Rules for trusted NanoClaw groups. Shared memory, session bootstrap, cross-group memory updates. Loaded for trusted and main containers only.
74
93%
Does it follow best practices?
Impact
—
No eval scenarios have been run
Risky
Do not use without reviewing
Reference for the runtime capabilities granted to each container trust tier. The runtime detection (read-only-filesystem error on a write to the group folder) is what the agent acts on per rules/container-trust-levels.md — this file is the on-demand expansion of what each tier actually allows.
/workspace/trusted/ shared memory/workspace/trusted/The authoritative source for this matrix is the host repo jbaruch/nanoclaw — specifically src/container-runner.ts (buildVolumeMounts for mount construction per tier; selectTiles for which tiles each tier installs) and the resource-limit constants applied to the container spawn. Update this doc alongside changes to those code paths.
docs
rules
skills
system-status
tests