I've been using it to wrap nodejs package managers in response to all malware shipped through them over the past few years. A simple wrapper script like this works fine (symlinked to `npm`/`yarn`/`pnpm` into whatever directory is the first in $PATH):
bin=$(basename "$0")
exec bwrap \
--bind "$PWD" "$PWD" \
--dev /dev \
--die-with-parent \
--dir /tmp \
--dir /var \
--disable-userns \
--new-session \
--proc /proc \
--ro-bind /etc/ca-certificates /etc/ca-certificates \
--ro-bind /etc/resolv.conf /etc/resolv.conf \
--ro-bind /etc/ssl /etc/ssl \
--ro-bind /usr /usr \
--setenv PATH /usr/bin \
--share-net \
--symlink /tmp /var/tmp \
--symlink /usr/bin /bin \
--symlink /usr/lib /lib \
--symlink /usr/lib64 /lib64 \
--unshare-all \
--unshare-user \
"/usr/bin/$bin" "$@"
It gets read-write access to the current path, and to its own copy of ~/.cache and ~/.local/share. It doesn't see anything else from your home directory, including any adjacent projects. It can easily be locked down further by allowing read-only access to the project, and read-write access to node_modules and nothing else.