review: add sandbox wrappers and docs for AI review agents

Add bwrap and firejail wrapper scripts that sandbox review agents
against prompt injection in untrusted patches. Document agent
configuration including Cursor CLI and sandboxing.

Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
4 files changed