NanoClaw Adopts OneCLI Agent Vault

Run NanoClaw in Docker Sandboxes

Don't trust AI agents