The latter does need to be a subset of the former, or else an attacker can trivially work around limitations on "what it should be able to do" by spawning a child instead of doing the thing directly.
But yes, it's unfortunate that macOS sandboxes cannot be nested.
>The latter does need to be a subset of the former, or else an attacker can trivially work around limitations on "what it should be able to do" by spawning a child instead of doing the thing directly.
That assumes you're only defending against malicious code. Spawning children with limited functionality is a useful defense against non-malicious code being exploited by malicious data, even if those children have privileges the parent lacks.