Ryan actually had the foresight to add permission sandboxing to deno from the start though
Sandboxing doesn't help against malicious code that changes expected behaviours or corrupt data.