Loading…
Tuesday October 6, 2026 16:05 - 16:25 CEST
We give agents our full filesystem permissions because that is how Unix works. We give them network access because they need to call APIs. We give them access to credentials and shell history not because they need any of it, but because we have not built the tooling to say: you can have this, but not that.

This talk is about building that tooling, shipping it, and being honest about what it does and does not solve.

nono enforces per-tool-call restrictions at the kernel level using Linux Landlock. Real credentials never exist inside the agent's execution context. The audit log is written by a process outside the sandbox that the agent cannot reach. The kernel does not negotiate. Once the sandbox is applied it is irreversible.

We show it working in production: Kubefence, a Red Hat Kubernetes NRI plugin, and the nono-py integration being merged into Microsoft's agent-governance-toolkit. The Secure Agentic Framework gives us a shared language for which attack classes this addresses. We will walk through that map carefully because an accurate map is needed for an agentic security model.
Speakers
avatar for Sal Kimmich

Sal Kimmich

Security Architect, NoLabs
Sal Kimmich is a Security Architect and AI Governance Consultant working at the intersection of open source security and agentic systems. They contribute to the Confidential Computing Consortium, OpenSSF, CHAOSS, and CNCF, with a focus on runtime enforcement and supply chain integrity... Read More →
Tuesday October 6, 2026 16:05 - 16:25 CEST
South Hall 3B-3C

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link