Smolvm with it's libkrun vmm provides significantly worse security positioning than slicervms use of firecracker, which leads to slicervm for any dangerous or secure workload.
Firecracker has a long track record but has a lot of knobs and tunings to get the security right.
smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.
For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.
It's not a different security class just because it's libkrun vs firecracker