nix: harden sower-agent systemd service
Apply comprehensive systemd hardening to the agent service,
reducing exposure score from 8.6 to 1.5. Adds filesystem,
kernel, namespace, capability, and syscall protections while
preserving network access and activator socket functionality.
sow-17
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>