In principle you are right. It would be nice if every app was sandboxed, even apps distributed outside the Mac App Store. But in practice the Sandbox has a few issues that make it unusable for many use cases:
- There is no way to provide automatic software updates for sandboxed apps. For Mac App Store apps, that doesn't matter (MAS takes car of updates), but for apps distributed outside the MAS, this is pretty much a deal breaker.
- Many technologies are not available for sandboxed apps, eg. shared memory. This makes it hard hard to distribute some popular software on the Mac App Store (eg. PostgreSQL)
- Unix Socket Connections outside the sandbox are not possible. This makes connecting with a lot of services (eg. SSH Agent) impossible.
- the whole sandbox mechanism is buggy, poorly documented, poorly supported, and error logging in insufficient.
I currently distribute a sandboxed app outside the Mac App Store, and I'm considering to remove the sandbox for the above reasons.