Honestly if the point is to run proprietary software like commercial AAA games, the supply chain is already compromised.
I treat my gaming computer as a video game console, it wouldn't occur to me to share passwords, accounts, data or anything sensitive on my gaming machine. And I only connect it to the network if I need to download a game/update.
Considering how many games require literal malware for anti cheat. It’s the only sane way to do gaming. Just let the games and proprietary junk have their own environment with total control. But with none of your sensitive data.
My understanding is that a lot of the games on Steam are actually executed in some kind of sandbox, but I am sure if that is just for compatibility/emulation reasons, and which directories are still accessible in that case.
I wish there was better documentation for this, because "random indie game demo cannot upload my family photos" would be a great selling point for SteamOS/Bazzite.
As it stands, the Steam flatpak is probably the safest way to play games (which does not work on Bazzite).
I totally agree and I have done likewise for many years now.
Consider setting up a VLAN or additional WiFi SSID if you find the network situation a hassle.