researchclaw-must-run-in-dedicated-container-for-experiment-sandboxing

AutoResearchClaw executes generated experiment code as part of its 23-stage pipeline. This MUST run in a dedicated isolated container (not installed inside oracle-hermes) to prevent dependency conflicts and contain arbitrary code execution. The container sits on oracle-network alongside oracle-hermes, oracle-mirofish, and oracle-graphiti-mcp. Docker-in-Docker or host Docker socket mounting is required for ResearchClaw’s internal experiment sandbox containers.