If you don't want to do the sandboxing by hand, you can try the experimental
auto-sandboxing support. The linked design document has information about the implementation. To enable auto-sandboxing, you need to pass the following flags to nacl-clang (e.g. by appending them to CFLAGS): ' -integrated-as -mllvm -nacl-enable-auto-sandboxing'
If you run into errors, please let us know, we're still debugging the auto-sandboxing implementation (which is why it's not enabled by default yet) and we're looking for more feedback.