So? Is this supposed to be mandatory to publish or is this supposed to be an option to have such a verified checkmark? You began your suggestion with Steam as an example. Steam does not have an optional way to verify developers. They verify all of them. And because they verify all of them, there is trust.
If it is an additional option to get a verified checkmark, it will not change the situation. Some games would have more trust, all the rest would still not have such a checkmark and be a hiding place for all the bad uploads.
The sandbox mode I talk about is on operating system level. It separates the user that runs the game from the user that normally uses the system. That's why I called it poor man's sandbox. The game user can't read the files belonging to the regular user.
Time is trust, but time is not trustworthy. I have seen malware that was indexed for two years. Several that were indexed half a year. And I saw hundreds of hacked accounts that were several years old and being used to upload malware. And it happens far too often that Itch will not remove reported malware for several weeks. Nope, time does not make a game trustworthy.