It's not a proper sandbox. Converted apps run with full trust. There's file system and registry redirection but a malicious app can get around it. See this discussion: https://arstechnica.com/civis/viewtopic.php?f=15&t=1312055
Also full trust vs app container here: https://msdn.microsoft.com/en-us/windows/uwp/porting/desktop...