nono is a free, open source ai security & privacy project written in Rust and released under Apache-2.0. It has 4,121 GitHub stars, 272 forks and 201 open issues, and was last pushed 9 hours ago. On this registry it ranks #10 of 34 tracked projects in AI Security & Privacy, with 5 head-to-head comparisons available. It gained 22 stars over the last 3 tracked days.

What is nono?

What it is

nono is a Rust project for secure multiplexed execution paths for AI agents. It lives in AI security and privacy. It is built by the team that brought Sigstore. It aims to run agents with zero trust, zero setup, and zero latency.

The problem is that AI agents can reach too much of a machine. nono addresses this with a least-privilege sandbox for agents such as Claude Code, Codex, Pi, CoPilot, Hermes, OpenCode, and OpenClaw. It runs with no daemon, no container, no VM, and no disk space usage. It supports macOS, Linux, and Windows WSL2.

Key capabilities

  • Runs AI agents inside a least-privilege sandbox and can restrict access to the current directory while leaving SSH keys, cloud credentials, and the rest of the disk invisible.
  • Provides a registry of agent profiles that bundle filesystem scope, network allowlist, hooks, and skills.
  • Supports profile composition through nono profile init and --extends, so a user can start from a published profile and edit a JSON profile.
  • Lets users search and run profiles with nono search and nono run --profile, as shown for nolabs-ai/opencode.
  • Supports macOS, Linux, and Windows WSL2, with installation paths for curl, Homebrew, Nix, Debian/Ubuntu, Fedora, Arch, RHEL, openSUSE, and WSL2.
  • Uses a registry namespace nolabs-ai after migration from always-further, and users must remove old packs before pulling new ones.

Who uses it and how

  • Developers can search the nono registry, pull a profile for an agent, and run that agent under the profile, as shown with nolabs-ai/opencode.
  • Teams can fork or extend default profiles, tweak them, and share them through the nono registry.
  • Engineers at some of the largest tech companies use nono in workflows or production to isolate agent execution and protect credentials, as reflected in Datadog and Okta endorsements.
  • Users who need stronger isolation than a default profile can scaffold a custom profile with nono profile init opencode --extends nolabs-ai/opencode.

Getting started

Install with curl -fsSL https://nono.sh/install.sh | sh, brew install nono, or Nix targets github:nolabs-ai/nono and github:nolabs-ai/nono#prebuilt. Then run an agent with nono run --profile nolabs-ai/opencode -- opencode.

When to use it — and when not to

nono fits users who want a zero-latency, zero-setup sandbox for supported agents and who accept pre-1.0 API changes, namespace migration, and 201 open issues. It may not fit teams that need a stable 1.0 API, because the README warns changes may still occur. It also requires users to work with profiles and registry pulls.

project readme (upstream, from github) — read inline

Built by the team that brought you Sigstore
The standard for secure software attestation, used by PyPI, npm, brew, and Maven Central

License CI Status OpenSSF Best Practices Documentation

Join Discord We're hiring agent-sign GitHub Action


[!NOTE] In the lead-up to a 1.0 release, APIs are stabilizing. API changes may still occur where necessary, but will be kept to a minimum.

[!IMPORTANT] Organization migration: The official nono registry namespace has moved from always-further to nolabs-ai. Update any references in your scripts, profiles, and CI. If you already have a pack installed under the old namespace, remove it first before pulling from the new one:

nono remove always-further/claude
nono pull nolabs-ai/claude

The old namespace will be retired — migrate now.

Run AI agents in a zero latency sandbox in seconds and with zero setupClaude Code, Codex, Pi, CoPilot, Hermes, OpenCode, OpenClaw and more — nono gets you up and running within seconds, with no daemon, no container, no VM, and no disk space usage. Out of the box, nono enforces a least-privilege sandbox and supports macOS, Linux, and Windows (WSL2).

From here fork the config, tweak it, theme it, make it your own, and share it with your team or the community via the nono registry.

Want to operationalise and run at scale or within your team? Engineers at some of the largest tech companies in the world use nono as part of their workflows or to run AI agents in production.

“Datadog engineers want their agents to move fast, and we want our credentials and production systems kept safe while they do. nono is the only sandbox that gives us both fine-grained, per-command policies and sophisticated credential management that fits existing, complex real-world toolchains.” James Carnegie -- Staff Security Engineer, Datadog

"Security is embedded in everything we build at Okta. nono gives us the confidence to innovate with AI agents by isolating their execution in a highly secure, policy-controlled sandbox. It ensures our credentials remain locked down and protected, without sacrificing developer velocity" Leonardo Zanivan, Principal Engineer, Okta

Copied by many — nono pioneered the zero-latency, zero-setup agent sandbox, and continues to innovate and lead the way in agent sandboxing.


Quickstart

curl
curl -fsSL https://nono.sh/install.sh | sh
macOS / Linux (Homebrew)
brew install nono
Nix

The project provides a Nix flake with two outputs:

  • #default (from source) — builds from source using buildRustPackage (first run compiles the crate and its dependencies)
  • #prebuilt — fetches the official release binary from GitHub Releases (fast, no compilation)
# Run without installing (from source)
nix run github:nolabs-ai/nono

# Run the prebuilt binary (no compilation)
nix run github:nolabs-ai/nono#prebuilt

# Install into your profile
nix profile add github:nolabs-ai/nono

# Pin to the latest release
nix run "github:nolabs-ai/nono?ref=$(curl -fsSL https://api.github.com/repos/nolabs-ai/nono/releases/latest | jq -r .tag_name)"

Other platforms — Debian/Ubuntu, Fedora, Arch, RHEL, openSUSE, WSL2: see install instructions.

Run it!

Search for an agent in the registry, then run it:

$ nono search opencode
nolabs-ai/opencode	-	Official Opencode Plugin

$ nono run --profile nolabs-ai/opencode -- opencode

That's it. opencode now runs with read/write access to the current directory and nothing else — your SSH keys, your cloud credentials, the rest of your disk are invisible to it.

Profiles for all the popular agents live at registry.nono.sh, secured and ready to pull. Each one bundles the right filesystem scope, network allowlist, hooks, skills and more.

Make it your own!

Outgrow the defaults? Scaffold a profile and tweak it — same command you already know:

nono profile init opencode --extends nolabs-ai/opencode
nono run --profile opencode -- opencode

nono profile init exports an extended and editable profile file for your agent, that inherits from the specified base profile. That profile is composable JSON, so you can review the exact filesystem, network, credentials, and tool rules before sharing it with a team or publishing it for the community.

Are you an agent developer and want to publish your own agent package? We would love to have you and promote your work! See the docs.

Sandbox the tools agents call

nono does not stop at "put the agent in a sandbox". Agents delegate real work to tools: git, gh, curl, kubectl, package managers, build scripts, MCP clients / servers, and whatever else is on PATH. Those tools are often where secrets, network access, and side effects show up. Most sandboxes just give the agent a blanket policy where a secret is universally available to the entire agent and every tool, but nono is different:

nono can put delegated tools in their own isolated child sandboxes, outside the agent's control. The agent gets its session sandbox; when it calls a controlled tool, nono's broker launches that tool with a separate policy, separate filesystem grants, separate network rules, and separate credentials. The tool does not inherit the agent's broad --allow grants, CWD access, raw credential paths, or network access unless its own policy says so.

That means a profile can express rules like:

  • the agent may call git, but git only gets the repo, trusted Git config files, and the Git object store
  • the agent may call gh, but gh only receives a GitHub token through nono's credential proxy
  • that token may only be used against selected GitHub API methods and paths through L7 filtering
  • git may call ssh under a chained policy, while direct ssh from the agent stays denied

The policy lives in the profile, not in the prompt. The agent can ask for a tool, but it cannot widen that tool's sandbox, mint new keys, or bypass endpoint policy from inside the session.

{
  "command_policies": {
    "credentials": {
      "github-api": {
        "type": "proxy",
        "upstream": "https://api.github.com",
        "credential_key": "keyring://gh:github.com/example?decode=go-keyring",
        "env_var": "GH_TOKEN",
        "inject_header": "Authorization",
        "credential_format": "Bearer {}"
      }
    },
    "commands": {
      "gh": {
        "from": {
          "session": {
            "sandbox": {
              "fs_read": ["."],
              "credentials": [
                {
                  "name": "github-api",
                  "endpoint_policy": {
                    "default": "deny",
                    "allow": [
                      { "method": "GET", "path": "/repos/nolabs-ai/nono/issues/**" }
                    ]
                  }
                }
              ]
            },
            "invocation_policy": {
              "default": "deny",
              "allow": [
                { "argv": { "prefix": ["issue", "list"] } },
                { "argv": { "prefix": ["issue", "view"] } }
              ]
            }
          }
        }
      }
    }
  }
}

Read more in Sandboxed Tool Execution.

Ready to go deep?

Head over to the docs and discover nono's rich composable policy system, credentials injection, L7 filtering, supply chain security, rollback, multiplexing, audit and more.

Lib

readme truncated — read the full docs on github

Frequently asked questions

Is nono free to use?

nono is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does nono do?

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

What is nono written in?

nono is primarily written in Rust. Its source is publicly available at https://github.com/nolabs-ai/nono, and it has 4,121 GitHub stars.