Furthermore I would add that the silicon die of an FPGA has a particular look which is very homogeneous compared to the die of a CPU or microcontroller, so if the vendor is including a small malicious CPU as a physical part of the FPGA, you should be able to detect that just by carefully scrutinizing the die with a microscope.