Yes, I know, but it's different.
The network traffic is going out of the sandbox to the real system (and then further out, on the network) - which is where it's scanned by the WebShield or NetworkShield. The scripts, however, are fully contained inside the sandbox, they don't "get out of it" (which is good for sure) - so avast! doesn't see them.