We should create guidance on how to safely build and run repro projects, since building or running a project implies that you trust it. This could be separate guidance, or it could be part of #45340.
If using Windows, the guidance probably involves using Windows Sandbox, and possibly how to script it to set up an environment.