Create a user that's not part of the wheel group, use that for most everything and log in to your admin account for admin tasks only.
One of the easiest privilege escalations is to toss a special lil' version of sudo in your home directory and addend $PATH in your .bashrc so it's prioritized over system sudo.
Do that and don't download stupid shit off the internet and you'll be fine, unless for some reason you're being targeted by state actors in which case I'd recommend purchasing a rectal dilator.