Run Agent Clis In A Capability Based Local Sandbox With Snapshots And Controlled Egress Using Nono
ASecurity
Constrain Claude Code, Codex, OpenClaw, and similar agent CLIs inside a kernel-enforced local sandbox with explicit filesystem, network, credential, and snapshot controls.
Installs into .claude/skills of the current project.
Are you the author of Run Agent Clis In A Capability Based Local Sandbox With Snapshots And Controlled Egress Using Nono?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/agentskillexchange-run-agent-clis-in-a-capability-based-local-sandbox)
---
name: "Run agent CLIs in a capability-based local sandbox with snapshots and controlled egress using nono"
slug: "run-agent-clis-in-a-capability-based-local-sandbox-with-snapshots-and-controlled-egress-using-nono"
description: "Constrain Claude Code, Codex, OpenClaw, and similar agent CLIs inside a kernel-enforced local sandbox with explicit filesystem, network, credential, and snapshot controls."
github_stars: 2080
verification: "security_reviewed"
source: "https://github.com/always-further/nono"
author: "always-further"
publisher_type: "organization"
category: "Security & Verification"
framework: "Multi-Framework"
tool_ecosystem:
github_repo: "always-further/nono"
github_stars: 2080
---
# Run agent CLIs in a capability-based local sandbox with snapshots and controlled egress using nono
Constrain Claude Code, Codex, OpenClaw, and similar agent CLIs inside a kernel-enforced local sandbox with explicit filesystem, network, credential, and snapshot controls.
## Prerequisites
nono plus a supported local agent CLI such as Claude Code, Codex, OpenClaw, or another profiled tool.
## Installation
Requirements and caveats from upstream:
- Also available as [Python](https://github.com/always-further/nono-py) , [TypeScript](https://github.com/always-further/nono-ts), [Go](https://github.com/always-further/nono-go) bindings.
- We encourage using AI tools to contribute. However, you must understand and carefully review any AI-generated code before submitting. Security is paramount. If you don't understand how a change works, ask in [Discord]...
Basic usage or getting-started notes:
- **nono registry** — The nono registry is now in alpha and available to try out. Host your skills, hooks, policies, and more in your own repository, then securely distribute them through the registry. This gives you th...
- Profiles for [Claude Code](https://docs.nono.sh/cli/clients/claude-code), [Codex](https://docs.nono.sh/cli/clients/codex), [OpenCode](https://docs.nono.sh/cli/clients/opencode), [OpenClaw](https://docs.nono.sh/cli/cli...
- ## Libraries and Bindings
- Source: https://github.com/always-further/nono
- Extracted from upstream docs: https://raw.githubusercontent.com/always-further/nono/HEAD/README.md
## Documentation
- https://nono.sh
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/run-agent-clis-in-a-capability-based-local-sandbox-with-snapshots-and-controlled-egress-using-nono/)