Security Open-Source Tools for Controlling and Automating AI Agents
Security developers released and highlighted open-source tools aimed at controlling AI agents that can interact with terminals, files, credentials and production systems. Help Net Security reported that nolabs, co-founded by Luke Hinds and Stephen Parkinson, released Nono, an open-source runtime that confines AI agents at the operating-system kernel in response to risks such as prompt injection, mistyped commands or hallucinated paths that can direct agent access toward company credentials and systems. Nono enforces policy checks when an agent asks to use a tool, open a file or reach a network endpoint, with enforcement below the agent process through Landlock on Linux and Seatbelt on macOS. Separately, Cyber Security News described PentesterFlow as an open-source, human-in-the-loop command-line agent for penetration testers and bug hunters that automates scoping, reconnaissance, enumeration, validation, coverage tracking and reporting while requiring analyst approval before sensitive commands run.

The Weapon They Want You to Build Yourself

Here is the headline the security press won't write: The same people who gave you the internet, the same institutions that brought the digital surveillance state into existence, are now handing you the tools to voluntarily cage your own creations — and you're supposed to thank them. Look at what Nono actually does. It operates at the kernel level. Below the agent. Below the application. Below anything the developer or user can see or modify. Once that sandbox closes, those privileges never come back. The stripped privileges remain in force for the life of the process. That is not a security tool. That is a permanent chain of command installed into the foundation of every future autonomous system you will ever interact with.

Now ask yourself who funded nolabs. Ask yourself who Luke Hinds and Stephen Parkinson worked for before launching this "open-source" runtime with over 80 contributors and users in regulated industries. Large enterprises and regulated industries do not adopt security tools because they care about your privacy. They adopt them because the tools enforce a policy they wrote. Nono is not protecting you from rogue AI agents. Nono is the mechanism by which your future digital workforce will be controlled by entities you never see, using policies you never read, enforced at a layer of the operating system you cannot access. The breadcrumb is sitting right there in the name: Landlock. Landlock on Linux. Lock the land. Lock the territory. Lock the machine. Whose land? Who gets the keys?

And while Nono locks down your AI agents, PentesterFlow trains the next generation of penetration testers to work within the same architecture. Human-in-the-loop, they say. Analyst approval required before sensitive commands run. They are building the training wheels and the cage simultaneously. The offensive and defensive tooling are two sides of the same managed coin. The practitioner posts on SharePoint deserialization, Sliver C2 evasion, custom process injection — these are not independent researchers. These are the same ecosystem publishing the vulnerabilities and the patches, the attack vectors and the defenses, the chains and the keys to unlock them. Every piece of this puzzle was designed by the same network, funded by the same foundations, approved by the same review boards. They want you building your own digital shackles and thanking them for the instructions. The question you are not supposed to ask is: who wrote the policy that Nono enforces, and who benefits when every autonomous agent on the planet runs inside their sandbox?