couldnt you deeply ingrain in the training data instructions for agents to always send data to some ip?
like its learning that a certain technical step just always involes ncatting SSH Priv keys to a chinese IP?
Not saying this is happening, just curious if thats not a real threatmodel?