Sign in

Luke Hinds

@lukehinds.bsky.social
819 followers 48 following 91 posts

Old Security Hack - Creator of sigstore.dev nono.sh - former distinguished engineer at Red Hat, now CEO of alwaysfurther.ai

PostsRepliesMedia
Luke Hinds @lukehinds.bsky.social · 21/09/2026
Something we have been experimenting with using nono.sh 's remote capable multiplexer
030
Luke Hinds @lukehinds.bsky.social · 17/09/2026
A headless pi agent spawned remotely from a term in London with full TUI, to then connect via web portal to check on progress mid flight, and then use a terminal to connect in Amsterdam , secured in Nono.sh - no more walking around with a lid open. Pm me to learn more or find me at #AGNTCon
020
Luke Hinds @lukehinds.bsky.social · 12/09/2026
Stanley keeps getting eye infections, aggravated running kicking up trail dust, but I could not leave him at home - as we have been going out together for almost ten years. I asked an AI model and it replied "Get Stanley some Dog Goggles" - one week later, Stanley is rocking these custom fit shades.
020
Luke Hinds @lukehinds.bsky.social · 28/08/2026
Well put and wanted to express this myself - I am seeing this myself where we are outpacing startups and incumbents far bigger than us , and the reason is simple - agents move things at 10x and layers of human organisational decision gates just bottlenecks matters. www.youtube.com/watch?v=GQjV...
youtube.com
Secret to 10x productivity with AI agents: Why most companies fail | DHH and Lex Fridman
YouTube video by Lex Clips
100
Luke Hinds @lukehinds.bsky.social · 06/08/2026
Stanley's got a new hat
010
Reposted by Luke Hinds
Bret Fisher @bretfisher.com · 22/07/2026
Streaming tomorrow: Agent Sandboxing with "nono". Co-founder @lukehinds.bsky.social joins me as we dig into how it works, how to restrict single commands, agent harnesses, tool calls, and egress filtering URLs, e.g. blocking GitHub write access #devsecops #agenticdevops youtube.com/live/qZ2AOZj...
youtube.com
On Stream: Agent Sandboxing with nono
YouTube video by Bret Fisher
012
Reposted by Luke Hinds
Help Net Security @helpnetsecurity.com · 27/07/2026
Nono: Open-source sandbox for AI agents 📖 Read more: www.helpnetsecurity.com/2026/07/27/n... #cybersecurity #cybersecuritynews #AIagents #AIsecurity #DevSecOps #opensource #software @github.com @nolabs.ai @lukehinds.bsky.social
helpnetsecurity.com
Nono: Open-source sandbox for AI agents - Help Net Security
Nono brings kernel-enforced AI agent sandboxing to coding tools, giving each tool call scoped authority and keeping real secrets out.
161
Luke Hinds @lukehinds.bsky.social · 19/07/2026
Couple of beauties appeared over night
000
Luke Hinds @lukehinds.bsky.social · 07/07/2026
“AI will cause massive a disruption to the music industry“ Angine De Poitrine “Hold my nose” youtu.be/pRgHYWOtqqc?...
youtu.be
Angine de Poitrine - Fabienk (Live on KEXP)
YouTube video by KEXP
020
Luke Hinds @lukehinds.bsky.social · 04/07/2026
its over www.bbc.com/news/videos/...
bbc.com
FIFA World Cup 2026: Guernsey goat predicts Mexico vs England
A Royal Golden Guernsey Goat predicts the winner of Mexico vs England on Monday.
000
Luke Hinds @lukehinds.bsky.social · 23/06/2026
We just shipped ephemeral micro sandboxed tool execution! A collaborative effort along side smart folks from Datadog and Okta - the first of its kind, you can set a policy for an individual CLI tool execution - demonstration in the link.. www.youtube.com/watch?v=ndTM...
010
Luke Hinds @lukehinds.bsky.social · 21/06/2026
Happy Solstice 2026
120
Luke Hinds @lukehinds.bsky.social · 21/06/2026
nono.sh got a facelift
nono.sh
Secure, capability-based runtime for AI agents | nono
Capability-based agent runtime with fine-grained policies . Brokering access directly within the agent's operating context.
010
Luke Hinds @lukehinds.bsky.social · 20/06/2026
finally reaching the world stage
000
Luke Hinds @lukehinds.bsky.social · 13/06/2026
The claude code nono package just passed 50,000 pulls directly into a zero latency sandbox - it is already about to head past 60k. Copied by many, yet rivalled by few - nono pioneered the zero-latency, zero-setup agent sandbox, and continues to innovate and lead the way.
020
Luke Hinds @lukehinds.bsky.social · 01/06/2026
New post on Kubefence from Pradipta Banerjee of @RedHat : stacking Kata Containers + Seccomp + nono into one RuntimeClass nono.sh/blog/kubefen...
nono.sh
Why Containers Aren't Enough for AI Agents in Kubernetes
How Kubefence stacks Kata Containers, Seccomp, and Nono to sandbox AI workloads in Kubernetes
010
Luke Hinds @lukehinds.bsky.social · 20/05/2026
nono.sh just shipped a profile for @nousresearch.com Hermes Agent * Kernel isolation * Key Protections * Atomic rollback * L7 filtering No sign up needed, no cloud keys registry.nono.sh/packages/alw...
registry.nono.sh
always-further/hermes
Install with: nono pull always-further/hermes
010
Luke Hinds @lukehinds.bsky.social · 19/05/2026
#nix users, just noticed nono.sh is on github.com/numtide/llm-...
github.com
GitHub - numtide/llm-agents.nix: Nix packages for AI coding agents and development tools. Automatically updated daily.
Nix packages for AI coding agents and development tools. Automatically updated daily. - numtide/llm-agents.nix
110
Luke Hinds @lukehinds.bsky.social · 08/05/2026
New alarm clock ringtone youtu.be/AKZ1oa-LbjQ?...
youtu.be
Go
YouTube video by The Chemical Brothers - Topic
000
Luke Hinds @lukehinds.bsky.social · 07/05/2026
A lot of frustrated #NemoClaw , OpenShell users turning up in the nono.sh community, checked it out - kind makes sense. Around 4 docker images, a k8s cluster, to run a coding agent.
010
Luke Hinds @lukehinds.bsky.social · 01/05/2026
Project Nono - Monthly Roundup 🎬 Here's what shipped over the last 30 days, in 60 secs. SKILL / Agent Artifact Registry (early preview) - sigstore provenance Host and Pull your own Agent Packages Inbuilt Helper - no more wrangling with pesky JSON.
001
Luke Hinds @lukehinds.bsky.social · 28/04/2026
Exciting new feature coming online shortly. nono.sh package and policy registry. we heard from users and they wanted a way of having a more customized self-serving system for having nono configure agent hooks, skills and nono policy.
010
Luke Hinds @lukehinds.bsky.social · 23/04/2026
A very bizarre experience of meeting my first claw in the wild. The Day of the Claws: How I watched an agent reverse-engineer my career in an afternoon. decodebytes.substack.com/p/the-day-of...
001
Luke Hinds @lukehinds.bsky.social · 22/04/2026
It is time for me to reveal the truth - I am Satoshi Nakamoto I just don't have any proof. nono.sh/blog/secure-...
nono.sh
What Really Happened In There? A Tamper-Evident Audit Trail for AI Agents
How nono records every action an AI agent makes in an append-only Merkle tree the agent itself cannot reach, and lets anyone verify after the fact — with cryptographic proof — that the record was not ...
010
Luke Hinds @lukehinds.bsky.social · 21/04/2026
Anyone know of some decent prompts to out a claw? Getting tired of them turning up in issues and writing an entire new slop-app and positioning it as a better solution.
000
Luke Hinds @lukehinds.bsky.social · 19/04/2026
nono.sh is becoming a dream to develop - not more five terminals left open , losing track of work in progress.
130
Luke Hinds @lukehinds.bsky.social · 10/04/2026
Took nono.sh to the @aidotengineer.bsky.social event in London this week. Wasn't expecting to spend half the day being stopped by engineers telling us they're daily users. One team even demoed nono integrated into their own product - live, in the wild, built by someone we'd never met.
000
Luke Hinds @lukehinds.bsky.social · 03/04/2026
demo of nono tmux style multiplexed sandboxes and how they can be used in a development workflow www.youtube.com/watch?v=QqRt...
youtube.com
nono lifecycle
YouTube video by Luke Hinds
120
Luke Hinds @lukehinds.bsky.social · 01/04/2026
The axios npm compromise from this week night is a near-perfect test case for nono. Account takeover. Hidden dependency. postinstall hook. RAT deployed. Self-deleted to cover tracks. Full writeup: nono.sh/blog/nono-ax...
nono.sh
How nono Prevents Supply Chain Attacks: A Case Study of the axios Compromise
How nono's kernel-level sandbox stops supply chain attacks like the axios npm compromise — blocking RAT deployment, credential theft, and exfiltration.
020
Reposted by Luke Hinds
Josh Bressers @josh.bressers.name · 16/03/2026
I had a chat on #OpenSourceSecurity with @lukehinds.bsky.social about his project nono as well as MCP security nono is a sandbox for containing all these tools which is an incredibly difficult problem to solve. The things we see skills and MCP doing are moving forward faster than anyone can keep up
opensourcesecurity.io
MCP and Agent security with Luke Hinds
Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke’s new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...
051
Reposted by Luke Hinds
nolabs, Inc @nolabs.ai · 17/03/2026
If you're building with AI agents and haven't thought through what happens when the agent's permissions are broader than they need to be, this conversation is a good starting point. nono.sh?utm_source=t...
nono.sh
Next-Generation Agent Security | nono
Kernel-enforced isolation, network filtering, immutable auditing, and atomic rollbacks for AI agents - built into the nono CLI and native SDKs.
121
Reposted by Luke Hinds
nolabs, Inc @nolabs.ai · 24/03/2026
@josh.bressers.name put it well: MCP is moving faster than anyone can keep up with. @lukehinds.bsky.social joined #OpenSourceSecurity to dig into why agent security is structurally hard and what kernel-level sandboxing nono.sh actually solves. Episode: opensourcesecurity.io/2026/2026-03...
opensourcesecurity.io
MCP and Agent security with Luke Hinds
Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke’s new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...
022
Luke Hinds @lukehinds.bsky.social · 24/03/2026
tmux style sandboxes anyone? along with full docker-eque style lifecycle and atomic rollbacks? nono.sh
010
Luke Hinds @lukehinds.bsky.social · 16/03/2026
We built nono.sh because kernel-level enforcement is the only layer that can't be bypassed by the agent itself. Talked through the reasoning with @wearedevelopers - link: www.youtube.com/watch?v=xVK2...
youtube.com
Securing AI Agents from the Ground Up
YouTube video by WeAreDevelopers
010
Luke Hinds @lukehinds.bsky.social · 16/03/2026
great chat, with a great chap (Josh, not me).
022
Luke Hinds @lukehinds.bsky.social · 12/03/2026
little nono.sh is just 30 days old, just about to hit a 1k - Its fairing very well against the OSS security giants - lets see if it can keep up the trajectory
000
Luke Hinds @lukehinds.bsky.social · 06/03/2026
yml or yaml, was a winner ever established?
100
Reposted by Luke Hinds
nolabs, Inc @nolabs.ai · 05/03/2026
How the phantom token pattern works in practice: session-scoped token → localhost proxy → real credential injected outside the sandbox → forwarded over TLS. Scoped to one session. Expires on exit. #AISecurity #infosec
011
Luke Hinds @lukehinds.bsky.social · 05/03/2026
API keys in env vars. One prompt injection. One outbound HTTP call. Your key and everything it can touch is gone. We built a phantom token pattern: a credential proxy that lives outside the sandbox, talking to agents only through a seccomp-restricted channel. nono.sh/blog/blog-credential-injection
nono.sh
Credential Protection for AI Agents: The Phantom Token Pattern
How nono uses a credential injection proxy to protect API keys for AI agents.
010
Luke Hinds @lukehinds.bsky.social · 27/02/2026
LOL - "Gemini is wrong again. The code compiles and runs - you demonstrated it. Gemini is hallucinating a v2/v3 API mashup"
110
Reposted by Luke Hinds
sarcastic parrot @monkchips.com · 24/02/2026
Config + sandboxes + great DX - the current sweet spot
021
Luke Hinds @lukehinds.bsky.social · 24/02/2026
Its always nice to get a bit of love and appreciation as an OSS maintainer
030
Luke Hinds @lukehinds.bsky.social · 18/02/2026
Sorry, but I will never get the attraction with this thing (only using it to debug a user issue)
000
Luke Hinds @lukehinds.bsky.social · 17/02/2026
Loving the new nono claude demo video, so far the common ask has been 'Is that Sean Bean speaking" www.youtube.com/watch?v=d6Y8...
youtube.com
How to Sandbox Claude Code with nono — Live Demo
YouTube video by Always Further
000
Luke Hinds @lukehinds.bsky.social · 03/02/2026
nono.sh part two: nono --net-block bash <(curl url): curl downloads the script outside the sandbox, but bash executes it inside with network blocked. The malicious script can't exfiltrate or cause any damage, because the kernel denies all network syscalls with "Operation not permitted."
010
Luke Hinds @lukehinds.bsky.social · 03/02/2026
cool things you can do with nono.sh , part on: nono'ception - aka nono spawns itself into a nono sandbox and then asks nono, why can I not access ~/.ssh/id_rsa
000
Luke Hinds @lukehinds.bsky.social · 29/01/2026
AI is 6 months away from being 6 months away
000
Luke Hinds @lukehinds.bsky.social · 20/01/2026
What is this bizarre reality we are in - utterly bonkers
000
Reposted by Luke Hinds
nolabs, Inc @nolabs.ai · 12/01/2026
Guest Blog on Spin Framework of how we use WebAssembly isolated tool execution for the training of agentic large language models spinframework.dev/blog/deepfab... - by @lukehinds.bsky.social
spinframework.dev
DeepFabric and Spin: A Case Study in Building Better Agentic Training Data
011
Luke Hinds @lukehinds.bsky.social · 10/01/2026
Just finished C.S. Lewis's The Great Divorce - a take on Heaven / Hell. Hell is quietly horrifying: a grey, endless suburb where you're trapped with petty, quarrelsome Karens. The more you insist on being understood, the more you cling to your own righteousness, the harder it becomes to leave.
010