Author here. We run an MCP server ourselves (BrightBean, YouTube intelligence API), so the security side of this protocol is something we think about daily. The breach timeline from April through October 2025 is what convinced us to write this up. Happy to go deeper on any of the CVEs or the remediation side.