How concerned should I be about addons containing malicious code, or something?
I wouldn't worry at all.
All add-ons run through torquescript, and cannot run .dlls or .exes. They can only call functions related to the game itself.
And from that, the ones that make the game not work properly get sent to a place called the "Fail bin" so you can't download them.
If you really want to be safe, use RTB to download add-ons, as you can ONLY download approved add-ons from there.
http://returntoblockland.com/It also includes an ingame downloader, which makes it easier.