researchclaw-experiment-sandbox-mandatory-dedicated-container

AutoResearchClaw executes generated experiment code during its pipeline, which MUST be sandboxed. A shared container with ORACLE Hermes is not viable — dependency conflicts and security isolation both require a dedicated researchclaw container. The container uses Docker-in-Docker or mounts the host Docker socket to spawn its own experiment sandbox containers.