I'm just going to leave this here: https://llm-attacks.org/
There are plenty more. But there are infinitely many paths. It's non-deterministic code. That just can't be tested reliably. But since there are potentially infinitely many paths to a bad state, it doesn't matter how much you test because the attack surface is infinite.







To be clear, there's a bit of nuance here. It's an argument against organizing focused primarily on insurrection, and against insurrectionist tendencies. But this does propose something that could be described as a latent insurgency, which would explicitly have the capability to evolve into an Insurrection (if necessary).
I don't remember if I made that totally clear in that specific essay.