Close the last onboarding gap: one shareable App Lab app a student imports
and Runs, no adb / no host install.
- package-onboard-app.sh: assemble a self-contained bundle — ZeroClaw binary
(matrix_text + i2c_scan), single-agent config, skills, responder sketch, and
the BAKED cloud token. Ships without .secret_key (each board mints its own)
or a team Telegram token; dist/ is gitignored.
- onboard-app/config.toml: the canonical packaged config (proven anthropic.max
single 'default' agent, matrix + i2c_scan allowlisted, Telegram-ready,
secrets stripped).
- ONBOARDING.md: the full flow — instructor packages once, student imports +
Runs, then the wizard. Notes APESS_URL (mDNS/per-team) + LAN reachability.
Validated on-hardware: a freshly-imported bundle mints its key, boots the
cloud agent, and runs the matrix + i2c_scan prompts in-container.
Co-Authored-By: Claude Opus 4.8 <[email protected]>