Sign in

nolabs, Inc

@nolabs.ai
21 followers 54 following 14 posts

nolabs, the agent security experts.

PostsRepliesMedia
nolabs, Inc @nolabs.ai · 07/04/2026
We'll be at AI Engineer Europe (London, 8–10 April) to talk kernel-level sandboxing and cryptographic provenance for agentic systems. Book time with @lukehinds.bsky.social and @scparkinson.bsky.social: nono.sh/book
nono.sh
Nono at AI Engineer Europe
000
nolabs, Inc @nolabs.ai · 02/04/2026
The axios case: a postinstall hook that ran with full user permissions, no prompt, no sandbox. nono confines npm install to what it actually needs. No C2. No system paths. No credential access. nono.sh/blog/nono-axios
nono.sh
How nono Prevents Supply Chain Attacks: A Case Study of the axios Compromise
How nono's kernel-level sandbox stops supply chain attacks like the axios npm compromise — blocking RAT deployment, credential theft, and exfiltration.
010
nolabs, Inc @nolabs.ai · 01/04/2026
nono v0.26.0 is out: kernel-enforced agent sandboxing, now on Windows via WSL2. Same Landlock enforcement as native Linux. 84% feature parity. The gap is a WSL2 kernel bug, not nono. nono.sh/blog/nono-wsl2-windows-support
nono.sh
nono Now Runs on Windows: Kernel-Enforced Sandboxing via WSL2
nono v0.26.0 brings kernel-enforced sandboxing to Windows via WSL2. Landlock isolation, network filtering, credential injection, and undo — all working on Windows.
000
nolabs, Inc @nolabs.ai · 27/03/2026
Kexin wrapped a GitHub triage bot with nono and documented what each feature does. Sandbox profile. Signed instruction file. Phantom token credential injection - real tokens never enter the sandboxed. Security comes from the launch wrapper. launched.https://nono.sh/blog/wrapping-github-bot-with-nono
000
nolabs, Inc @nolabs.ai · 24/03/2026
@josh.bressers.name put it well: MCP is moving faster than anyone can keep up with. @lukehinds.bsky.social joined #OpenSourceSecurity to dig into why agent security is structurally hard and what kernel-level sandboxing nono.sh actually solves. Episode: opensourcesecurity.io/2026/2026-03...
opensourcesecurity.io
MCP and Agent security with Luke Hinds
Josh talks to Luke Hinds, CEO of Always Further, about MCP and agent security. We start out talking about Luke’s new tool, nono which is a sandboxing tool that has AI agents in mind as a use case. We ...
022
nolabs, Inc @nolabs.ai · 17/03/2026
If you're building with AI agents and haven't thought through what happens when the agent's permissions are broader than they need to be, this conversation is a good starting point. nono.sh?utm_source=t...
nono.sh
Next-Generation Agent Security | nono
Kernel-enforced isolation, network filtering, immutable auditing, and atomic rollbacks for AI agents - built into the nono CLI and native SDKs.
121
nolabs, Inc @nolabs.ai · 06/03/2026
Most AI coding agents run with your full user permissions - SSH keys, AWS credentials, API tokens all exposed. nono is a kernel-level sandbox that changes this. Filesystem, network, and credentials enforced outside the agent's trust domain. nono.sh #AISecurity #infosec #opensource
nono.sh
nono - Next-Generation Agent Security
Kernel-enforced isolation, network filtering, immutable auditing, and atomic rollbacks for AI agents - built into the nono CLI and native SDKs.
010
nolabs, Inc @nolabs.ai · 05/03/2026
How the phantom token pattern works in practice: session-scoped token → localhost proxy → real credential injected outside the sandbox → forwarded over TLS. Scoped to one session. Expires on exit. #AISecurity #infosec
011
nolabs, Inc @nolabs.ai · 04/03/2026
Threat model most teams miss: AI agent API keys sit in /proc/PID/environ on Linux - readable by any same-user process. One prompt injection away from exfiltration. nono's credential proxy: the agent never holds real keys. nono.sh/blog/blog-credential-injection #AISecurity #infosec #opensource
nono.sh
Credential Protection for AI Agents: The Phantom Token Pattern
How nono uses a credential injection proxy to protect API keys for AI agents.
020
nolabs, Inc @nolabs.ai · 12/01/2026
Guest Blog on Spin Framework of how we use WebAssembly isolated tool execution for the training of agentic large language models spinframework.dev/blog/deepfab... - by @lukehinds.bsky.social
spinframework.dev
DeepFabric and Spin: A Case Study in Building Better Agentic Training Data
011
nolabs, Inc @nolabs.ai · 06/01/2026
How do you train an SEO-focused agent from scratch? Our co-founder Stephen Parkinson covers the full process - dataset generation, live tool execution setup, and more. Part two dropping soon. deepfabric.dev
011
nolabs, Inc @nolabs.ai · 02/01/2026
Fine Tune a 4B Model to Beat Claude and Gemini at Tool Calling for free on Google Colab! www.alwaysfurther.ai/blog/train-4...
000
Reposted by nolabs, Inc
Luke Hinds @lukehinds.bsky.social · 04/12/2025
huggingface.co/blog/lukehin... @alwaysfurther.ai
huggingface.co
DeepFabric, advanced synthetic creation for Model Behavior Training
A Blog post by Luke Hinds on Hugging Face
001
nolabs, Inc @nolabs.ai · 04/12/2025
Latest Blog on why relying on system prompts as guardrails could let you down www.alwaysfurther.ai/blog/system-...
011
nolabs, Inc @nolabs.ai · 01/12/2025
We're out of stealth! Today we're announcing Always Further and our $1.8M pre-seed to deliver precise, secure and reliable open language models. More soon. Let's build 🚀 www.alwaysfurther.ai/blog/announc...
alwaysfurther.ai
Announcing Always Further and our Pre-Seed Investment
011