TIL: capsicumizer
"capsicumizer is a sandbox launcher that imposes #Capsicum capability mode onto an unsuspecting program, allowing "sysadmin style" or "oblivious" sandboxing (i.e. no source code modifications, all restrictions added externally).
You just write AppArmor-esque "profiles" and capsicumizer takes care of sandboxing the applications."