These sandboxing tools aren't designed to make it safe to run arbitrary untrusted code. If you want that then you're looking at a VM- either a full VM like firecracker or a software VM like V8.
In fact I'd argue it's precisely the lack of such knowledge which makes sandboxing useful: after all, if I knew that the program won't touch or call anything sensitive, I would just simply run it as-is; contrariwise, if I knew it would steal my bank login info and send it to Serbia, I would just not run it at all.
EDIT: Don't get me wrong, I don't have anything against applications putting themselves into restricted modes, and splitting potentially sensitive logic into separate processes; but that functionality really should also be exposed to an end-user as well, akin to
$ pledge --promises=stdin --chroot=/var/empty --cwd=/ -- suspicious_program