User-initiated `!`/`$` (and RPC bash) executions persist as
`bashExecution`/`pythonExecution` roles, which are always user-run —
the model's bash goes through `toolCall`. The history serializer emitted
them as a bare `→ bash! …` line and cleared the watched-mode role label,
so in advisor deltas the command trailed the `**agent**:` block with no
user attribution. The advisor then misread user-run commands as agent
actions (e.g. a false blocker over a user-run worktree cleanup).
Render these lines under a `**user**:` label in watched mode and prefix
them `→ user-bash!` / `→ user-python!` so provenance is explicit in every
render path.
Fixes#6837