The guest profile cannot see what the owner profile has installed. Only the owner profile can view apps installed in other profiles through those special Settings menus. Non-owner profiles, including guest, are restricted — the Settings app in guest won't show apps that exist only in owner.
This setup actually works the way you're thinking: put your sensitive or "concealed" apps exclusively in the owner profile, then use the guest as your daily driver. The guest stays clean and isolated from seeing what's in owner.
Here's the tradeoff, and it's a big one.
The owner profile has to stay unlocked for the device to run at all — its data stays decrypted and in memory the whole time you're using the guest profile. You can't "end session" on the owner without rebooting.
Secondary profiles can be encrypted at rest when logged out the way a computer with LUKS is when powered off. That's a cryptographic guarantee that snoopers can GFY.
Cable hacking like Cellebrite might be able to get into Owner one day if the phone is on, since the session is decrypted.