PulseGateWireMethodologyCompanyThe global software index— through the gate this hour
Coverage—in the index
Freshness—newest listing
Cadence—last week average · — today
Index9 markets91 categories · 140 niches
PulseGate

The global index of software taking shape now.

Stores show what passed through a store. Launch sites show what launched there. Catalogs show what entered their catalog. Each sees the market through its own gate. PulseGate reads across them.

FollowGitHubX (Twitter)LinkedIn
Platform
IndexIndex by setCategoriesWireMethodologySupply IndexDead ProjectsData SourcesCoverage RulesGlossaryEmbed Widget
Support
Help CenterSubmit your projectReport an Issue
Company
AboutTeamDimaxiaPress & DataContactPlatform Status
Legal
PrivacyTermsDisclaimer
Dimaxia · Dymaxio s.r.o. · Prague, Czechia · © 2026WatchlistSitemapSystem status
PulseGateSFSandbox for AI Agents
Visit↗
Skip to content
  1. Index›
  2. Frameworks & SDKs›
  3. Sandbox for AI Agents
← Back to the index
SF

Sandbox for AI Agents

nono.sh·Infrastructure

Sandbox for AI Agents, also known as nono, is a tool designed to provide kernel-level isolation and policy-governed runtime environments for AI agents. It addresses the security and auditability needs of running AI agents by offering operating system-level sandboxing for Linux, macOS, and Windows. js, and Go-based AI agents, as well as any terminal agent, without requiring code rewrites or wrappers.

Key features include kernel-enforced isolation with irrevocable allow-lists, atomic filesystem snapshots for undo and rollback capabilities, and cryptographically verifiable audit trails for every action. The tool supports domain-level network filtering, dynamic permission supervision at runtime, and proxy-based credential injection that ensures secrets are only available at the sandbox boundary and are zeroized upon exit. It offers composable, scalable JSON policy profiles that can be version-controlled alongside code, allowing for fine-grained, per-command security policies tailored to each agent or tool. The system also supports detachable session lifecycles through its "Ghost Sessions" feature.

nono is delivered as a command-line interface (CLI) and provides SDKs for Python and TypeScript. Installation is available via shell script, Homebrew, and various Linux package managers. Users can search for and run signed agent profiles from a registry, enabling rapid and secure deployment of AI agents with zero setup. The platform is designed to scale from individual laptops to large fleets, maintaining consistent policy enforcement and auditability across deployments.

The tool was created by the team behind Sigstore and emphasizes supply chain integrity through signed agent profiles. It is used in production by engineers at major technology companies and is positioned as an industry-standard approach for secure, auditable AI agent execution.

Open SourceApache-2.0CLImacOSWindowsLinuxSelf-hosted
SSandbox for AI Agents preview
Visit nono.sh↗
2.7kstars
188forks
12features
2026since

Overview

12 features

In the Frameworks & SDKs space, Sandbox for AI Agents takes a focused approach. It focuses on running AI agents securely with kernel-level isolation and tamper-evident audit trails. It is built as an open-source project for AI engineers and developers. Sandbox for AI Agents is open source under the Apache-2.0 license. It ships for the command line, macOS, Windows, and Linux, and it can be self-hosted.

Behind Sandbox for AI Agents is Sigstore team, and it first shipped in 2026. The project is developed in the open on GitHub with 2.7k stars and 1.1k commits in the last 90 days. Key capabilities include kernel isolation, audit trail, and network filtering.

Summary written by a language model from the project’s public pages.

  • ✓Kernel isolation
  • ✓Audit trail
  • ✓Network filtering
  • ✓Atomic rollback
  • ✓Credential injection
  • ✓Session management
  • ✓Policy enforcement
  • ✓Python sandbox
  • ✓Node.js sandbox
  • ✓Go sandbox
  • ✓Dynamic permissions
  • ✓Sigstore integration
Tags
agent-sandboxingkernel-isolationaudit-loggingai-securityruntime-policy
AI capabilities
Weights: Open

Built with & integrations

Framework
Next.js
Hosting
Vercel
AI providers
anthropic
Runs on
CLImacOSWindowsLinuxSelf-hosted
Detected from
Next.js
x-nextjs-prerender header · /_next/static/ in the HTML · __next_f in the HTML
Vercel
x-vercel-id header · x-vercel-cache header

Trust & compliance

License
Apache-2.0
Verified signals
✓HTTPS✓Open Source✓Free tier✓GitHub · ★ 2.7k✓Active maintenance

Indexing history

2

What PulseGate has recorded for this listing

  1. Indexed28 Jun · 02:27 UTC
    What Happened in There? A Tamper-Evident Audit Trail for AI Agents verified against its public source
    Source: PulseGate · Open ↗
  2. Indexed16 Jun · 06:41 UTC
    Listing verified against its public source
    Source: PulseGate · Open ↗

Frequently asked questions about Sandbox for AI Agents

What is Sandbox for AI Agents?
Sandbox for AI Agents focuses on running AI agents securely with kernel-level isolation and tamper-evident audit trails. It is catalogued under Frameworks & SDKs on PulseGate.
Who should use Sandbox for AI Agents?
Sandbox for AI Agents is an open-source project built for AI engineers and developers.
Does Sandbox for AI Agents have a free plan?
Yes — Sandbox for AI Agents is open source under the Apache-2.0 license and free to use.
What platforms does Sandbox for AI Agents run on?
Sandbox for AI Agents runs on the command line, macOS, Windows, and Linux. It can also be self-hosted.
Is Sandbox for AI Agents still maintained?
The GitHub repository shows 1.1k commits in the last 90 days.
Who makes Sandbox for AI Agents?
Sandbox for AI Agents is developed by Sigstore team.
How long has Sandbox for AI Agents been around?
Sandbox for AI Agents first shipped in 2026.
Is Sandbox for AI Agents open source?
Yes — Sandbox for AI Agents is open source under the Apache-2.0 license, developed on GitHub.

At a glance

Platforms
Cli
Languages
English
Open source
Yes · ★ 2.7k
License
Apache-2.0
Built for
AI engineers and developers
Model
Open source
Solves
Running AI agents securely with kernel-level isolation and tamper-evident audit trails.

Registered as

GitHub
always-further/nono

Developer

Sigstore team
Community-driven
↗ GitHub

Open source

View on GitHub →
Stars
2,699
Forks
188
Open issues
164
Last commit
15 Jun 2026
Commits 90d
1,099
Contributors
71
Authorship
Community-driven
Default branch
main
Latest release
v0.63.0 · 15 Jun 2026

Index record

Identity confidence
High · 95.6
Indexed
16 Jun 2026
Lifecycle
Alive
Last seen
28 Jun 2026
Identity audit (12)
Slug
sandbox-for-ai-agents-kernel-level-isolation-nono-nono-sh
Lifecycle last checked
8 Aug 2026
Verification state
Indexed for public listing
Listing state
Listed: yes
Index status
Included in index
Latest evidence snapshot
28 Jun 2026
Timeline basis
Indexed-at chronology. This listing's first-seen date was written by the catalog backfill, not observed here, so it is not treated as a sighting.
Name from
Derived from the project's own page and URL.
Category from
Assigned by a language model.
Summary from
Written by a language model from public pages.
Languages from
Detected by a language model, checked against the page's own declaration.
Canonical URL
https://nono.sh/

Ship this? Send a correction — no account, and you get a link to follow it.

Similar projects

Closest matches by what these projects do

  • SAsandboxed.shsandboxed.sh