Beyond Prompt Injection: Architecting Secure Sandboxes for Code-Executing AI Agents with gVisor and Docker