always-further/nono

Secure, kernel-enforced sandbox CLI and SDKs for AI agents. Capability-based isolation with secure key management, atomic rollback, cryptographic immutable audit chain of provenance. Run your agents in a zero-trust environment.

63
/ 100
Established

Implements kernel-enforced sandboxing via Landlock (Linux 5.13+) and Seatbelt (macOS 10.5+) with irreversible capability-based access control applied before execution. Provides credential injection via proxy mode—keeping API keys entirely outside the sandbox—or environment injection from system keystores and 1Password. Includes Sigstore-based cryptographic verification of agent instruction files and scripts using DSSE envelopes and in-toto attestations to prevent supply chain attacks.

980 stars. Actively maintained with 267 commits in the last 30 days.

No Package No Dependents
Maintenance 25 / 25
Adoption 10 / 25
Maturity 11 / 25
Community 17 / 25

How are scores calculated?

Stars

980

Forks

73

Language

Rust

License

Apache-2.0

Last pushed

Mar 12, 2026

Commits (30d)

267

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/agents/always-further/nono"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.