Beyond the Sandbox
Capability brokering for AI agents. The ideas, the four layers, the limits, and how to run it yourself. nono is open source under Apache-2.0.
Three ideas from the talk
- 1
Nobody breaches an agent. They borrow it.
An agent inherits everything its user can reach: the working copy, the home directory, keys, tokens, and the open network. One prompt injection is enough to spend that authority. The sandbox is the wall; the attack goes around it, through what the agent was handed.
- 2
Authority belongs to the action, not the agent.
Grant each capability to the command that needs it, for as long as it needs it. In the demo, git reaches the SSH key through its own child envelope while the session itself is denied it. Anything unplanned goes to a human.
- 3
Prevention is a stronger evidence class than detection.
A denied request that never left the machine is a different kind of evidence from an alert about one that did. nono records both allowed and denied operations in a tamper-evident log the agent cannot write to.
Try it in five minutes
No API key needed until you run an agent. The full walkthrough is in the quickstart, and the registry has signed profiles for the popular coding agents.
# Install (Homebrew, or: curl -fsSL https://nono.sh/install.sh | sh)brew install nono# See the boundary: run from a project folder, not your home directorynono run --allow . -- cat ~/.ssh/config# expect a denial: ~/.ssh is on nono's default deny list# Run an agent under a signed registry profilenono search opencodenono run --profile nolabs-ai/opencode -- opencode# Make the profile yoursnono profile init opencode --extends nolabs-ai/opencode
Capability brokering
Access starts from a declared profile, enforced by the kernel before the agent starts. Credentials are injected by nono's proxy, so the agent holds a phantom token. On Linux, the supervisor can grant more at runtime, only with a human approval.
Network denial
Network access is open by default. Allow the domains a task needs and the child is restricted to nono's proxy. Cloud metadata endpoints and link-local ranges stay denied whatever the profile says.
Tamper-evident audit
Every run is recorded by default in a Merkle-committed log, written by the supervisor outside the sandbox. Change one event and verification fails. Signing the finished session is opt-in.
Provenance
Instructions are inputs, not authority. Sign instruction files like AGENTS.md and CLAUDE.md with Sigstore, keyed or keyless. Unsigned or tampered files are denied before the agent starts.
The kernel boundary underneath
Every layer above sits on an irrevocable kernel sandbox: Landlock on Linux and WSL2, Seatbelt on macOS. No daemon, no container, no root. Child processes inherit the restrictions. The OS sandbox page covers how each platform enforces it.
What nono does not do
Read this before you trust the rest.
- A sandbox bounds what a process can reach. It does not judge whether an allowed action is a good idea.
- A credential you grant through the proxy stays out of the sandbox, but the agent can still call the allowed API with it. Environment-variable injection puts the secret in the process environment.
- macOS Seatbelt cannot filter by TCP port. Network rules there are coarser than on Linux.
- Linux Landlock is strictly allow-list. It cannot carve a deny out of an allowed directory, so nono refuses to start rather than enforce that policy wrongly.
- Enforcement depends on the kernel: Linux 5.13+ for basic sandboxing, 6.2+ for full filesystem control, 6.7+ for TCP filtering. Windows runs through WSL2.
- nono is pre-1.0. APIs are stabilizing, and profile fields can still change between releases.
Check the project, not just the tool
Design changes that are large or security-consequential go through a nono Enhancement Proposal (NEP): new capability types, changes to enforcement semantics or the policy model, new sandbox backends, and breaking profile or CLI changes.
Every NEP carries a mandatory Security Considerations section, reviewed against the security model before it can be accepted, and proposals are reviewed as public pull requests before any implementation starts.
Get started with nono
Runtime safety infrastructure that works on macOS, Linux, Windows, and in CI.