NanoClaw latches onto Docker Sandboxes for safer AI agents
… "But agents fundamentally are different and they violate that primitive from day one. You launch the agent and the very first thing it wants to do is look at the environment, install new packages, write some files, spin up databases that are mocked. …