openclaw/extensions/openshell
Peter Steinberger dab1f08376
feat: give every plugin a compact chat activity icon (#147333)
* feat: give every plugin a compact chat activity icon

Separate package-owned activity SVGs from plugin identity artwork. Ship 154 defaults and seven exact tool overrides, preserving Echo and the progress claw. Include authenticated bounded delivery, safe mask rendering, packaging, and authoring guidance.

* test: declare Vite types for the activity asset browser test

* refactor: keep plugin artwork selection with catalog presentation facts

* test: scope activity browser types and simplify fixture copies
2026-09-13 13:49:51 -07:00
..
assets feat: give every plugin a compact chat activity icon (#147333) 2026-09-13 13:49:51 -07:00
src fix(openshell): match shared invalid-environment diagnostic (#147348) 2026-09-14 04:15:04 +08:00
.npmignore
index.test.ts refactor: keep plugin work and cleanup owned during retirement (#144252) 2026-09-11 13:42:35 -07:00
index.ts
openclaw.plugin.json feat(plugins): assign one purpose category to every bundled plugin (#142760) 2026-09-10 20:44:20 -07:00
package.json improve: reduce worktree filesystem stalls and archive syncs (#146906) 2026-09-13 04:07:17 -07:00
README.md
tsconfig.json

@openclaw/openshell-sandbox

Official NVIDIA OpenShell sandbox backend for OpenClaw.

This plugin lets OpenClaw use OpenShell-managed local or remote sandboxes with SSH command execution. Choose mirror mode for a synchronized local workspace or remote mode for a remote-canonical workspace.

Mirror operations sharing a workspace run sequentially so concurrent agent turns cannot overwrite one another. Outbound attachments resolve against the configured remote workspace, which defaults to /sandbox.

Configuring an OpenShell workspace requires OpenShell v0.0.88 or newer. The plugin supports OpenShell control-plane workspaces through plugins.entries.openshell.config.workspace; this is separate from OpenClaw's local/remote filesystem workspace mode. The setting applies to the whole plugin instance, not individual agents or sessions. When unset, the plugin preserves the OpenShell CLI's ambient OPENSHELL_WORKSPACE selection, or its default fallback when no ambient selection exists.

Install

openclaw plugins install @openclaw/openshell-sandbox

Restart the Gateway after installing or updating the plugin.

Configure

Install and configure the OpenShell CLI before enabling the backend. As the same operating system user that runs the OpenClaw Gateway, verify:

openshell --version
openshell gateway list
openshell sandbox list

Set agents.defaults.sandbox.backend to "openshell", enable plugins.entries.openshell, and restart the OpenClaw Gateway. OpenShell settings belong under plugins.entries.openshell.config.

The optional policy setting must be the path to a readable OpenShell policy YAML file on the Gateway host; it is not a policy name or ID. Use an absolute path to avoid resolving it relative to an agent workspace.

Use the OpenShell docs for credentials, workspace mirroring, runtime selection, and troubleshooting:

Package

  • Plugin id: openshell
  • Package: @openclaw/openshell-sandbox
  • Minimum OpenClaw host: 2026.5.12-beta.1