f367ebeb5d
_run_job_script popped the launch profile's secret-source names in an inline loop right above strip_launch_profile_env, so only the no_agent child got that protection; the four other callers of the same helper (the external cron worker, scheduler_delivery, kanban dispatch and the byterover plugin) still handed a served profile the launch vault or 1Password names. Fold the names into the helper's residue set, which is already gated on multiplex and on the target not being the launch profile, and keeps administrator-managed keys.