Lock Down SSH Key so it can only be used for ZFS Send/Receive Commands

You could just ensure that your replication user has virtually zero rights to do anything on your source system with the exception of zfs allow send in a PULL configuration.