nono

A container-free CLI sandbox for AI agents that runs Claude Code, Codex, or OpenCode with restricted access to files, network, and credentials

CLI

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Installs a system binary and manages file, network, and credential access policies
  • Runs arbitrary commands from the agent and the tools it calls, even inside a restricted environment
All reasons and checks

nolabs-ai/nono

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add cli/nono

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Install the tool

brew install nono

Commands for macOS and Linux, on Windows run them in Git Bash.

You will need: Homebrew

Checked against the repository on Sep 25, 2026, commit 775e515.

Text for your agent

Install nono with curl -fsSL https://nono.sh/install.sh | sh (on macOS and Linux, brew install nono also works). Look up a ready profile for the target agent with nono search <agent> and launch it with nono run --profile <owner>/<profile> -- <agent command>.

Other ways from the author
curl -fsSL https://nono.sh/install.sh | sh

Universal install script for macOS and Linux

This is third-party code. Review the repository files before installing.

What it does

nono wraps an agent's launch in a process-level sandbox: the binary installs with one command and immediately isolates the agent from disk, network, and credentials outside its granted policy. Policies (profiles) describe which folders, domains, and secrets an agent may reach, stored as plain JSON that you can extend with profile init. The registry.nono.sh registry ships ready profiles for popular agents such as OpenCode. A separate mechanism watches not just the agent itself but the tools it calls: git, gh, curl, kubectl, package managers, and MCP clients and servers run through a broker in their own child sandboxes with their own permissions instead of inheriting the agent's broad access.

Who it is for. For developers and security engineers who run AI coding agents locally or across a team and want to keep SSH keys, cloud tokens, and unrelated folders off limits.

Good fit when

  • You need to run Claude Code, Codex, or another agent without risking SSH keys and cloud credentials
  • You need different file and network policies per project or per teammate
  • The agent calls tools like git, curl, or kubectl that also need their own restrictions

Not a fit when

  • The agent already runs inside an isolated environment such as a dedicated virtual machine
  • You need full hardware emulation or hypervisor-level isolation rather than a lightweight process sandbox

Example request

Wrap Codex in a nono sandbox with the matching profile so it cannot reach my SSH keys or unrelated folders

Limitations

The sandbox works at the OS and process level rather than as a full virtual machine, so isolation depends on OS capabilities. Ready-made registry profiles are written by other authors, and their policies are worth reviewing before production use. Windows support goes through WSL2.

How to disable. Run the agent directly, without the nono run wrapper. To remove the tool itself, use brew uninstall nono or delete the installed binary by hand.

Security check

  • Installs a system binary and manages file, network, and credential access policies
  • Runs arbitrary commands from the agent and the tools it calls, even inside a restricted environment

README in short

The README presents nono as the fastest way to sandbox an AI agent with no setup: install via a curl script, Homebrew, or Nix, then look up a ready profile in the public registry and launch it with nono run. A profile can be extended with profile init and shared with a team. A separate section explains how nono isolates not just the agent but the tools it calls along the way, such as git, gh, curl, kubectl, and MCP clients, through a broker with a separate policy for each. The project comes from the team behind Sigstore and is used by engineers at Datadog and Okta.

FAQ

How is nono different from running an agent in Docker?

nono does not spin up a daemon, container, or virtual machine, the sandbox works at the process level and starts instantly, and access policies are declared in a JSON profile.

Can it restrict the MCP servers an agent calls, not just the agent itself?

Yes, nono's broker launches tools the agent calls, including MCP clients and servers, in their own child sandboxes with their own network, filesystem, and credential rules.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AInono

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.