Because I don't trust the developer not to have security holes in their code.

But you are asking the developer to make these restrictions... Node.js is the user-space program, controlled by developers. Ops shouldn't (need to) deal with it.