Both local `hermes serve` spawn sites spread process.env into the child. Route them through profileBackendParentEnv so a pooled profile backend, and a primary pinned to (or sticky on) a non-launch profile, only get the credentials their own profile scope provides (#68367). Co-authored-by: Yash Jain <23dec512@lnmiit.ac.in>