researchclaw-dedicated-container-isolation-requirement

AutoResearchClaw must run in a dedicated container (not inside oracle-hermes) because it executes generated experiment code during the pipeline — sandboxed execution is a hard requirement. The container joins oracle-network alongside oracle-hermes, oracle-mirofish, and oracle-graphiti-mcp. Docker-in-Docker or host Docker socket binding is needed for AutoResearchClaw’s own experiment sandbox containers.