nono
Freenono - a capability-based, multiplexing sandbox tool, built for developers - lift'n'shift seamless path to prod. Run agents securely without needing any additional infra, zero setup, zero latency.
About nono
nono is an open-source sandbox for AI agents that provides kernel-level isolation with zero setup and zero latency. Designed for developers, it allows running terminal agents securely without additional infrastructure. Key capabilities include composable JSON policies for fine-grained permissions, tool-specific sandboxing enforcing least privilege, credential protection where secrets are injected at the boundary and zeroised on exit, and a fully auditable cryptographic audit trail. It integrates seamlessly with popular agents like Claude Code, OpenCode, Codex, Antigravity, Goose, OpenClaw, GitHub Copilot, Qwen Code, Pi, and Hermes. nono scales from a single laptop to fleets of agents, and is used in production by companies such as Datadog and Okta.
Key Features
Pros & Cons
- Fast installation and zero configuration required
- Fine-grained, composable policies that are easy to manage
- Per-tool sandboxing reduces blast radius compared to monolithic sandboxes
- Secrets are never exposed to the agent, enhancing security
- Fully auditable with a cryptographic trail that can be verified by third parties
- Actively used by large organizations (Datadog, Okta) in production
- Currently limited to terminal-based AI agents, not GUI applications
- Requires understanding JSON policy syntax for custom configurations
Best For
Alternatives to nono
giskard-oss
🐢 Open-Source Evaluation & Testing library for LLM Agents
ai-captcha-bypass
AI Captcha Bypass
backdoor-learning-resources
A list of backdoor learning resources
claude-bug-bounty
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
agentic-radar
A security scanner for your LLM agentic workflows