Luke Hinds

@lukehinds.bsky.social

Old Security Hack - Creator of https://sigstore.dev https://nono.sh - former distinguished engineer at Red Hat, now CEO of alwaysfurther.ai

The claude code nono package just passed 50,000 pulls directly into a zero latency sandbox - it is already about to head past 60k. Copied by many, yet rivalled by few - nono pioneered the zero-latency, zero-setup agent sandbox, and continues to innovate and lead the way.

Bild

Project Nono - Monthly Roundup 🎬 Here's what shipped over the last 30 days, in 60 secs. SKILL / Agent Artifact Registry (early preview) - sigstore provenance Host and Pull your own Agent Packages Inbuilt Helper - no more wrangling with pesky JSON.

Exciting new feature coming online shortly. nono.sh package and policy registry. we heard from users and they wanted a way of having a more customized self-serving system for having nono configure agent hooks, skills and nono policy.

BildBild

Anyone know of some decent prompts to out a claw? Getting tired of them turning up in issues and writing an entire new slop-app and positioning it as a better solution.

I had a chat on #OpenSourceSecurity with @lukehinds.bsky.social about his project nono as well as MCP security nono is a sandbox for containing all these tools which is an incredibly difficult problem to solve. The things we see skills and MCP doing are moving forward faster than anyone can keep up

MCP and Agent security with Luke Hinds

Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke’s new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...

opensourcesecurity.io

If you're building with AI agents and haven't thought through what happens when the agent's permissions are broader than they need to be, this conversation is a good starting point. nono.sh?utm_source=t...

Next-Generation Agent Security | nono

Kernel-enforced isolation, network filtering, immutable auditing, and atomic rollbacks for AI agents - built into the nono CLI and native SDKs.

nono.sh

Luke Hinds@lukehinds.bsky.social · 5mo ago

We built nono.sh because kernel-level enforcement is the only layer that can't be bypassed by the agent itself. Talked through the reasoning with @wearedevelopers - link: www.youtube.com/watch?v=xVK2...