Server-side agent wrappers: safe defaults for sandbox/network/api-key sourcing?