Nono: A secure, kernel-enforced capability sandbox for AI agents | Dark Hacker News