#47 · Primary category: Cybersecurity & Decryption Tools

nono

agent-sandbox agent-security ai-agent-sandbox ai-agent-security ai-agents ai-security ai-security-tool code-execution llm-security mcp mcp-security security sigstore supply-chain-security zero-trust

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

Project last updated:08/29/26

GitHub Stars

3.9K

Forks

253

Contributors

96

License

Apache-2.0

Why we included this project

Letting a coding agent run commands on your machine means giving it access to your files, and nono is a lightweight way to keep that from becoming a problem. It doesn't wrap the agent in a container or VM; instead it uses the OS's own isolation, Landlock on Linux and Seatbelt on macOS, to give the agent a least-privilege sandbox with almost no overhead, no daemon, and no disk usage. It adds a capability-based policy layer, diagnostics, secure key management, and atomic rollback, so a misbehaving model can't quietly rewrite files and leave you with no way to undo it. If you run agents like Claude Code, Codex, or OpenCode in personal or CI workflows and you care about execution and supply-chain security, it's worth evaluating against your own threat model.

Articles for this project

No articles for this project yet.

To suggest a topic or contribute an article, contact us.

Related projects in this category