# ScienceClaw's security section promises isolation and its compose file disables seccomp

> A Docker-based research assistant with a sandboxed agent, a self-hosted web search service and about 1,900 scientific tools borrowed from a public ecosystem. Read the compose file before the marketing: the sandbox runs with the syscall filter turned off, and a database password is committed.

**AgentTeam-TaichuAI/ScienceClaw** — ScienceClaw is a personal research assistant built with LangChain DeepAgents and AIO Sandbox infrastructure, adopting a completely new architecture beyond OpenClaw. It offers stronger security, better transparency, and a more user-friendly experience.

- Repository: https://github.com/AgentTeam-TaichuAI/ScienceClaw
- Website: https://scienceclaw.zidongtaichu.com/
- Stars: 669 · Forks: 71
- Language: Python
- License: not declared
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/agentteam-taichuai-scienceclaw

## The security claim and the sandbox's seccomp setting point opposite ways

The first of three selling points is titled security first, and it says the whole system runs inside Docker containers, that the agent cannot access the host system, personal files or environment variables, that all code execution happens in an isolated sandbox, and that generated data stays in a local workspace directory. The compose file for that sandbox contains two settings worth reading before believing the paragraph:

```yaml
    security_opt:
      - seccomp:unconfined
    extra_hosts:
      - "host.docker.internal:host-gateway"
```

Unconfined removes the syscall filter the kernel's secure-computing profile would otherwise apply, and the host gateway entry gives the container an explicit route to the host. Both are common in development, and both belong in a threat model rather than in a security claim. The sandbox is also given two gigabytes of shared memory, a memory limit defaulting to eight gigabytes and four CPUs, which tells you what the isolation costs.

## A database password in the repository and an admin login on the page

The compose file sets the database root account in plain text, a fixed username and a fixed password, and publishes that database on a host port as 27014 mapped to 27017. Anyone who clones the repository has the credentials for any instance deployed from it unchanged. On top of that, the quick start publishes the interface's default login in a table: username `admin`, password `admin123`, followed by a warning to change it after the first login. Both are ordinary onboarding shortcuts, and both are the kind of thing that survives into production. The page also asks for nothing else by default, since the rest of the configuration is environment variables and image names, so these two are the whole of the credential story a new operator inherits.

## The Windows build skips Docker and comes from a third-party host

There are two products on this page. The macOS and Linux route is Docker, with a documented guide in Chinese and a prerequisite list of Docker with Compose plus a recommended eight gigabytes of memory. The Windows route is a desktop installer that states no Docker and no command line are required, distributed as a version 0.0.4 archive hosted on a third-party git forge rather than on this repository, which publishes no releases of its own. The consequence for the security story is direct: the isolation argument applies to the Docker deployment, and the Windows build does not claim it. A reader who installs the desktop app on Windows gets a different architecture from the one the security section is describing, with no container boundary described anywhere.

## Three compose files, and the path of least resistance needs an explicit one

The repository root carries three: a default file, a release file and one for China. The quick start's recommended command is not the default one:

```bash
docker compose -f docker-compose-release.yml up -d --pull always
```

That pulls prebuilt images and states that no local compilation is needed. Developers are pointed at the plain command with a build flag instead, which compiles everything from source and warns the first build downloads dependencies and takes longer. The interface is then on a local port in the 5173 range. So the difference between a five-minute install and a long build is which filename you pass, and the file that gets used if you type the command from memory is the slow one. The Chinese file is there to swap image sources, which the page does not explain.

## The search stack replaces a commercial API and turns off the limiter

The compose file contains a self-hosted metasearch instance and a separate web search and crawling service built from a directory in the repository, with a comment in Chinese stating that the search service replaces a named commercial search API. The metasearch service is configured with its rate limiter disabled and a base URL pointing at a local port, and it is itself published on a host port. The sandbox reaches it through an internal service name on a container network. That is a coherent design for a local-first tool, and it has a cost worth naming: without a commercial provider's limits, the limiter is the only thing standing between a research loop and an aggressive crawl of someone else's site, and it is switched off in the shipped configuration.

## The 1,900 tools are wrappers over public databases, mounted read-only

The headline number is 1,900-plus built-in scientific tools, and the page attributes them to a named external ecosystem rather than to code in this repository. The table that follows is a list of public data sources by discipline: drug discovery with target databases, adverse event reporting, protein structures and predicted structures, genomics and expression atlases, clinical trials; astronomy with object catalogues, a sky survey, an exoplanet archive, ephemeris services and a solar event database; earth science with earthquake, hydrology, ocean and soil datasets and two weather services; chemistry with crystal structure databases and molecular property prediction; biodiversity with species, plant taxonomy and bird records. The repository ships them anyway, in a tools directory and a skills directory, and the sandbox mounts both read-only along with a built-in skills directory.

## The architecture section is an empty element, and the page sells cloud credits

The section that should carry the argument for a new architecture contains an empty centred block and nothing else, and the same is true of the badge row near the top, where every image is gone. What the page does carry instead is commercial. It invites readers to try a hosted version, offering a trial credit balance on registration, a credit reward for both sides of a referral with the note that the more you invite the more you earn, and an extra balance for verifying an academic email address. A separate table offers free language-model token allocations, ten million from a national supercomputing network and ten million from the project's own cloud, both claimed by following links elsewhere. The self-hosted product and the paid cloud are presented on one page, in the same voice.

## Conclusion

Start with the two things to fix before anyone runs this. The page's security claim is that the agent cannot reach your host system, and the compose file's sandbox service sets its seccomp option to unconfined and adds a host gateway entry, which is the opposite posture from what the claim implies; if the sandbox runs real code from a research agent, that filter is the thing standing between a mistake and the host. Second, the compose file commits a MongoDB root username and password in plain text while publishing the database on a host port, and the web interface ships a fixed admin login that the page asks you to change after first use. With those handled, what is left is a genuinely capable local stack: the agent loop, a web search service that replaces a commercial API, a read-only mount of thousands of scientific wrappers, and three compose files for three different ways to run it. The claim of a new architecture is not evidenced on the page, because the architecture section is an empty element. It suits a researcher who will audit and harden the deployment. It does not suit anyone installing it on a shared or reachable machine as written.

## FAQ

### What is ScienceClaw?

A personal research assistant that runs inside Docker containers, built on LangChain's deep agents framework and a sandbox infrastructure project. It is described as going beyond a named alternative architecture, and it reaches about 1,900 scientific tools through an external ecosystem covering drug discovery, astronomy, earth science, chemistry and biodiversity, with results and generated files kept in a local workspace directory.

### How do I run ScienceClaw?

On macOS and Linux with Docker and Compose, eight gigabytes of memory recommended. The quick path pulls prebuilt images with a compose file named for releases and always pulling, then opens the interface on a local 5173 port; developers can instead build every image from source. Windows uses a desktop installer archive that needs neither Docker nor a command line, hosted on a third-party forge at version 0.0.4.

### What are the default ScienceClaw credentials?

The web interface ships with the username admin and the password admin123, and the page asks you to change it after the first login. The compose file additionally sets a fixed database root username and a fixed password in plain text, and publishes that database on a host port, so the credentials are in the repository rather than in your environment.

### Can I install ScienceClaw on Windows without Docker?

Yes. The Windows route is described as needing no Docker and no command line: download the desktop installer archive, extract it, follow the setup wizard, then launch it from a desktop shortcut. The security claims about container isolation on the page describe the Docker deployment, and the desktop build does not repeat them.

## Sources

- [AgentTeam-TaichuAI/ScienceClaw on GitHub](https://github.com/AgentTeam-TaichuAI/ScienceClaw)
- [Issues](https://github.com/AgentTeam-TaichuAI/ScienceClaw/issues)
- [Project website](https://scienceclaw.zidongtaichu.com/)
- [README](https://github.com/AgentTeam-TaichuAI/ScienceClaw/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/agentteam-taichuai-scienceclaw
