3 ms·
We have taken to letting our agents use specific CLIs directly and we narrow down their access control with nono tool sandboxing via a customized Pi agent runni
by trickleup 24d ago
We have taken to letting our agents use specific CLIs directly and we narrow down their access control with nono tool sandboxing via a customized Pi agent running headless. We have one agent that can use the aws CLI and nono feeds in a phantom SigV4 credential and then policy limits to just read-only http methods and certain L7 filtering on paths to limit its abilities - this means we can have it monitor and debug deployment failures without it doing any damage.
It was all largely based off this example https://github.com/nolabs-ai/nono/tree/main/tool-sandbox-examples/aws-cli https://github.com/nolabs-ai/nono/tree/main/tool-sandbox-exa...
- 0x696C6961 24d agoHow is this better than using MCP?