An AGI kill switch with defined security properties — LessWrong