Luke Hinds
@lukehinds.bsky.social
Old Security Hack - Creator of https://sigstore.dev https://nono.sh - former distinguished engineer at Red Hat, now CEO of alwaysfurther.ai
“AI will cause massive a disruption to the music industry“ Angine De Poitrine “Hold my nose” youtu.be/pRgHYWOtqqc?...
Angine de Poitrine - Fabienk (Live on KEXP)
YouTube video by KEXP
youtu.be
We just shipped ephemeral micro sandboxed tool execution! A collaborative effort along side smart folks from Datadog and Okta - the first of its kind, you can set a policy for an individual CLI tool execution - demonstration in the link.. www.youtube.com/watch?v=ndTM...
finally reaching the world stage
'World Shin-Kicking Championships: Broken legs and broken toes – ‘It’s not for the faint-hearted’. @icshc.bsky.social Emeritus Prof. Martin Polley @historymartin.bsky.social interviewed by @theathletic.com on the Cotswold Olimpicks - www.nytimes.com/athletic/732... #sportshistory
The claude code nono package just passed 50,000 pulls directly into a zero latency sandbox - it is already about to head past 60k. Copied by many, yet rivalled by few - nono pioneered the zero-latency, zero-setup agent sandbox, and continues to innovate and lead the way.
New post on Kubefence from Pradipta Banerjee of @RedHat : stacking Kata Containers + Seccomp + nono into one RuntimeClass nono.sh/blog/kubefen...
Why Containers Aren't Enough for AI Agents in Kubernetes
How Kubefence stacks Kata Containers, Seccomp, and Nono to sandbox AI workloads in Kubernetes
nono.sh
nono.sh just shipped a profile for @nousresearch.com Hermes Agent * Kernel isolation * Key Protections * Atomic rollback * L7 filtering No sign up needed, no cloud keys registry.nono.sh/packages/alw...
always-further/hermes
Install with: nono pull always-further/hermes
registry.nono.sh
#nix users, just noticed nono.sh is on github.com/numtide/llm-...
GitHub - numtide/llm-agents.nix: Nix packages for AI coding agents and development tools. Automatically updated daily.
Nix packages for AI coding agents and development tools. Automatically updated daily. - numtide/llm-agents.nix
github.com
Project Nono - Monthly Roundup 🎬 Here's what shipped over the last 30 days, in 60 secs. SKILL / Agent Artifact Registry (early preview) - sigstore provenance Host and Pull your own Agent Packages Inbuilt Helper - no more wrangling with pesky JSON.
Exciting new feature coming online shortly. nono.sh package and policy registry. we heard from users and they wanted a way of having a more customized self-serving system for having nono configure agent hooks, skills and nono policy.
A very bizarre experience of meeting my first claw in the wild. The Day of the Claws: How I watched an agent reverse-engineer my career in an afternoon. decodebytes.substack.com/p/the-day-of...
It is time for me to reveal the truth - I am Satoshi Nakamoto I just don't have any proof. nono.sh/blog/secure-...
What Really Happened In There? A Tamper-Evident Audit Trail for AI Agents
How nono records every action an AI agent makes in an append-only Merkle tree the agent itself cannot reach, and lets anyone verify after the fact — with cryptographic proof — that the record was not ...
nono.sh
Anyone know of some decent prompts to out a claw? Getting tired of them turning up in issues and writing an entire new slop-app and positioning it as a better solution.
nono.sh is becoming a dream to develop - not more five terminals left open , losing track of work in progress.
Took nono.sh to the @aidotengineer.bsky.social event in London this week. Wasn't expecting to spend half the day being stopped by engineers telling us they're daily users. One team even demoed nono integrated into their own product - live, in the wild, built by someone we'd never met.
demo of nono tmux style multiplexed sandboxes and how they can be used in a development workflow www.youtube.com/watch?v=QqRt...
nono lifecycle
YouTube video by Luke Hinds
youtube.com
The axios npm compromise from this week night is a near-perfect test case for nono. Account takeover. Hidden dependency. postinstall hook. RAT deployed. Self-deleted to cover tracks. Full writeup: nono.sh/blog/nono-ax...
How nono Prevents Supply Chain Attacks: A Case Study of the axios Compromise
How nono's kernel-level sandbox stops supply chain attacks like the axios npm compromise — blocking RAT deployment, credential theft, and exfiltration.
nono.sh
I had a chat on #OpenSourceSecurity with @lukehinds.bsky.social about his project nono as well as MCP security nono is a sandbox for containing all these tools which is an incredibly difficult problem to solve. The things we see skills and MCP doing are moving forward faster than anyone can keep up
MCP and Agent security with Luke Hinds
Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke’s new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...
opensourcesecurity.io
If you're building with AI agents and haven't thought through what happens when the agent's permissions are broader than they need to be, this conversation is a good starting point. nono.sh?utm_source=t...
Next-Generation Agent Security | nono
Kernel-enforced isolation, network filtering, immutable auditing, and atomic rollbacks for AI agents - built into the nono CLI and native SDKs.
nono.sh
We built nono.sh because kernel-level enforcement is the only layer that can't be bypassed by the agent itself. Talked through the reasoning with @wearedevelopers - link: www.youtube.com/watch?v=xVK2...
@josh.bressers.name put it well: MCP is moving faster than anyone can keep up with. @lukehinds.bsky.social joined #OpenSourceSecurity to dig into why agent security is structurally hard and what kernel-level sandboxing nono.sh actually solves. Episode: opensourcesecurity.io/2026/2026-03...
MCP and Agent security with Luke Hinds
Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke’s new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...
opensourcesecurity.io
tmux style sandboxes anyone? along with full docker-eque style lifecycle and atomic rollbacks? nono.sh
We built nono.sh because kernel-level enforcement is the only layer that can't be bypassed by the agent itself. Talked through the reasoning with @wearedevelopers - link: www.youtube.com/watch?v=xVK2...
Securing AI Agents from the Ground Up
YouTube video by WeAreDevelopers
youtube.com
great chat, with a great chap (Josh, not me).
I had a chat on #OpenSourceSecurity with @lukehinds.bsky.social about his project nono as well as MCP security nono is a sandbox for containing all these tools which is an incredibly difficult problem to solve. The things we see skills and MCP doing are moving forward faster than anyone can keep up
little nono.sh is just 30 days old, just about to hit a 1k - Its fairing very well against the OSS security giants - lets see if it can keep up the trajectory