Use Case

NemoClaw Secures the Runtime. VettIQ Secures the Supply Chain.

NemoClaw sandboxes your AI agent with OpenShell. VettIQ scans every MCP server and skill before it enters the sandbox. Together: defense in depth.

What NemoClaw Does

NVIDIA's NemoClaw (launched at GTC March 2026) provides enterprise-grade runtime security for AI agents.

Sandboxed Execution

OpenShell containers isolate agent actions from the host system. File access, network calls, and process execution are all containerized.

Policy Enforcement

Define what your agent can and cannot do with declarative policy profiles. Restrict network access, limit API calls, require human approval for sensitive actions.

Privacy Router

Route sensitive data to local Nemotron models instead of cloud APIs. PII stays on-premise, non-sensitive queries go to faster cloud models.

What NemoClaw Doesn't Do

Runtime sandboxing protects the host. But it doesn't protect you from what's inside the sandbox.

🔍

Vet MCP Server Code

NemoClaw trusts whatever you install into the sandbox. It doesn't scan MCP server source code for prompt injection, credential theft, or malicious patterns.

📦

Check Dependency Security

MCP servers pull in npm/pip dependencies. NemoClaw doesn't scan those dependency trees for known vulnerabilities or supply chain attacks.

⚖️

Score Skill Trustworthiness

Is this MCP server maintained? Does it have known issues? NemoClaw doesn't evaluate reputation, activity, or security posture of third-party skills.

How VettIQ Fills the Gap

VettIQ scans every MCP server through 4 security engines before you install it.

Snyk

Prompt injection & code vulnerabilities

Cisco Kenna

Dependency risk scoring across the full tree

Semgrep

Dangerous code patterns (eval, exec, credential access)

VirusTotal

Malware signature matching against 70+ engines

Results Published to the MCP Trust Directory

0 – 30Approved
31 – 65Guardrails
66+Rejected

1,000+ MCP servers scanned. Free to browse at vettiq.ai/mcp

Getting Started

No install required. Just check the trust score before you install any MCP server.

1.

Go to vettiq.ai/mcp and search for the MCP server you want to install.

2.

Check the trust score and scanner results. Green (0-30) means safe to install.

3.

Install into your NemoClaw OpenShell environment with confidence.

4.

For automated security rules, download a free Security Blueprint.

Coming soon: NemoClaw + OpenShell Security Blueprint — automated rules for secure agent configuration.