Skip to content

docs(agent): ship static sandbox policy advisor skill #1095

Description

@zredlined

Description

Ship a static /etc/openshell/skills/policy_advisor.md in the sandbox image that teaches agents the deny/log -> inspect -> draft -> prove -> submit -> watch loop using policy.local.

Context

Parent: #1062
RFC artifact: https://github.com/NVIDIA/OpenShell/blob/feat/agent-driven-policy-management/rfc/0001-agent-driven-policy-management.md

This is part of the locked Agent-Driven Policy Management MVP. GitHub issues are the development source of truth; Linear is only a roadmap pointer.

The MVP uses a static named skill file instead of runtime generation. Use a named file so future images can add more OpenShell skills beside it.

Definition of Done

  • Sandbox image includes /etc/openshell/skills/policy_advisor.md.
  • Skill documents the policy.local endpoints and example JSON payloads.
  • Skill documents how to inspect recent denials and sandbox-local activity logs.
  • Skill documents the L7-first norm and when L4 fallback is acceptable.
  • Skill tells agents to use PolicyMergeOperation-shaped JSON payloads rather than CLI flag strings.
  • Skill documents rejection guidance and revision behavior.
  • No hidden policy ceilings, approval thresholds, or secrets are exposed.
  • MCP is described as out of scope for MVP, not as a required setup step.

Activity

  1. added
    area:docsDocumentation and examples
    area:policyPolicy engine and policy lifecycle work
    area:sandboxSandbox runtime and isolation work
    on Apr 30, 2026
  2. changed the title [-]docs(agent): ship static sandbox policy skill[/-] [+]docs(agent): ship static sandbox policy advisor skill[/+] on Apr 30, 2026
  3. added 3 commits that reference this issue on May 12, 2026
    d5fe465
    605cf01
    009e17d
  4. added a commit that references this issue on May 14, 2026
    ea2fddb
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:docsDocumentation and examplesarea:policyPolicy engine and policy lifecycle workarea:sandboxSandbox runtime and isolation workstate:agent-readyApproved for agent implementation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions