Skip to content
Back to skills

Run Agent Clis In A Capability Based Local Sandbox With Snapshots And Controlled Egress Using Nono

ASecurity

Constrain Claude Code, Codex, OpenClaw, and similar agent CLIs inside a kernel-enforced local sandbox with explicit filesystem, network, credential, and snapshot controls.

  • 36 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added June 2, 2026
ai-agentstypescriptpythongogitsecuritydocumentation

Works with

  • claude code
  • cli

Security analysis

A100/100

Scanned June 2, 2026

npx -y skills add agentskillexchange/skills --skill run-agent-clis-in-a-capability-based-local-sandbox-with-snapshots-and-controlled-egress-using-nono --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Run Agent Clis In A Capability Based Local Sandbox With Snapshots And Controlled Egress Using Nono?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Run Agent Clis In A Capability Based Local Sandbox With Snapshots And Controlled Egress Using Nono
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/agentskillexchange-run-agent-clis-in-a-capability-based-local-sandbox/badge)](https://www.skillsdirectory.com/skills/agentskillexchange-run-agent-clis-in-a-capability-based-local-sandbox)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "Run agent CLIs in a capability-based local sandbox with snapshots and controlled egress using nono"
slug: "run-agent-clis-in-a-capability-based-local-sandbox-with-snapshots-and-controlled-egress-using-nono"
description: "Constrain Claude Code, Codex, OpenClaw, and similar agent CLIs inside a kernel-enforced local sandbox with explicit filesystem, network, credential, and snapshot controls."
github_stars: 2080
verification: "security_reviewed"
source: "https://github.com/always-further/nono"
author: "always-further"
publisher_type: "organization"
category: "Security & Verification"
framework: "Multi-Framework"
tool_ecosystem:
  github_repo: "always-further/nono"
  github_stars: 2080
---

# Run agent CLIs in a capability-based local sandbox with snapshots and controlled egress using nono

Constrain Claude Code, Codex, OpenClaw, and similar agent CLIs inside a kernel-enforced local sandbox with explicit filesystem, network, credential, and snapshot controls.

## Prerequisites

nono plus a supported local agent CLI such as Claude Code, Codex, OpenClaw, or another profiled tool.

## Installation

Requirements and caveats from upstream:
- Also available as [Python](https://github.com/always-further/nono-py) , [TypeScript](https://github.com/always-further/nono-ts), [Go](https://github.com/always-further/nono-go) bindings.
- We encourage using AI tools to contribute. However, you must understand and carefully review any AI-generated code before submitting. Security is paramount. If you don't understand how a change works, ask in [Discord]...

Basic usage or getting-started notes:
- **nono registry** — The nono registry is now in alpha and available to try out. Host your skills, hooks, policies, and more in your own repository, then securely distribute them through the registry. This gives you th...
- Profiles for [Claude Code](https://docs.nono.sh/cli/clients/claude-code), [Codex](https://docs.nono.sh/cli/clients/codex), [OpenCode](https://docs.nono.sh/cli/clients/opencode), [OpenClaw](https://docs.nono.sh/cli/cli...
- ## Libraries and Bindings

- Source: https://github.com/always-further/nono
- Extracted from upstream docs: https://raw.githubusercontent.com/always-further/nono/HEAD/README.md

## Documentation

- https://nono.sh

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/run-agent-clis-in-a-capability-based-local-sandbox-with-snapshots-and-controlled-egress-using-nono/)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…