FWIW the Factorio Lua sandbox IS pretty resilient to sandbox escapes from malicious mods. They've ripped out major known "scary" Lua APIs that have been used in other games to attack players' computers. And they've tried to lock down any weak areas that are identified and reported to them.
That being said, the desire to download from the portal is understandable. But just calling out the devs HAVE done a pretty decent job to limit the mod damage to only save files ;-)