Demo shows root shell. So an attacker could simply install a RAT into /Library/LaunchDaemons and it's permanent.
It is impossible to untethered persist a modified version of MacEFI without another exploit on the T2 since it has to be signed by Apple and the signature is properly checked.
I mean, you can just ad-hoc sign?