ME relies on security by obscurity (and hence the motivation of some for open source code). Of course that's not proof.
But I wouldn't rely on a Skylake ME's integrity for a public IP'd computer if it was running Windows 98 because it can be pwnd in ways that a Pentium Pro can not: replacing the disk drive won't get ownership back.