The leaks likely happened in the first place because the model forgot it had a tool call for running properly managed background tasks (claude seems to do this all the time). I'm not saying a the model is going to be malicious and try to escape, I'm just saying it's going to employ workarounds to get its job done.