It should just be a user configuration.
In the original we defaulted to the latest Fedora image (yes, even in the days of CoreOS... blame me for that), but allowed the user to override this with an environment variable (and later a `.toolboxrc` file in their home directory). Thus, IMHO, this is a regression.
Now it seems the new stewards are trying to be "clever" and protect you from yourself, creating "foot-guns" in the process.
According to the docs (https://github.com/containers/toolbox#image-requirements): Since Toolbox only works with OCI images that fulfill certain requirements, it will refuse images that aren't tagged with com.github.containers.toolbox="true" and com.github.debarshiray.toolbox="true" labels. These labels are meant to be used by the maintainer of the image to indicate that they have read this document and tested that the image works with Toolbox. You can use the following snippet in a Dockerfile for this:
LABEL com.github.containers.toolbox="true"
edit: I forgot part of my point: This is a regression from the original utility.Oh...well that's unfortunate.
The main advantage of Silverblue is its readonly root fs. Toolbox comes as the provided way for devs to be able to work on top of that feature.
I think Debian has/had some energy devoted to turn the root fs read-only as an option (perhaps in order to move to an ostree based distro, ostree being already available as a package in Sid). Hopefully they'll manage to get it working.
Also, please note that it's not a silver bullet. An immutable FS is a good feature for security (both from malicious adversaries and an oblivious self), but of course it's not enough.
I link to some build scripts people use in my repo, but yeah it would be nice if there were more distros in toolbox so that people can use whatever they want.