oracle-researchclaw-dedicated-container-rationale

AutoResearchClaw must run in a dedicated container (not inside oracle-hermes) because it executes generated experiment code that requires sandboxing isolation. Coupling it with Hermes risks dependency conflicts and removes the safety boundary for arbitrary code execution. The container joins oracle-network alongside oracle-hermes, oracle-mirofish, and oracle-graphiti-mcp.