personally, I think a malicious PDS would be bad since it has full control over your identity & keys and also should act as a mitm for all on-protocol traffic. so it could modify/refuse incoming or outgoing posts, inject ads into feeds, lock you out of migrating, post or delete for you, etc