You can run it using Docker Sandboxes: https://github.com/docker/sbx-kits-contrib/pull/156. Doesn't replace reading the code, but `sbx policy log` shows every request the network policy blocked or allowed, and combined with an explicit allowlist, that gives you a meaningfully more secure environment to run it in.