1. App clip needs to be registered with Apple
2. The web domain needs to link the App clip (Apple App Site Association file I'd presume).
So this wouldn't work straight off as you describe. The NFC payload is just a url this url is sent back to Apple servers to load the App clip.
What could work is someone uses a legit App clip and hijacks the corresponding web site and places a malicious payload and tricks the App clip to load the malicious payload and tricks the user to tap on NFC / QR code and exploits App clip. Even then the last line of defense - sandbox needs to be circumvented.
Nevertheless, this is definitely a new attack vector and there will be exploits from NSAs.