I think the two labels are being used confusingly at the moment, all WinRT applications run in the full screen sandboxed environment and are deployed via the Windows App Store. Metro is really only the name of the design style used by the system and recommended as the way apps should behave. When people talk about "Metro apps" they are really meaning "WinRT apps".
They can, however, scan the application to identify what system calls it's making and ensure they're constrained to those they are supposed to call. Furthermore it means the store knows exactly what the application installs and in the event it is later identified as malware, can much more effectively remove it from a users machines.