Do the same as the nix-info script, which nix-build
s this file and inspects the exit code.
Short version:
nix-build --no-out-link -E 'import <nixpkgs/pkgs/tools/nix/info/multiuser.nix>' 2> /dev/null
If and only if the exit code of that is 0, the sandbox is in use.
Note the above does not check for the relaxed sandbox, see the linked scripts for more detail on that.
Also relevant: Nix issue Add command that output system information like nix-info