nono crate is the foundational Rust library that provides:
- CapabilitySet - Builder for defining filesystem and network capabilities
- Sandbox - OS-level sandbox enforcement via Landlock (Linux) and Seatbelt (macOS)
- FFI bindings - C API for language bindings (Python, TypeScript)