My attempt at a portable solution: Linux VM inside WASM for sandboxed execution: http://agentvm.deepclause.ai

Minimal dependencies, but not as fast as containers or bubblewrap.