I don't think I've seen this come up before - but because of Solid's emphasis on read-write web, a possible risk is that a malicious app vandalise data it has access to, rendering it useless (denial of service?) or introducing malicious data (e.g. escalating to #20 ).
While granting an app read only access is a mitigation, this would limit normal operation of most apps. Audit trails, version control and backup are also relevant.