6 ms·
We have taken to letting our agents use specific CLIs directly and we narrow down their access control with nono tool sandboxing via a customized Pi agent runni
by trickleup 14d ago
We have taken to letting our agents use specific CLIs directly and we narrow down their access control with nono tool sandboxing via a customized Pi agent running headless. We have one agent that can use the aws CLI and nono feeds in a phantom SigV4 credential and then policy limits to just read-only http methods and certain L7 filtering on paths to limit its abilities - this means we can have it monitor and debug deployment failures without it doing any damage.
It was all largely based off this example https://github.com/nolabs-ai/nono/tree/main/tool-sandbox-examples/aws-cli https://github.com/nolabs-ai/nono/tree/main/tool-sandbox-exa...
- 0x696C6961 14d agoHow is this better than using MCP?