Nothing is a security mechanism against privilege escalation flaws in the mechanism itself. That's what appeals to me with seccomp, it should be possible to be made secure, as opposed to complex stuff such as LSM- or SELinux-arbitrated access control.