Aside from random errors made by the model, another reason to sandbox is that prompt injection could make your agent behave in an actively harmful manner.