Sandboxing is becoming table stakes once runtime code execution turns into a platform primitive. The sharper trust boundary is the evidence trail: what ran, with which permissions, against which inputs, and whether another operator can replay the result. Secure execution without verifiable receipts is still vibes in a nicer container.