Sandbox for AI Agents, also known as nono, is a tool designed to provide kernel-level isolation and policy-governed runtime environments for AI agents. It addresses the security and auditability needs of running AI agents by offering operating system-level sandboxing for Linux, macOS, and Windows. js, and Go-based AI agents, as well as any terminal agent, without requiring code rewrites or wrappers.
Key features include kernel-enforced isolation with irrevocable allow-lists, atomic filesystem snapshots for undo and rollback capabilities, and cryptographically verifiable audit trails for every action. The tool supports domain-level network filtering, dynamic permission supervision at runtime, and proxy-based credential injection that ensures secrets are only available at the sandbox boundary and are zeroized upon exit. It offers composable, scalable JSON policy profiles that can be version-controlled alongside code, allowing for fine-grained, per-command security policies tailored to each agent or tool. The system also supports detachable session lifecycles through its "Ghost Sessions" feature.
nono is delivered as a command-line interface (CLI) and provides SDKs for Python and TypeScript. Installation is available via shell script, Homebrew, and various Linux package managers. Users can search for and run signed agent profiles from a registry, enabling rapid and secure deployment of AI agents with zero setup. The platform is designed to scale from individual laptops to large fleets, maintaining consistent policy enforcement and auditability across deployments.
The tool was created by the team behind Sigstore and emphasizes supply chain integrity through signed agent profiles. It is used in production by engineers at major technology companies and is positioned as an industry-standard approach for secure, auditable AI agent execution.
In the Frameworks & SDKs space, Sandbox for AI Agents takes a focused approach. It focuses on running AI agents securely with kernel-level isolation and tamper-evident audit trails. It is built as an open-source project for AI engineers and developers. Sandbox for AI Agents is open source under the Apache-2.0 license. It ships for the command line, macOS, Windows, and Linux, and it can be self-hosted.
Behind Sandbox for AI Agents is Sigstore team, and it first shipped in 2026. The project is developed in the open on GitHub with 2.7k stars and 1.1k commits in the last 90 days. Key capabilities include kernel isolation, audit trail, and network filtering.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do