Found via SkillFence scan (npmjs.com/package/skillfence, 76 rules).
Key findings across 291 files:
- CORS wildcard (*) in server examples — allows cross-origin attacks
- Auth disabled in example configs — should default to secure
- MCP sampling patterns without approval gates
Scan: npx skillfence scan . (Verdict: BLOCK, 113 findings, 17 critical, 28 high)
Recommendation: Default examples should use restrictive CORS and require auth. Add security notes to docs.