There's absolutely nothing special about any of these agents. They're regular processes that execute some subshells. They're trivially jailable.