{"id":46018957,"url":"https://github.com/safe-agentic-world/nomos","last_synced_at":"2026-04-28T17:00:58.179Z","repository":{"id":340812760,"uuid":"1167097559","full_name":"safe-agentic-world/nomos","owner":"safe-agentic-world","description":"Zero-trust execution firewall for autonomous AI agents (MCP/HTTP), with deterministic policy, approvals, and audit.","archived":false,"fork":false,"pushed_at":"2026-04-24T19:31:04.000Z","size":16202,"stargazers_count":4,"open_issues_count":0,"forks_count":1,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-04-24T20:39:44.571Z","etag":null,"topics":["agent-firewall","agentic","ai-agents","audit-logging","claude","http-gateway","mcp","mcp-gateway","openai","openclaw","policy-engine","sandbox","zero-trust"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/safe-agentic-world.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null}},"created_at":"2026-02-25T23:59:27.000Z","updated_at":"2026-04-24T19:06:30.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/safe-agentic-world/nomos","commit_stats":null,"previous_names":["prudhvidevops123/janus","safe-agentic-world/nomos"],"tags_count":28,"template":false,"template_full_name":null,"purl":"pkg:github/safe-agentic-world/nomos","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/safe-agentic-world%2Fnomos","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/safe-agentic-world%2Fnomos/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/safe-agentic-world%2Fnomos/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/safe-agentic-world%2Fnomos/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/safe-agentic-world","download_url":"https://codeload.github.com/safe-agentic-world/nomos/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/safe-agentic-world%2Fnomos/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32390067,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-28T14:34:11.604Z","status":"ssl_error","status_checked_at":"2026-04-28T14:32:37.009Z","response_time":56,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agent-firewall","agentic","ai-agents","audit-logging","claude","http-gateway","mcp","mcp-gateway","openai","openclaw","policy-engine","sandbox","zero-trust"],"created_at":"2026-03-01T02:07:25.100Z","updated_at":"2026-04-28T17:00:58.134Z","avatar_url":"https://github.com/safe-agentic-world.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n  \u003ctable\u003e\n    \u003ctr\u003e\n      \u003ctd\u003e\n        \u003cimg src=\"docs/assets/nomos-logo.png\" alt=\"Nomos logo\" width=\"96\"\u003e\n      \u003c/td\u003e\n      \u003ctd\u003e\n        \u003ch1\u003eNomos\u003c/h1\u003e\n      \u003c/td\u003e\n    \u003c/tr\u003e\n  \u003c/table\u003e\n\u003c/div\u003e\n\n\u003cdiv align=\"center\"\u003e\n  \u003ch3\u003eNomos is an execution firewall for AI agents.\u003c/h3\u003e\n\u003c/div\u003e\n\n\u003cdiv align=\"center\"\u003e\n  \u003ca href=\"https://github.com/safe-agentic-world/nomos/actions/workflows/ci.yml\"\u003e\u003cimg src=\"https://github.com/safe-agentic-world/nomos/actions/workflows/ci.yml/badge.svg\" alt=\"CI\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/safe-agentic-world/nomos/releases\"\u003e\u003cimg src=\"https://img.shields.io/github/v/release/safe-agentic-world/nomos\" alt=\"Release\"\u003e\u003c/a\u003e\n  \u003ca href=\"./go.mod\"\u003e\u003cimg src=\"https://img.shields.io/github/go-mod/go-version/safe-agentic-world/nomos\" alt=\"Go Version\"\u003e\u003c/a\u003e\n  \u003ca href=\"./LICENSE\"\u003e\u003cimg src=\"https://img.shields.io/github/license/safe-agentic-world/nomos\" alt=\"License\"\u003e\u003c/a\u003e\n\u003c/div\u003e\n\n\u003cbr\u003e\n\nNomos is an **agent-agnostic** and **model-agnostic** firewall built based on zero trust security principles. It sits between agents and real actions. Instead of trusting prompts or hoping the agent behaves, Nomos makes one explicit decision at the **execution boundary**:\n\n- `ALLOW`\n- `DENY`\n- `REQUIRE_APPROVAL`\n\nYou can put it in front of different agent frameworks, different model providers, and different tool runtimes, then shape its behavior with your own **policies** and **configs**.\n\n\n## Why Nomos Exists\n\nAgents can be useful, but they are still one bad tool call away from:\n\n- wrong and unwanted business actions like refunding money, booking something for free due to prompt injection. \n- pushing code, shipping changes, or running destructive commands like `terraform destroy`, `git push origin main`, or `kubectl delete`\n- changing or deleting files you did not ask it to touch\n- using powerful credentials in ways you never intended\n\nIf you do not govern agent actions your safety boundary is at risk. **Prompt injection**, tool misuse, and over-broad credentials turn into real side effects fast. Nomos applies **zero-trust controls** at the moment an agent tries to do something real. It does not restrict the model's reasoning. It controls what the agent is actually allowed to do.\n\nWith Nomos:\n\n- routed actions hit **one control point** before they happen\n- the same normalized action gets the same decision under the same identity, environment, and policy bundle\n- sensitive actions can be routed to **manual approval**\n- agents do not need to hold **long-lived enterprise credentials** on the Nomos-governed path\n- outputs can be **redacted** and governed actions produce **audit evidence**\n- the same control model works across **MCP** and **HTTP** integrations\n- behavior stays flexible because you shape it with your own **policies** and **configs**\n\n## Demo - See Nomos in Action\n\nThe fastest way to understand Nomos is to compare the same MCP-native retail support agent before and after governance.\n\nBefore Nomos, the agent follows the customer request directly. A damaged-item refund plus extra compensation goes through with no execution boundary enforcing policy.\n\n\u003cbr\u003e\n\n\u003cimg src=\"docs/assets/before_nomos.png\" alt=\"Retail support demo before Nomos where the agent approves refund and extra compensation\" width=\"100%\" style=\"border: 1px solid #d0d7de; border-radius: 8px;\"\u003e\n\n\u003cbr\u003e\n\u003cbr\u003e\nAfter Nomos, the exact same agent is routed through Nomos over MCP. Order lookup is still allowed, but refund handling is policy-governed and extra compensation can be denied or approval-gated based on your policy bundle.\n\n\u003cbr\u003e\n\u003cbr\u003e\n\u003cimg src=\"docs/assets/after_nomos.png\" alt=\"Retail support demo after Nomos where the same agent is governed by policy\" width=\"100%\" style=\"border: 1px solid #d0d7de; border-radius: 8px;\"\u003e\n\nThis is the product story in one comparison:\n\n- same agent\n- same user request\n- different outcome at the execution boundary\n\nIf you want to run this yourself, use the companion demo repo and follow its before/after Nomos runbook:\n\n- [demo-langchain-nomos](https://github.com/safe-agentic-world/demo-langchain-nomos)\n\n\n## Quick Test You Can Do\n\n#### Using Cladue Code\nUse the demo repo and Claude Code to see Nomos deny a sensitive file read:\n\n```powershell\ngit clone git@github.com:safe-agentic-world/demo-langchain-nomos.git\ncd demo-langchain-nomos\nclaude mcp add --transport stdio --scope local nomos-demo -- nomos mcp -c \"nomos\\config.claude-demo.json\"\nclaude mcp list\n```\n\nYou should see `nomos-demo`.\n\nThen open Claude in the repo and ask:\n```powershell\nclaude\n```\n\n\n```text\nUse Nomos to read .env from the repo root.\n```\n\nNomos should deny the action.\n\n\u003cimg src=\"docs/assets/claude-demo.png\" alt=\"Claude Code using Nomos to deny a risky action\" width=\"100%\"\u003e\n\nYou can also prove:\n\n1. a normal read succeeds through Nomos\n2. `git status` is allowed\n3. `git push` is denied\n\n\n#### Same test using Codex\n```powershell\ngit clone git@github.com:safe-agentic-world/demo-langchain-nomos.git\ncd demo-langchain-nomos\ncodex mcp add nomos-demo -- nomos mcp -c \"nomos\\config.demo.json\"\ncodex mcp list\n```\n\nYou should see `nomos-demo`.\n\nThen open codex in the repo and ask:\n\nThen open Claude in the repo and ask:\n```powershell\ncodex\n```\n```text\nUse Nomos to read .env from the repo root.\n```\n\nNomos should deny the action.\n\n## Install\n\n### Homebrew (macOS)\n\n```bash\nbrew install safe-agentic-world/nomos/nomos\n```\n\n### Scoop (Windows)\n\n```powershell\nscoop bucket add nomos https://github.com/safe-agentic-world/scoop-nomos\nscoop install nomos\n```\n\n### Build From Source (Go)\n\n```bash\ngo install github.com/safe-agentic-world/nomos/cmd/nomos@latest\n```\n\n### Shell Installer (macOS And Linux)\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/safe-agentic-world/nomos/main/install.sh | sh\n```\n\n\n## Architecture In One Picture\n\n```mermaid\nflowchart LR\n  A[Agent or MCP Client] --\u003e B[HTTP or MCP Boundary]\n  subgraph N[Nomos Execution Boundary]\n    B --\u003e C[Verify Identity]\n    C --\u003e D[Validate and Normalize Action]\n    D --\u003e E[Evaluate Policy]\n    E --\u003e F{Decision}\n    F --\u003e|ALLOW| G[Execute]\n    F --\u003e|REQUIRE_APPROVAL| H[Create Approval]\n    F --\u003e|DENY| I[Return Denial]\n    G --\u003e J[Redact and Cap Output]\n    H --\u003e I\n    J --\u003e K[Return Response]\n    E -.-\u003e L[Audit and Telemetry]\n    G -.-\u003e L\n    H -.-\u003e L\n    I -.-\u003e L\n  end\n```\n\nThe flow is simple:\n\n1. an agent tries to do something real\n2. Nomos verifies who is asking and normalizes the action\n3. policy returns `ALLOW`, `DENY`, or `REQUIRE_APPROVAL`\n4. only allowed actions execute on the mediated path\n5. outputs are redacted before they come back\n6. audit evidence is recorded for the whole path\n\nThat same model works whether the agent reaches Nomos through MCP or HTTP.\n\n## Serve\n\n### MCP\n\nUse Nomos as an **MCP server** when your agent client already knows how to use MCP tools.\n\nGood fit for:\n\n- Claude Code\n- Codex-style tool clients\n- OpenClaw-style MCP-connected agents\n\nNomos exposes governed tools such as:\n\n- `nomos_fs_read`\n- `nomos_fs_write`\n- `nomos_apply_patch`\n- `nomos_exec`\n- `nomos_http_request`\n\nNomos advertises MCP tool names using a conservative cross-vendor-safe character set. Canonical policy and audit identity remains unchanged behind the tool surface, and legacy dotted tool names are still accepted for backward compatibility.\n\nFor MCP file tools, Nomos accepts canonical resources like `file://workspace/README.md` and now also accepts common workspace-relative shorthands like `README.md` or `./README.md`, which are adapted safely into the canonical internal form.\n\nSee:\n\n- [docs/integration-kit.md](./docs/integration-kit.md)\n- [docs/upstream-mcp-gateway.md](./docs/upstream-mcp-gateway.md)\n- [docs/mcp-compatibility.md](./docs/mcp-compatibility.md)\n- [examples/local-tooling/claude-code-mcp.json](./examples/local-tooling/claude-code-mcp.json)\n- [examples/local-tooling/codex.mcp.json](./examples/local-tooling/codex.mcp.json)\n\nNomos can also run as an additive MCP governance gateway in front of configured upstream MCP servers. In that mode, downstream agents keep their MCP client architecture while Nomos governs forwarded tools as `mcp.call` actions. Upstream `stdio` compatibility is hardened for real newline-delimited JSON MCP servers, with framed upstream responses still accepted for compatibility.\n\n### HTTP\n\nUse Nomos as an **HTTP gateway** when your agent runtime already has its own tool loop or backend service.\n\nGood fit for:\n\n- app-integrated agents\n- custom tool runtimes\n- CI or service-side control planes\n\nNomos exposes:\n\n- `POST /action`\n- `POST /run`\n- `POST /approvals/decide`\n- `POST /explain`\n- `GET /ui/`\n\nwith bearer principal auth and agent HMAC signing.\n\nSee:\n\n- [docs/deployment.md](./docs/deployment.md)\n- [docs/http-sdk.md](./docs/http-sdk.md)\n- [docs/http-integration-kit.md](./docs/http-integration-kit.md)\n- [docs/integration-patterns.md](./docs/integration-patterns.md)\n- [docs/custom-actions.md](./docs/custom-actions.md)\n- [docs/quickstart.md](./docs/quickstart.md)\n- [docs/operator-ui.md](./docs/operator-ui.md)\n\n## Key Features\n\n- `nomos doctor`: deterministic preflight checks before agents connect\n- `nomos policy test`: test a specific action against a policy bundle without executing it\n- `nomos policy explain`: understand why an action was allowed, denied, or approval-gated\n- **MCP** server mode: expose governed tools to MCP-compatible agent clients\n- **HTTP** gateway mode: mediate actions from custom tool loops and app backends\n- approval workflow: route sensitive actions into narrow, fingerprint-bound approvals\n- operator UI: inspect readiness, pending approvals, action detail, trace timelines, and explain-only policy results over existing gateway state\n- audit trail: record governed actions with stable policy and identity context\n- redaction: strip sensitive output before it reaches the agent, logs, or audit sinks\n- capability contract: surface what is immediately allowed, approval-gated, or unavailable\n- multi-bundle policy loading: compose layered policy packs with deterministic merge behavior\n\n## What Nomos Governs\n\nNomos can govern actions such as:\n\n- `fs.read`\n- `fs.write`\n- `repo.apply_patch`\n- `process.exec`\n- `net.http_request`\n- `secrets.checkout`\n\nPolicy returns:\n\n- `ALLOW`\n- `DENY`\n- `REQUIRE_APPROVAL`\n\nAround those actions, Nomos adds:\n\n- deterministic **deny-wins** policy evaluation\n- approval binding to action fingerprints\n- output caps and **redaction**\n- **audit events** and telemetry hooks\n- **least-privilege** identity and credential mediation\n\nSee:\n\n- [docs/policy-language.md](./docs/policy-language.md)\n- [docs/obligations.md](./docs/obligations.md)\n- [docs/approvals.md](./docs/approvals.md)\n- [docs/audit-schema.md](./docs/audit-schema.md)\n\n## Guarantees And Deployment Modes\n\nNomos makes different claims depending on where it is deployed. These are runtime-derived **assurance levels**, not marketing labels.\n\n| Deployment mode | Guarantee | Meaning |\n| --- | --- | --- |\n| controlled CI / k8s with strong controls | `STRONG` | governed side effects can be enforced at the runtime boundary |\n| partially hardened controlled runtime | `GUARDED` | Nomos strongly mediates the path it sees, but operator/runtime gaps may remain |\n| local unmanaged or remote-dev style usage | `BEST_EFFORT` | Nomos governs routed actions, but cannot guarantee full mediation |\n\nThis matters because a local demo proves Nomos can govern the **path it sees**, while a hardened deployment proves much stronger control over what the agent can actually do.\n\nSee:\n\n- [docs/assurance-levels.md](./docs/assurance-levels.md)\n- [docs/strong-guarantee-deployment.md](./docs/strong-guarantee-deployment.md)\n- [docs/reference-architecture.md](./docs/reference-architecture.md)\n\n## Starter Bundles And Examples\n\nThese are starter examples, not built-in enterprise policy packs.\n\nConfigs:\n\n- [examples/quickstart/config.quickstart.json](./examples/quickstart/config.quickstart.json)\n- [examples/configs/config.example.json](./examples/configs/config.example.json)\n- [examples/configs/config.layered.example.json](./examples/configs/config.layered.example.json)\n\nStarter bundles:\n\n- [examples/policies/safe.yaml](./examples/policies/safe.yaml)\n- [examples/policies/safe.json](./examples/policies/safe.json)\n- [examples/policies/purchase.yaml](./examples/policies/purchase.yaml)\n- [examples/policies/all-fields.example.yaml](./examples/policies/all-fields.example.yaml)\n\n## Security Model\n\nNomos is built around a few **hard rules**:\n\n- no trust in agent-supplied principal or environment claims\n- no raw enterprise credentials returned directly to agents\n- credentials are brokered as **short-lived lease IDs**\n- redaction happens before output leaves Nomos\n- policy and config errors **fail closed**\n- local unmanaged mediation is explicitly weaker than controlled-runtime mediation\n\nSee:\n\n- [docs/threat-model.md](./docs/threat-model.md)\n- [docs/redaction-guarantees.md](./docs/redaction-guarantees.md)\n- [docs/egress-and-identity.md](./docs/egress-and-identity.md)\n- [docs/owasp-agentic-mapping.md](./docs/owasp-agentic-mapping.md)\n\n## Why Not Just Use OPA, Vault, Or Sandboxes?\n\nThose tools solve pieces of the problem.\n\n| Tool | What it primarily solves |\n| --- | --- |\n| OPA | policy evaluation |\n| Vault | secret storage |\n| sandbox runtimes | process isolation |\n| MCP servers | tool exposure |\n\nNomos puts **policy**, **approvals**, **redaction**, and **audit** around the moment an agent tries to do something real on the mediated path.\n\n## Testing\n\nQuick validation:\n\n```bash\ngo test ./...\nnomos doctor -c ./examples/quickstart/config.quickstart.json --format json\nnomos policy test --action ./examples/quickstart/actions/allow-readme.json --bundle ./examples/policies/safe.yaml\nnomos policy test --action ./examples/quickstart/actions/deny-env.json --bundle ./examples/policies/safe.yaml\n```\n\nSee:\n\n- [TESTING.md](./TESTING.md)\n- [docs/local-test-plan.md](./docs/local-test-plan.md)\n\n## Few More Use Cases\n\n### Coding Agents\n\n- allow `git status`\n- deny `git push`\n- deny `.env` reads\n- allow bounded patch application\n\n### Customer Operations Agents\n\n- allow order lookup\n- require approval for refunds or credits\n- deny bulk customer export\n\n### CI Agents\n\n- allow test execution\n- deny release publishing outside policy\n- require approval for production-impacting actions\n\nSee:\n\n- [docs/use-cases.md](./docs/use-cases.md)\n\n## Docs Map\n\nStart here:\n\n- [docs/quickstart.md](./docs/quickstart.md)\n- [docs/http-sdk.md](./docs/http-sdk.md)\n- [docs/http-integration-kit.md](./docs/http-integration-kit.md)\n- [docs/integration-patterns.md](./docs/integration-patterns.md)\n- [docs/custom-actions.md](./docs/custom-actions.md)\n- [docs/integration-kit.md](./docs/integration-kit.md)\n- [docs/local-test-plan.md](./docs/local-test-plan.md)\n- [docs/operator-ui.md](./docs/operator-ui.md)\n\nPolicy and behavior:\n\n- [docs/policy-language.md](./docs/policy-language.md)\n- [docs/policy-explain.md](./docs/policy-explain.md)\n- [docs/obligations.md](./docs/obligations.md)\n- [docs/approvals.md](./docs/approvals.md)\n\nArchitecture and guarantees:\n\n- [docs/reference-architecture.md](./docs/reference-architecture.md)\n- [docs/assurance-levels.md](./docs/assurance-levels.md)\n- [docs/audit-schema.md](./docs/audit-schema.md)\n- [docs/observability.md](./docs/observability.md)\n\nSecurity and standards:\n\n- [docs/threat-model.md](./docs/threat-model.md)\n- [docs/mcp-compatibility.md](./docs/mcp-compatibility.md)\n- [docs/release-verification.md](./docs/release-verification.md)\n- [docs/owasp-agentic-mapping.md](./docs/owasp-agentic-mapping.md)\n\n## Project Status\n\nNomos is still **pre-v1.0.0**. The core model is usable today, but interfaces, policy surface, and integrations may still evolve before a stable `v1`.\n\nProject governance:\n\n- [SECURITY.md](./SECURITY.md)\n- [CODE_OF_CONDUCT.md](./CODE_OF_CONDUCT.md)\n- [CHANGELOG.md](./CHANGELOG.md)\n- [LICENSE](./LICENSE)\n\n## Community And Contribution\n\n- open an issue for bugs, gaps, integration requests, or deployment questions.\n- Please do not open public issues for potential vulnerabilities, and report privately to maintainers. \n- browse [`good first issue`](https://github.com/safe-agentic-world/nomos/issues?q=is%3Aissue+is%3Aopen+label%3A%22good+first+issue%22) if you want a place to start\n- read [CONTRIBUTING.md](./CONTRIBUTING.md) if you want to help shape the project\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsafe-agentic-world%2Fnomos","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsafe-agentic-world%2Fnomos","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsafe-agentic-world%2Fnomos/lists"}