Anthropic confirmed the MCP STDIO remote code execution vulnerability is by-design behavior. With 150 million downloads affected and no protocol fix coming, here is the concrete checklist every team running agentic workflows needs to implement this week.