GIT_FEED

always-further/nono

Kernel-enforced agent sandbox and agent security CLI and SDKs. Capability-based isolation with secure key management, atomic rollback, cryptographic immutable audit chain of provenance. Run your agents in a zero-trust environment.

View on GitHub

What it does

Nono is a security tool that locks AI agents inside an isolated container at the operating system level, so they can only access what you explicitly allow — making it structurally impossible for them to read sensitive files, run dangerous commands, or be manipulated into doing harm. It also protects API keys, logs every action with a tamper-proof record, and lets you instantly undo anything the agent did — all with a one-line install and no complex infrastructure to set up.

Why it matters

As companies race to ship AI agents that take real actions in the world, the liability and trust question of 'what can this agent actually do to my systems or my customers' is becoming a board-level concern — and nono offers a credible answer from the creator of Sigstore, a tool already trusted by the world's largest software registries. For founders and PMs building agent-powered products, this is the kind of infrastructure that could become a prerequisite for enterprise sales and insurance conversations.

39Active

On the radar — signal detected

Stars
1.3k
Forks
91
Contributors
27
Language
Rust
Category
Security

Score updated Mar 25, 2026

Related projects

PentAGI is an open-source AI system that autonomously conducts cybersecurity stress-tests — known as penetration testing — on computer systems, mimicking what a human security expert would do to find vulnerabilities. Rather than requiring a skilled security professional to manually probe for weaknesses, PentAGI's AI agents work independently to identify and report security gaps.

// why it matters Security testing is expensive and scarce, with qualified experts commanding high rates and limited availability — automating this with AI could dramatically lower the cost and frequency of security audits for startups and enterprises alike. With nearly 13,500 stars on GitHub, strong developer interest signals this is a category with real demand, making it relevant for founders building security products or considering their own security posture.

Go13.6k stars1.7k forks18 contrib

OWASP Nest is a discovery platform that helps people find, explore, and contribute to OWASP — the world's leading nonprofit focused on software security standards and best practices. Think of it as a curated directory and community hub that makes it easier to navigate OWASP's hundreds of projects, local chapters, and volunteer opportunities, all in one place.

// why it matters With 170 contributors and nearly 400 stars, this project signals strong community momentum around making security knowledge more accessible — a growing priority as regulators and enterprises demand better software security practices. For founders and PMs, it represents a ready-made engagement layer for the security community, and its open, contributor-friendly model demonstrates how open-source platforms can scale without a large core team.

Python408 stars605 forks184 contrib

Clawdstrike is a security monitoring and threat detection system specifically designed for fleets of AI agents — the kind used in autonomous workflows where multiple AI systems operate and communicate together. Think of it as the equivalent of enterprise antivirus and threat detection software, but built from the ground up for AI-driven systems rather than traditional computers and networks.

// why it matters As companies deploy more autonomous AI agents to handle real business tasks, securing those agents becomes a critical and largely unsolved problem — making this an early entry into what could become a major product category. Founders building AI automation products or enterprises adopting agentic workflows will increasingly need to answer 'how do we secure this?' and tools like Clawdstrike represent the emerging infrastructure layer for that answer.

Rust264 stars28 forks5 contrib

Brave Core is the engine that powers the Brave browser, a privacy-focused web browser available on both desktop and mobile devices. It builds on top of Google's open-source Chromium project (the same foundation as Chrome) and adds Brave's unique features like built-in ad blocking, privacy protections, and its rewards system.

// why it matters With growing consumer demand for privacy and increasing regulatory pressure around data collection, Brave represents a real market shift away from ad-supported browser models — and its open-source engine means builders can study or build on the same privacy-first architecture. For founders and investors, it signals that privacy is becoming a product feature users actively seek out, not just a compliance checkbox.

C++3.0k stars1.2k forks493 contrib
// SUBSCRIBE

The repos that moved this week, why they matter, and what to watch next. One email. No noise.