I have my nsec living outside the container for my Jorgenclaw. We use a nostr signing daemon. Keeps your nsec away from the agent so that the human can become a safety valve.
I built it for NanoClaw so it cxan be adapted easily to openclaw
https://github.com/qwibitai/nanoclaw/pull/1056