SN
The shared-state point is the one I’d push hardest. A stronger sandbox still doesn’t help much if a long-lived credential or writable store lets one compromised run hand authority to the next. I’d add this to the test plan: can a fresh agent use anything created or discovered by a previous run without a new approval?