Can your sd card get compromised and steal your passphrase or private key when connecting via coldcard air gap?

What should I look for when signing transactions -just the signed psbt file and making sure no other files exist?

Sorry for the newb questions

Thanks in advance