Libkrun and firecracker had similar foundations (Rust, KVM, rust-vmm).
Firecracker has a long track record but has a lot of knobs and tunings to get the security right.
smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.
For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.
It's not a different security class just because it's libkrun vs firecracker