Why it matters
NVIDIA launched the Open Secure AI Alliance and contributed NOOA, an Apache-2.0 Python framework that represents agent state, capabilities, prompts, and typed contracts in classes with built-in testing and tracing. NVIDIA reports 86.8% on CyberGym L1 with GPT-5.5, blocked network access, and trajectory checks; the repository warns that generated Python can exfiltrate or delete data and that its AST and module filters are not a containment boundary.
My takeaway: Treat NOOA as an inspectable agent harness, not a sandbox or proven industry standard. Run generated code behind OS-level isolation with blocked egress, scoped credentials, resource limits, and replayable traces; reproduce benchmark results on representative workloads, and wait for concrete alliance governance, interoperable controls, and independent adoption before relying on coalition claims.