What kind of things are you even doing that the agent would try to perform a kernel exploit on you? I thought sandboxing is just to protect from the agent accidentally clearing your home directory.
Side note, just 6 days ago a Linux VM escape exploit was disclosed.