@Jax excellent question and good to be think along those lines.
Those directories should be outside of the publicly accessible web paths, so they should be okay.
You can try more restrictive permissions like 700 for just owner access, or 755 for just owner write, just make sure those...