... interestingly, Anthropic's SRT is built on the same macOS primitives and DOES support the network configuration I'm looking for:
https://github.com/anthropics/sandbox-runtime/tree/main#as-a...
const config: SandboxRuntimeConfig = {
network: {
allowedDomains: ['example.com', 'api.github.com'],
deniedDomains: [],
},
filesystem: {
denyRead: ['~/.ssh'],
allowWrite: ['.', '/tmp'],
denyWrite: ['.env'],
},
}