orion-cli: unauthenticated MCP admin proxy lets DNS-rebound web pages administer Orion via disabled Host-guard
orion-cli mcp serve --http disables the MCP SDK's default Host/Origin allowlist and adds no auth middleware of its own, while binding 0.0.0.0:8081 by default, so a DNS-rebound browser can reach the endpoint and call any of the 32 administrative tools (workflow/channel/connector CRUD, data injection, DLQ purge, engine reload) with no credential, under whatever backend admin API key the operator configured.