seccomp.
Binary identitywhich executable may use a grant resolved by exe path plus an ancestor walk with a trust-on-first-use hash; argv[0] is distrusted because it is spoofable.
Persistencecron, skills, and the SOUL.md persona Workspace permissions and host-managed file protection determine whether persona files can change. Verify the running configuration.
Inference routingwhich model endpoint calls leave through routed through the managed inference.local gateway; the Privacy Router decides what context may leave on the operator's policy, not the agent's.

Try it · the same task, weighed across harnesses

The artifact compares harness weight along these axes:

Describe a task and compare how much machinery each harness supplies. The editable cell exposes its system prompt and response logic. It also shows the examples. Rerun the cell after an edit to rebuild the artifact.

Build an agent around the browser runtime?

Build a CLI agent whose shell is this browser

The browser agent has one js tool that runs JavaScript in this page. It can read the DOM, call fetch, and use course helpers within browser permissions. Stop cancels model requests and prevents later tool calls; it cannot interrupt synchronous JavaScript already executing or undo a completed action.

Module 4c returns to this browser form factor. Its interactive web surface has visible state and controls that can be reused with another host. Authentication, storage, network access, and tool adapters depend on that host.

Open the launchable shell and sandbox shortcut?

Open a real shell on your launchable

Your NemoClaw launchable gives you a real host shell over the same /ws/terminal connection Module 4a's policy probes use. That host carries the openshell CLI, the operator tool that manages your sandboxed agent. Every line you type below runs on the launchable, and the output is its own.

Connect your launchable on Module 3a first. Type a command, click a chip, or press Tab to autocomplete. On the host, openshell sandbox list shows your agent and openshell status reports the gateway. Your agent runs inside a sandbox, so prefix a command with agent to run it there: agent ls lists its files through openshell sandbox exec. Each command runs in its own short-lived shell, so to chat with the agent interactively, use the panel below rather than the openclaw tui.

Chat with your agent

The openclaw tui is an interactive, full-screen chat that a one-shot terminal cannot hold open. The panel below talks to the same live agent over the OpenClaw gateway, the /cli/gateway connection Modules 3b and 3c use, so you can chat with it without leaving the page. It streams the agent's reply and shows each tool or command the agent runs. Connect your launchable on Module 3a first (its URL and token). Ask it anything, click a prompt, or press Tab to autocomplete.

The terminal above is the operator plane. The host shell manages the sandboxed agent. Commands sent with agent <cmd> run inside that agent environment; host commands use operator permissions. Inspect both boundaries as in Module 4a.

← Module 4a: OpenShell