The dangerous four
Unlimited approve, Permit and Permit2, setApprovalForAll, and raw eth_sign. Each can grant far more than a single action.
Why they matter
Legitimate use exists for all of them, but on a phishing site any one can hand over your tokens or NFTs in a single click.
Your defense
When you see these, pause and confirm the site and the intent. If a simple action requests one of these against a valuable asset, reject it.