Capability-based agent runtime with fine-grained policies . Brokering access directly within the agent's operating context, with zero setup and zero latency
Nono is a capability-based, policy-governed sandbox runtime written in Rust that restricts what an AI agent process can access on the host machine, enforcing limits on file paths, network destinations, environment variables, and credentials using kernel primitives (Landlock on Linux, Seatbelt on macOS). It integrates directly with Claude Code via pre-built profiles pulled from a registry, invoked with a single `nono run --profile always-further/claude -- claude` command, and supports other agents including Codex and OpenCode. The core Rust library is policy-free and embeds into any application, with bindings also available for Python, TypeScript, and Go. A standout feature is credential proxy mode, which keeps API keys entirely outside the sandbox rather than injecting them into the agent process, with support for keystore, 1Password, and Apple Passwords. Audit logs, Sigstore-based attestation of instruction files like CLAUDE.md, content-addressable rollback snapshots, and composable policy profiles make the tool particularly relevant for security teams deploying Claude Code in shared or production environments.
- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Healthy fork ratio
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
git clone https://github.com/always-further/nono && cp nono/*.md ~/.claude/agents/Resumen de Subagents
Lo que la gente pregunta sobre nono
¿Qué es always-further/nono?
+
always-further/nono es subagents para el ecosistema de Claude AI. Capability-based agent runtime with fine-grained policies . Brokering access directly within the agent's operating context, with zero setup and zero latency Tiene 2.7k estrellas en GitHub y se actualizó por última vez today.
¿Cómo se instala nono?
+
Puedes instalar nono clonando el repositorio (https://github.com/always-further/nono) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar always-further/nono?
+
Nuestro agente de seguridad ha analizado always-further/nono y le ha asignado un Trust Score de 100/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene always-further/nono?
+
always-further/nono es mantenido por always-further. La última actividad registrada en GitHub es de today, con 171 issues abiertos.
¿Hay alternativas a nono?
+
Sí. En ClaudeWave puedes explorar subagents similares en /categories/agents, ordenados por popularidad o actividad reciente.
Despliega nono en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/always-further-nono)<a href="https://claudewave.com/repo/always-further-nono"><img src="https://claudewave.com/api/badge/always-further-nono" alt="Featured on ClaudeWave: always-further/nono" width="320" height="64" /></a>Más Subagents
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
The agent that grows with you
Java 面试 & 后端通用面试指南,覆盖计算机基础、数据库、分布式、高并发、系统设计与 AI 应用开发
Production-ready platform for agentic workflow development.
The agent engineering platform.
🤯 LobeHub is your Chief Agent Operator, organizing your agents into 7×24 operations by hiring, scheduling, and reporting on your entire AI team.