- https://snapcraft.io/docs/security-sandboxing
- https://docs.flatpak.org/en/latest/sandbox-permissions.html
However, in my (limited) experience, apps that actually do a lot of things have most of the sandbox features disabled anyway (network, disk access, etc.).
Note that AppImage is similar, but contains no sandboxing.
I've taken to running steam and other untrusted software under a separate user account. It's probably not ideal, and it's annoying to switch accounts to use certain software. But at least it may help limit the damage if the software is hacked as everything is contained within the throwaway account.
I'm sure one can do a lot better with selinux/apparmor/firejail, but it would probably take a lot of work to get it set up properly.