Kernel-Level Sandboxing for Agent Code