Andrew Healey wrote a great blog post about sandboxing, particularly related to us: https://healeycodes.com/sandboxing-javascript-code
And we recently launched more secure semantics: https://blog.val.town/blog/restricted-library-mode
But in the general case, it's a hard, never-ending cat-and-mouse game, particularly with free and unauthenticated use. We will eventually probably need to restrict use severely unless you have somehow proved you're a real person (ie connect to your github account) or are a paying customer.