Security-hardened fork of OpenClaw for untrusted CLI environments, enforcing strict workspace-only agent sandboxing.