feat(agents): Option B — _BackendProtocol in langchain, backend on AgentRuntime
- _BackendProtocol: private Protocol with core backend methods (read/write/ls etc.)
- AgentRuntime.backend: _BackendProtocol | None — typed at the langchain layer
- create_agent accepts backend= and threads it into AgentRuntime at dispatch time
- No AgentRuntime subclass or BackendMiddleware needed in subpackages