nono
View on GitHubsecure multiplexed execution paths for agents - zero trust, zero setup, zero latency.
nono is a zero-setup, zero-latency Rust sandbox for running AI coding agents and their delegated tools under least-privilege policy. It isolates filesystem, network and credentials per agent and per tool (including MCP servers), with no VM, daemon or container.
Use Cases
Run Claude Code, Codex or OpenCode inside a least-privilege sandboxGive an agent read/write access to one project directory and hide SSH keys and cloud credentialsProxy GitHub tokens so gh only sees scoped API methods and pathsSandbox delegated tools like git, kubectl, curl and build scripts in child sandboxesIsolate MCP clients and servers from the agent's broader grantsEnforce per-command invocation policies defined in a composable JSON profileNetwork allowlisting and L7 endpoint filtering for agent trafficPublish and share agent sandbox profiles via a registryRun untrusted AI-generated code without a VM, daemon or containerEmbed the sandbox in Rust, Python, TypeScript or Go applications via FFI bindings
Built With
- Language
- Rust
- Frameworks
- MCP · Sigstore · Landlock · Tokio · Nix · Docker · Homebrew · WSL2 · Claude Code · OpenAI Codex · OpenCode
Tags
agent-sandbox · zero-trust · agent-security · mcp-security · credential-proxy · code-execution · least-privilege · l7-filtering · policy-engine · llm-security · sandbox · supply-chain-security · sigstore · rust · ffi-bindings · audit