Well, if your agent lacks shell access (or has some other sandboxing going on), it shouldn't have access to envs and MCP setup files.
(leaving out cases where your genius GPT-12 Galaxy Ultra agent hacks the sandboxing from inside)