Disabling AutoPlay and any other "automatically run a program when media is inserted" feature would be a good first step. Not running executable files (Windows users: unhide those file extensions!) that have no reason to be executable, and using AV software (or multiple, like those online services) to scan the files you are interested in is also a good idea.
If you're really paranoid, do everything with a separate machine.
People have put little nano atmel's in usb drive cases that have emulated a virtual keyboard. Sending ~a few strokes could open command, download, and run an executable.
If you're really paranoid, do everything with a separate machine.