researchclaw-must-run-in-dedicated-container-for-experiment-sandboxing
AutoResearchClaw executes generated experiment code as part of its 23-stage pipeline. This MUST run in a dedicated isolated container (not installed inside oracle-hermes) to prevent dependency conflicts and contain arbitrary code execution. The container sits on oracle-network alongside oracle-hermes, oracle-mirofish, and oracle-graphiti-mcp. Docker-in-Docker or host Docker socket mounting is required for ResearchClaw’s internal experiment sandbox containers.
Related
- autoresearchclaw-requires-dedicated-container-for-sandbox
- autoresearchclaw-requires-dedicated-container-sandbox
- autoresearchclaw-must-run-in-isolated-container-not-hermes
- researchclaw-dedicated-container-oracle-network-deployment
- autoresearchclaw-requires-dedicated-container-for-experiment
- oracle-researchclaw-dedicated-container-rationale
- researchclaw-dedicated-container-isolation-requirement
- researchclaw-dedicated-container-required-for-experiment-san
- researchclaw-must-run-in-dedicated-container-for-sandboxing
- researchclaw-dedicated-container-oracle-network-topology