Earlier quoted context omitted.
An AMT exploit, if having internal access to CPU, could weaken a RNG plus anything else you can think of. Passive attacks are definitely possible with a backdoor. It just makes a component, hardware or software, do something upon certain trigger conditions. Otherwise it stays silent. Example from high-assurance field: https://calhoun.nps.edu/bitstream/handle/10945/6073/02Mar_An...
I think woodmans argument is that AMT is an active service, you should see network traffic to the management engine and such -- so firewalls/airgaps/SPI should detect and prevent tampering. I think that is a naive view of AMT, it seems far more capable, network management is just one avenue (and it's been proven difficult to comprehensively implement anyways).
Nope, I'm talking about scale. You'd need to signal (paint with radar, send a packet, dip the power in morse code, put the magic cookie in the root DNS server response, whatever) every target at least once prior to exploitation. But yes, stealth would certainly be a concern that would reduce the value of AMT relative to a factory backdoored RNG.