researchclaw-dedicated-container-not-inside-hermes

AutoResearchClaw MUST run in a dedicated container (researchclaw) on oracle-network, NOT installed inside the oracle-hermes container. AutoResearchClaw executes generated experiment code that requires sandboxing — running it inside Hermes would create both security risk and Python dependency conflicts. The dedicated container uses Docker-in-Docker or host Docker socket for its own experiment sandbox containers, matching the existing oracle-* topology pattern.