Sandboxing AI Agents at the Kernel Level