I think you might be misunderstanding nixos, the tree separation will not improve security for this kind of scenario, the only guarantee that nixos offer is that the package is exactly as it’s described on nixpkgs if the store is untainted.
Wouldn't be shocked at all, I mostly think of it as "Linux but with a bunch of inherent security separations introduced", which is why I thought it might be what the...grandparent at this point? is using.
gotta love how every discussion pertaining to program isolation in the last 20 years is just "well all these years i thought this thing isolates processes like it ought to do", followed by a quick, "nope, it actually doesn't". i blame UN*X
Eh, it's a field/domain I am definitely ignorant of - at least I'm not out there confident in my wrong beliefs X)