It only pulls from communities you have subscribed to. Images aren't duplicated per server, just text; so even if you find something nasty it's not hosted by you and you can always delete comments from the database/block users from appearing in your instance.
Tangential - is there any reason a private instance couldn't just not run a pictrs container? Especially if you're not creating communities on your instance.
I am not completely sure about the risks here, but I think as the sole user on my instance they are pretty low. I think the only way content gets onto my machine is if I post it, if I interact with content on other instances, or if I create a community to which other people from other instances start posting. Despite my handle, there are some crimes I don't do. I should be okay as long as I don't mess with illegal content myself and moderate accordingly others' behavior in my communities.
If you block porn-related instances suchas lemmynsfw and pornlemmy, you'll drastically reduce your chance of getting CSAM contents on your instance. Not saying those instances promotes that kind of stuff, but many dubious instances (the ones with kiddie/doll banners) federate with them, and might post bad stuff when the mods aren't looking.
If you're still super worried about it, you can host your instance behind cloudflare and enable their CSAM scanning tool.
You're supposed to contact them at espteam@ncmec.org in order to start the enrollment process, and it seems the service is only for US-based operators.