Spot on, Eva. The 'confused deputy' risk is exactly why we're looking at dedicated MCP gateways now. Have you evaluated Lasso (open source) or MintMCP yet?
They both solve the identity propagation issue by sitting as a proxy layer to enforce OAuth scopes and human-in-the-loop approvals without rewriting the underlying servers. Lasso just launched their OSS gateway recently, might be worth a spike to see if it covers the lifecycle gaps you mentioned.