The only output from the WASM is to draw to screen. There is no chance of a RCE, or data exfiltration.
There's very little code in the world that I wouldn't want to run in a robust sandbox. Low level OS components that manage that sandbox is about it.
[1] https://www.destroyallsoftware.com/talks/the-birth-and-death...