
nono is an open-source security runtime for people running terminal AI agents on their own machines or servers. It limits what an agent and each tool it calls can access, with boundaries enforced by the operating system. It runs on macOS, Linux and Windows through WSL2, without requiring a container, VM or daemon.
Its main distinction is per-tool isolation. A coding agent can have access to a workspace while a command it delegates gets narrower permissions for files, network requests and credentials. Each controlled invocation runs in a temporary sandbox outside the agent's control, which nono removes when the command exits.
Network policies can restrict HTTP methods and paths, so access to GitHub doesn't have to mean permission to post comments or merge pull requests. Real credentials stay with the supervisor; tools receive substitute tokens, and the proxy adds the secret at the network boundary. Actions outside the supplied policy can pause for human approval.
nono works with Claude Code, Codex, OpenCode, Pi and other terminal agents without requiring changes to the agent. Signed registry profiles provide starting policies, while composable JSON profiles let teams review and share their own rules alongside code.
The runtime is written in Rust and uses the Apache 2.0 license. It supports atomic rollbacks and records security events in a cryptographically verifiable, tamper-evident audit trail. Rust, Python, TypeScript and Go bindings let developers incorporate it into their own software.
Claim this page with an email at nono.sh. nono gets the verified badge, and you can upgrade the listing to be featured on localhosted. Proud to be listed? Put our badge on your site.
Want more people to find nono?Promote it
Something wrong or outdated on this page?
1.8KUpdated 3 months agoApache-2.0
macOS · Windows · Linux · Docker#Agent Client Protocol#Code execution#Guardrails
Stakpak is an open source AI agent for developers and DevOps teams who want to run production operations on their own machines or servers. It can work interactively in a terminal or run continuously in the background, investigating app health problems, taking corrective action and notifying a human when it needs help.
13.7KUpdated 8 hours agoApache-2.0
macOS · Windows · Linux · Docker#Agent Skills#Code execution#Guardrails
OpenShell is a self-hosted runtime for teams running autonomous AI agents that need access to files, APIs and credentials. It runs agents in sandboxes with kernel-level isolation and explicit access policies. It's open source under Apache 2.0 and supports Linux and macOS on Apple Silicon, with Docker, Podman or host virtualization.
1.3KUpdated 3 weeks agoMIT
macOS · Windows · Linux#Code execution#Guardrails#MCP
27.6KUpdated 1 day agoMIT
macOS · Windows · Linux#Code execution#MCP#Tool calling
1.2KUpdated 2 days agoMIT
macOS · Windows · Linux · Docker · Web#Guardrails#llama.cpp backend#LLM tracing
55Updated 7 days agoMIT
macOS · Windows · Linux#Code execution#Resumable workflows#Works offline
Quicksand gives AI agents a full Linux virtual machine on your own hardware, controlled through an async Python API. It's for developers who need agents to execute code or interact with a desktop inside a separate operating system. Each sandbox has its own kernel and uses QEMU for hypervisor-level isolation.
Reverify is a local verification toolkit for developers and reverse engineers who use AI to analyze binaries or rewrite code. It checks a model's claims against the actual file or executed behavior, then returns a verdict with evidence. The Python project is open source under the MIT license and runs on Linux, Windows and macOS as a CLI or MCP server.
Cua gives AI agents access to computers they can inspect and operate, with tools for desktop automation, local virtual machines, and hosted fleets. It's for developers building agents that work across native apps and browsers, or evaluating how well those agents complete computer tasks. You bring the agent and model.
GoModel is a self-hosted AI gateway for developers and platform teams that want one API for local models and cloud providers. It accepts OpenAI- and Anthropic-compatible requests, so applications can keep their existing SDKs while the gateway handles provider selection and usage controls.