Let me quote the workers GitHub:
> WARNING: workerd is not a hardened sandbox
> workerd tries to isolate each Worker so that it can only access the resources it is configured to access. However, workerd on its own does not contain suitable defense-in-depth against the possibility of implementation bugs. When using workerd to run possibly-malicious code, you must run it inside an appropriate secure sandbox, such as a virtual machine. The Cloudflare Workers hosting service in particular uses many additional layers of defense-in-depth.
Sandstorm was great because it did proper sandboxing. This is pretty weak by comparison.