nono — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by always-further · MCP Server · ★ 2.2k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is nono safe to install? View the security audit →

About nono

Built by the team that brought you Sigstore The standard for secure software attestation, used by PyPI, npm, brew, and Maven Central [!NOTE] In the lead-up to a 1.0 release, APIs are stabilizing. API change

agent-sandboxagent-securityai-agent-sandboxai-agent-securityai-agentsai-securityai-security-toolcode-executionllm-sandboxllm-security

Quick Facts

Stars2,238
Forks157
LanguageRust
CategoryMCP Server
LicenseApache-2.0
Quality Score67.7993425979246/100
Open Issues120
Last Updated2026-05-05
Created2026-01-31
Platformsmcp, rust
Est. Tokens~4844k

nono alternative? Top 6 similar tools

Looking for a nono alternative? If you're comparing nono with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • hol-guard by hashgraph-online · ⭐ 650

    Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, M

  • Adrian by secureagentics · ⭐ 564

    Open-source runtime AI agent security tool - monitors and controls AI agents, catching malicious tool use, pro

  • medusa by Pantheon-Security · ⭐ 962

    AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions

  • pipelock by luckyPipewrench · ⭐ 896

    Firewall for AI agents. DLP scanning, SSRF protection, bidirectional MCP scanning, tool poisoning detection, a

  • zerobox by afshinm · ⭐ 698

    Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with fil

  • toolhive by stacklok · ⭐ 2.2k

    ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Rust Agent Tools

Frequently Asked Questions

What is nono?

nono is nono - a capability-based, multiplexing sandbox tool, built for developers - lift'n'shift seamless path to prod. Run agents securely without needing any additional infra, zero setup, zero latency.. It is categorized as a MCP Server with 2.2k GitHub stars.

What programming language is nono written in?

nono is primarily written in Rust. It covers topics such as agent-sandbox, agent-security, ai-agent-sandbox.

How do I install or use nono?

You can find installation instructions and usage details in the nono GitHub repository at github.com/always-further/nono. The project has 2.2k stars and 157 forks, indicating an active community.

What license does nono use?

nono is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to nono?

The top alternatives to nono on Agent Skills Hub include hol-guard, Adrian, medusa. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools