Some code should never touch your real machine.
A recruiter sends a coding challenge. A tutorial says to pipe a script into your shell. A dependency you have never heard of wants a post-install hook.
Each of those runs with your files, your SSH keys, your browser profile, and your password manager sitting right there. Attackers know it Elastic Security Labs documented a campaign that delivered malware through fake interview challenges, which is part of what prompted this project.
Sandfort's answer is boring on purpose: give that work a whole separate computer, make the separate computer cheap to create, and make throwing it away the normal thing to do rather than a chore.