It's the switches job to drop traffic from rogue routers/DHCP servers. Look up RA Guard and DHCPv6 guard. You also need to worry about rogue DHCP(v4) servers too. DHCP Snooping takes care of that.
If you're that paranoid then you also need to worry about IPv4 ARP and IPv6 ND attacks. Again, managed switches are required to drop unauthorized ARP and ND replies.
I never claimed that my nervousness is rational. But it's very real. This is complex stuff, and since I haven't been working with IPv6 for decades, I can't shake the fear that I've made a configuration error and am not aware that I've made a configuration error.
But SLAAC makes me equally nervous. If/when I shift my home network to IPv6, I'll probably just go with static routing to avoid both of them.