github andrewyng/openworker v0.3.0
OpenWorker 0.3.0

2 hours ago

OpenWorker 0.3.0

Agent Security OpenWorker now provides multiple layers of protection for AI agents. The approval system and the permission ladder decide what an agent may do, and a secure runtime now sets a hard limit on what it can do. OpenWorker integrates the OpenShell secure runtime from the NVIDIA Open Agent Safety Platform, announced this week. It is an enforceable boundary outside the model and the agent harness. Every agent runs in its own Linux container, with Landlock and seccomp on every process. This enables Users to restrict AI agents to only allowed files and allowed websites. Even if an agent is misled by a prompt injection or drifts from its task, it cannot read your other files, take your keys, or reach anywhere else. Docker (or Docker Desktop) needs to be installed on Mac, Windows or Linux to allow OpenWorker to setup and use OpenShell. In absence of Docker, sandboxing is still provided using OS specific primitives. Detailed architecture to come soon as a blog and docs. Thanks to @devikaverma for this researching and enabling above techniques inside OpenWorker to provide a more secure way to run AI agents.
Set it up in Settings ▸ Sandbox.

Machines. Run OpenWorker on a different machine and use it from the desktop app. Sessions live on that remote machine and keep running when your laptop is closed. Join a machine from Settings ▸ Machines.
This enables several use cases like 24x7 code reviewer agent, or an agent that answers question from Slack.

openworker command line. On Linux, install it with one command:

curl -fsSL https://raw.githubusercontent.com/andrewyng/openworker/main/packaging/install.sh | sh

Or download it below: openworker-linux-x86_64.tar.gz or openworker-linux-aarch64.tar.gz.
The command line can be used to make a remote openworker join the Desktop app, allowing the user to control it remotely.

Also: the app is in English and Simplified Chinese; many fixes to the agent loop, approvals, scheduled tasks and MCP tools.
More languages are in the roadmap.

Downloads: Mac (Apple Silicon: OpenWorker-macos-arm64.dmg; Intel: OpenWorker-macos-x64.dmg), Windows (OpenWorker-windows-setup.exe), Linux (above).

What's Changed

  • Updating README by @rohitprasad15 in #569
  • security(teams): enforce worker visibility on board item reads by @rakeshutekar in #585
  • fix(teams): enforce attachment read authorization by @rakeshutekar in #586
  • Add GUI internationalization with English and Simplified Chinese by @jasmine889966 in #127
  • fix: scheduled task can run twice when an approval lands on a tick by @Saidheerajgollu in #379
  • Parse inbox reply intent from the leading word, not substrings by @Saidheerajgollu in #24
  • Reject path-traversal session ids in the conversation store by @Saidheerajgollu in #55
  • Recover truncated tool calls, and never pass a leaked one off as an answer by @hacksics in #219
  • Tolerate a corrupt line when loading a conversation .jsonl by @Saidheerajgollu in #56
  • Make the conversation-log shrink rewrite atomic (prevent history loss on a mid-write crash) by @lifrary in #70
  • fix: repair tool-call/result pairing on load to prevent unrecoverable 400 errors by @rkfshakti in #350
  • fix(skills): confine staged upload tokens by @mo-tunn in #548
  • MCP permission model: EXTERNAL floor, durable per-tool trust, fixed approval cards (OPE-136) by @devikaverma in #598
  • fix(engine): agent loop fixes for long, tool-heavy sessions (OPE-156) by @devikaverma in #669
  • setup_dev_env.sh: install the bedrock extra so a fresh env passes the test suite by @xiaonancui in #285
  • fix: handle Windows drive-letter paths in grep (ripgrep) output by @engmohamedsalah in #123
  • fix: preserve exception chain in RelayHub.wait_dispatched by @Anuj04432 in #172
  • fix: add httpx2 dev dependency to silence Starlette TestClient deprec… by @Aadhithya-arulvanan in #183
  • security: reject shell variable expansion in read-only grants by @harneet2512 in #566
  • fix: make Bedrock verification and tests tolerate missing optional boto3 by @tyoon10 in #554
  • fix(tests): import ExceptionGroup from backport for Python 3.10 compatibility by @tyoon10 in #555
  • Escape LIKE wildcards when re-keying board cursors by @tyoon10 in #556
  • fix: add coverage measurement and reporting to CI by @rkfshakti in #328
  • Remote machines, agent-team cards, and connectors across machines by @rohitprasad15 in #672
  • CLI: openworker join, up and machine commands; package publishes as openworker by @rohitprasad15 in #673
  • Add Team View and harden agent-team coordination by @rohitprasad15 in #679
  • Add support for Sandboxing using NVIDIA OpenShell by @devikaverma in #684
  • Add docs for OpenShell support by @rohitprasad15 in #685
  • feat(sandbox): guided OpenShell setup, readiness checks, switching for open sessions (OPE-205, OPE-206, OPE-207, OPE-208, OPE-209) by @devikaverma in #699
  • Sandboxing improvements for Windows and Mac by @rohitprasad15 in #700
  • Simplify the Sandbox settings page. by @rohitprasad15 in #701
  • Fix KeyError 'none' crash in openai_compat_effort for unlisted model ids by @aashish254 in #677
  • OpenShell clean-up removes only the sandboxes its own state folder made by @rohitprasad15 in #704
  • Linux: build openworker as one program, no Python needed by @rohitprasad15 in #705
  • fix(mentions): a corrupt mention_threads.json must not brick server startup by @Lesereingrape in #690
  • fix(providers): handle effort "none" on every provider, Anthropic omits it, OpenAI-compat sends it (#702) by @devikaverma in #703
  • fix(security): refuse find's fprint family under a bare allowlist entry by @rkfshakti in #688
  • Release 0.3.0: Linux download and install script by @rohitprasad15 in #706

New Contributors

Full Changelog: v0.2.1...v0.3.0

Don't miss a new openworker release

NewReleases is sending notifications on new releases.