Registry

Signed packs. Verifiable installs.

A central registry for nono policies, agent hooks, skills, and any custom artifacts for your agents. Every pack is signed, scanned, and verified before it reaches your machine — software supply-chain security built in.

Publish

Publish from your own repo

You own the source. Tag a release and the pack lands on the registry — signed, scanned, and ready to install.

01

Your repo

Push the pack to your own GitHub repo and tag a release.

02

Sign & scan

CI signs the artifact and emits a verifiable manifest.

03

Publish

The pack is indexed on registry.nono.sh.

04

Install anywhere

Anyone runs nono pull yourname/pack.

Signed·Scanned·Verified·Apache-2.0

Find a pack. Or publish your own.

Signed, scanned, and verified packs for sandboxing AI agents — install with one command, or publish from your own GitHub repo.