Securing Agents with OpenShell and NemoClaw
Abstract
Modern agents are everywhere, and they’re conceptually simple: a model wired to tools, memory, and a routing decision that keeps running until the task is done. This course starts by building such a system from scratch, then connects those ideas to modern frameworks used by software engineers and non‑technical users alike. You’ll go from a single API call to agent coordination, grounded retrieval, deep planning, and safe deployment using NVIDIA OpenClaw and NVIDIA NemoClaw™.
build.nvidia.com by default. You can change each route's model and endpoint to suit your performance needs.Learning Objectives
Upon completion of this course, students will be able to:
- Build a basic agent loop and identify its core components.
- Implement reliable tool use and function calling within an agent system.
- Design and coordinate multi-agent systems using structured routing patterns.
- Utilize OpenShell to configure agent identities and ensure safe, sandboxed operations.
- Deploy and manage autonomous agents while building persistent skill libraries.
Source: NVIDIA Build blueprint card.
Entering Your API Key
Your browser saves the chat and embedding routes across lessons and sends each key only to its selected endpoint. Use a custom route only when you have a reachable HTTPS endpoint.
How to use these lessons
Run the examples, inspect their output, then change an input and compare. JavaScript is available under each cell's code control; you can read and run the examples before editing it.
Click a section heading or its arrow to expand or collapse that section. Color reinforces the written label: blue marks information, amber marks a caution, and red marks an error. Read the text rather than relying on color alone.
Use Sections to find a section. Heading links can be bookmarked or shared. The Assistant can use the current section when you ask a question. Its model and session controls are optional; start by asking about the example you are reading.
If a model request fails
Stop cancels the current request. An aborted-request message by itself does not establish whether the cause was cancellation, navigation, or an interrupted connection. Keep the visible error and any partial output. A timeout means no response headers or stream data arrived within the configured wait.
For a read-only model example, check model access above, wait briefly, and rerun once. A repeated failure needs diagnosis: note the lesson and section link, cell label, selected model, error text, and time. Never include an API key. Before repeating a tool or command that changes files, schedules work, or creates a session, inspect whether the first attempt already performed that action.
HTTP 401 or 403 calls for checking credentials or access. HTTP 429 means the service is limiting requests; wait before trying again. A 5xx response can indicate a provider or relay failure. Request handling in setup controls waiting and optional retries before streaming begins. Longer waits or more retries will not fix invalid credentials. Report persistent failures through the support link at the bottom of this page.
Exploring the Material
The following modules can be taken as desired or in order. Feel free to skip around, but note that some modules build on earlier ones. Each module has a live artifact at the end, and the supporting code is available for inspection and adaptation. You can modify the examples in the browser, self-host them, or give this repository to a coding agent as context for a local deployment or application.
What this course runs on
The course uses these three systems from the browser. Each card shows what the system contributes and opens the relevant service or catalog.
nvapi- key and the selected model route.webSearch ranks the course glossary, papers, and posts.
instantAnswer returns one matching glossary definition. Open the catalog to
inspect the sources and search request.