But what am I specifically supposed to fear about Steams security? What are the ramifications? Eager to know where you are coming from here...
Any closed code which is run on your system and can modify it is automatically a suspect. And if the purpose of that code is to modify your system (installation, updates etc.) - even more so! Its closed nature doesn't allow external audit. Plus Steam has DRM in its client. While it's not always used, it's still there, which increases security concerns many fold by definition.