The tester will need to have deep understanding what is malicious first of all, because that’s not something subjective and tied to interpretations, as well as sandbox tend to overblown and flag most files as malicious. So the tester will have to review the report, quickly and take a decision whether or not this actually is working malware.
Of course, someone like Leo won’t really do that.
Leo’s purpose is NOT to be informative and help the confused customer choose security solution (in an ocean of such). Leo’s purpose is to generate revenue through ads, sponsorships and through promoting not-so-amazing products like Sophos, without any actual evidence or explanation how exactly they are superior.
Long story short, don’t trust a youtuber to perform these highly technical tasks and tell you the truth.
If he was so professional, he wouldn’t be a youtuber.
Doing things “to the best of your ability” is one, doing it to the required, professional standard is something else.