Deep Agents Code on NemoClaw: A Governed Blueprint for Your Most Sensitive Code
Patch your teams to install NemoClaw CLI, onboard dcode with Nemotron 3 Ultra, and run your codebase in the OpenShell sandbox.
Patch your teams to install NemoClaw CLI, onboard dcode with Nemotron 3 Ultra, and run your codebase in the OpenShell sandbox.
Summary
NemoClaw is a one‑command blueprint that bundles LangChain’s Deep Agents Code harness, NVIDIA’s Nemotron 3 Ultra open model, and NVIDIA’s OpenShell sandbox. The OpenShell runtime denies networking by default, requires human approval for sensitive operations, and provides a full audit trail, keeping credentials outside the sandbox so the agent never touches them. Onboarding builds a sandbox, installs dcode, and wires it to Nemotron 3 Ultra through NemoClaw’s managed inference. The sandbox can be customized with a Dockerfile to match the application stack, and each run can be snapshotted into NemoClaw’s per‑session audit logs. The blueprint is designed for modernizing legacy codebases, .NET and Windows migration, dependency mapping, security patch workflows, and more, all while keeping source, model, and audit trail under the team’s control. By running dcode inside the sandbox, teams can read code, propose migration plans, refactor incrementally, and review diffs with human approval for every sensitive action. The result is a governed, auditable, and cost‑controlled coding agent that can handle the most sensitive code without exposing it to external APIs.
NemoClaw is available today and can be installed via a simple curl script, with onboarding commands that support both default and custom Dockerfile setups. It provides a complete, open, and secure stack for enterprises that need to run coding agents on production code while meeting regulatory and security requirements.
Key changes
- One‑command onboarding builds OpenShell sandbox, installs dcode, and wires to Nemotron 3 Ultra
- OpenShell denies networking by default and requires human approval for sensitive ops
- Credentials stay outside sandbox; agent never touches them
- Per‑session audit logs provide full audit trail
- Custom Dockerfile onboarding matches application stack
- Sandbox supports legacy modernization, .NET migration, dependency mapping, security patches
- Blueprint gives enterprises control over source, model, and audit trail