# Run agent CLIs in a capability-based local sandbox with snapshots and controlled egress using nono

> Constrain Claude Code, Codex, OpenClaw, and similar agent CLIs inside a kernel-enforced local sandbox with explicit filesystem, network, credential, and snapshot controls.

- Skill: `agentskillexchange/run-agent-clis-in-a-capability-based-local-sandbox-with-snap` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/run-agent-clis-in-a-capability-based-local-sandbox-with-snap`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/run-agent-clis-in-a-capability-based-local-sandbox-with-snap/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/run-agent-clis-in-a-capability-based-local-sandbox-with-snap

---


# Run agent CLIs in a capability-based local sandbox with snapshots and controlled egress using nono

Constrain Claude Code, Codex, OpenClaw, and similar agent CLIs inside a kernel-enforced local sandbox with explicit filesystem, network, credential, and snapshot controls.

## Prerequisites

nono plus a supported local agent CLI such as Claude Code, Codex, OpenClaw, or another profiled tool.

## Installation

Requirements and caveats from upstream:
- Also available as [Python](https://github.com/always-further/nono-py) , [TypeScript](https://github.com/always-further/nono-ts), [Go](https://github.com/always-further/nono-go) bindings.
- We encourage using AI tools to contribute. However, you must understand and carefully review any AI-generated code before submitting. Security is paramount. If you don't understand how a change works, ask in [Discord]...

Basic usage or getting-started notes:
- **nono registry** — The nono registry is now in alpha and available to try out. Host your skills, hooks, policies, and more in your own repository, then securely distribute them through the registry. This gives you th...
- Profiles for [Claude Code](https://docs.nono.sh/cli/clients/claude-code), [Codex](https://docs.nono.sh/cli/clients/codex), [OpenCode](https://docs.nono.sh/cli/clients/opencode), [OpenClaw](https://docs.nono.sh/cli/cli...
- ## Libraries and Bindings

- Source: https://github.com/always-further/nono
- Extracted from upstream docs: https://raw.githubusercontent.com/always-further/nono/HEAD/README.md

## Documentation

- https://nono.sh

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/run-agent-clis-in-a-capability-based-local-sandbox-with-snapshots-and-controlled-egress-using-nono/)

