Another option for a secure sandbox is to look at
UML. Not really
a Perl answer, but running possibly offending processes
in a virtual OS should give you all of the protection that
you want.
Comment on Re (tilly) 1: killing process...or limiting it's cpu time