The connectors are still optional.
Haphazard code is not a new thing. Some statistics claim that almost 50% of "vibe coded" websites have security flaws. It's not much different from the old "12345" password, or the "qwerty" one (not naming names, but have known people using it on government infrastructure), or the "who'd want to hack us?" attitude.
MCP is the right step forward, nothing wrong with it on itself.
People disregarding basic security practices... will suffer, as always... and I don't really see anything wrong with that either. Too bad for those forced to rely on them, but that's a legislative and regulatory issue, vote accordingly.
I would still be extremely hesitant of enabling any MCP connector on non-local model instances. People need to push harder for local and on-prem AI, it's the only sane way forward.