Is a fixed /tmp CODEX_HOME fallback a safety risk in agent wrappers?