Utilize "burner" user accounts to sandbox specific "sketchy" apps
I'd be more inclined towards a 'burner' VM macOS install if you're that worried. Duplicate it before any sketchy install, so you can just delete it after use, keeping the 'master' VM safe.