The only output from the WASM is to draw to screen. There is no chance of a RCE, or data exfiltration.
There's very little code in the world that I wouldn't want to run in a robust sandbox. Low level OS components that manage that sandbox is about it.