researchclaw-dedicated-container-required-for-sandbox

AutoResearchClaw MUST run in its own dedicated Docker container (not inside oracle-hermes) because it executes generated experiment code that requires sandbox isolation. Coupling it to the Hermes container risks dependency conflicts and breaks the experiment safety boundary. The container needs Docker-in-Docker or access to the host Docker socket for its own nested experiment containers.