Rules for trusted NanoClaw groups. Shared memory, session bootstrap, cross-group memory updates. Loaded for trusted and main containers only.
77
96%
Does it follow best practices?
Impact
—
No eval scenarios have been run
Risky
Do not use without reviewing
The runtime's mount layout is the contract. A read-only-filesystem error on a write to the group folder means you're in an untrusted container.
If a write to /workspace/group/ fails with EROFS / "Read-only file system", do NOT retry. The mount is intentionally RO; the retry will fail the same way.
The full trust-tier capability matrix (mounts, plugins, Composio access, idle timeout, RAM/CPU caps) lives in docs/trust-tier-capabilities.md.
rules
skills
system-status