> ...or wait a minute.. is that risky in these Intel ME times?
Intel ME has nothing to do with it as it is basically a separate system
inside the CPU with its own memory etc. Of course it is possible for Intel ME
to read/modify/transmit every bit of information on your system without even
asking/informing you. Theoretically it is possible that Intel ME can also
insert malware during your kernel compilation (or after it) but -
theoretically.
The best thing you can do is to disable Intel ME on your system (be careful,
read everything):
https://github.com/corna/me_cleaner
Unfortunately that won't free you from proprietary BIOS or from any other
firmware which may be running in device chips. There is no absolutely
free/libre system. At least I don't know of any.