What happened
NVIDIA shipped NemoClaw v0.0.114 (Aug 23, 2026) adding deterministic read-only MCP tool calls with mutation rejection, credential-shaped-output redaction, destructive-operation warnings, sealed-configuration recovery with integrity verification, and fail-closed installer/image-provenance checks.
Why it matters
Converts several agentic-AI risk mitigations (excessive tool authority, secret leakage via tool output, unverified supply chain) into enforceable platform controls rather than system-prompt guidance, following the same product's v0.0.109 release a week earlier.
Applicability
Teams building agent runtimes on NVIDIA NemoClaw/agentic sandboxes should adopt the read/write tool separation and image-provenance checks as a baseline control pattern.