An option to run the potentially harmful script in a rootless container, then dump filesystem diffs, audit events, etc...might be helpful.
I get containers aren't perfect isolation, but...
I get containers aren't perfect isolation, but...
It is Linux-only, though.