AI agent credentials live in the same box as untrusted code. Two new architectures show where the blast radius actually stops.