Favicon of nono

nono

An open-source AI agent sandbox for macOS, Linux and Windows via WSL2, with per-tool permissions, protected credentials and verifiable audit records.

Screenshot of nono website

nono is an open-source security runtime for people running terminal AI agents on their own machines or servers. It limits what an agent and each tool it calls can access, with boundaries enforced by the operating system. It runs on macOS, Linux and Windows through WSL2, without requiring a container, VM or daemon.

Its main distinction is per-tool isolation. A coding agent can have access to a workspace while a command it delegates gets narrower permissions for files, network requests and credentials. Each controlled invocation runs in a temporary sandbox outside the agent's control, which nono removes when the command exits.

Network policies can restrict HTTP methods and paths, so access to GitHub doesn't have to mean permission to post comments or merge pull requests. Real credentials stay with the supervisor; tools receive substitute tokens, and the proxy adds the secret at the network boundary. Actions outside the supplied policy can pause for human approval.

nono works with Claude Code, Codex, OpenCode, Pi and other terminal agents without requiring changes to the agent. Signed registry profiles provide starting policies, while composable JSON profiles let teams review and share their own rules alongside code.

The runtime is written in Rust and uses the Apache 2.0 license. It supports atomic rollbacks and records security events in a cryptographically verifiable, tamper-evident audit trail. Rust, Python, TypeScript and Go bindings let developers incorporate it into their own software.

Similar to nono