If I understand correctly, Claude Code will(shortly, if not already) make use of Anthropic's sandbox that wraps Seatbelt on OS X, not sandbox-exec?
It's cool that they made this open source. It seems straightforward and useful enough that it could be used on its own for sandboxing purposes.
https://docs.claude.com/en/docs/claude-code/sandboxing
https://github.com/anthropic-experimental/sandbox-runtime