Injected design tokens never reach the sandbox iframe
The design plugin's postProcess (plugins/design/src/pipeline.ts) and the editor preview's client-side stand-in (packages/editor/app/src/lib/preview/block-renderer.ts) both deliver a sandbox's design-context tokens as a child element: <meta data-field="design-tokens" content="{…}">. The identity transform leaves it in place (it is not a modifier), so it ships inside <rf-sandbox>.
The rf-sandbox behaviour never reads that child. It looks for the tokens on a host attribute, this.dataset.designTokens (packages/behaviors/src/elements/sandbox.ts:112), and otherwise falls back to RfContext.designTokens. Nothing in the repo sets either: no transform emits data-design-tokens, and no code assigns RfContext.designTokens. So this._tokens is always null and the iframe never receives a token set, whichever context the sandbox names.
Found while fixing BUG-032. That fix makes the build pick the right token set per context. This bug is what keeps that set from reaching the page.