Run NanoClaw in Docker Sandboxes

Don't trust AI agents