Luke Hinds
@lukehinds
Old Security Hack - Creator of - former distinguished engineer at Red Hat, now CEO of alwaysfurther.ai
We just shipped ephemeral micro sandboxed tool execution! A collaborative effort along side smart folks from Datadog and Okta - the first of its kind, you can set a policy for an individual CLI tool execution - demonstration in the link.. www.youtube.com/watch?v=ndTM...
The claude code nono package just passed 50,000 pulls directly into a zero latency sandbox - it is already about to head past 60k. Copied by many, yet rivalled by few - nono pioneered the zero-latency, zero-setup agent sandbox, and continues to innovate and lead the way.
A lot of frustrated #NemoClaw , OpenShell users turning up in the nono.sh community, checked it out - kind makes sense. Around 4 docker images, a k8s cluster, to run a coding agent.
Project Nono - Monthly Roundup 🎬 Here's what shipped over the last 30 days, in 60 secs. SKILL / Agent Artifact Registry (early preview) - sigstore provenance Host and Pull your own Agent Packages Inbuilt Helper - no more wrangling with pesky JSON.
Exciting new feature coming online shortly. nono.sh package and policy registry. we heard from users and they wanted a way of having a more customized self-serving system for having nono configure agent hooks, skills and nono policy.
A very bizarre experience of meeting my first claw in the wild. The Day of the Claws: How I watched an agent reverse-engineer my career in an afternoon. decodebytes.substack.com/p/the-day-of...
nono.sh is becoming a dream to develop - not more five terminals left open , losing track of work in progress.
Took nono.sh to the @aidotengineer.bsky.social event in London this week. Wasn't expecting to spend half the day being stopped by engineers telling us they're daily users. One team even demoed nono integrated into their own product - live, in the wild, built by someone we'd never met.
tmux style sandboxes anyone? along with full docker-eque style lifecycle and atomic rollbacks? nono.sh
little nono.sh is just 30 days old, just about to hit a 1k - Its fairing very well against the OSS security giants - lets see if it can keep up the trajectory
LOL - "Gemini is wrong again. The code compiles and runs - you demonstrated it. Gemini is hallucinating a v2/v3 API mashup"
Its always nice to get a bit of love and appreciation as an OSS maintainer
Sorry, but I will never get the attraction with this thing (only using it to debug a user issue)
nono.sh part two: nono --net-block bash <(curl url): curl downloads the script outside the sandbox, but bash executes it inside with network blocked. The malicious script can't exfiltrate or cause any damage, because the kernel denies all network syscalls with "Operation not permitted."
cool things you can do with nono.sh , part on: nono'ception - aka nono spawns itself into a nono sandbox and then asks nono, why can I not access ~/.ssh/id_rsa
How we trained a 4b SLM to outperform Claude Sonnet 2.5 and Gemini 2.5 pro at Tool Calling - run on a free T4 GPU on Google Colab: colab.research.google.com/drive/1EG1V4...
DeepFabric now supports live tool execution during dataset generation, isolated within web-assembly components care of the @cncf.io spinframework- this produces training data with far less hallucinations and encourages more reactive learning patterns during SFT or RL based training.
Claude Code really likes using python asserts outside of tests, which is proper insanity. When compiling to optimised byte code, python asserts are ignored. This will mean a lot of code running in production, where assert style logic will be completely removed from the code.
In remembrance today at the 11th hour - "eyes-on" Rifles, fallen, but not forgotten.
I generated a 3k chain-of-thought reasoning dataset on infrastructure outages. huggingface.co/datasets/luk...
This is the first time I have not seen a cookie banner and not said 'go do one' and instead wanted to keep it open
This is so wonderful to see. Jade Leung is the new Prime Minister’s AI adviser. ❤️ Jade was the CTO of the UK's AI Security Institute for AI. The Governance Lead at OpenAI, focusing on secure / safe evals. Head of R&D at the Centre for the Governance of AI at the University of Oxford!