For people running businesses in SL that may be worth real money, it could be very useful to know that their partners are at least carrying out the minimum of effort as far as account security is concerned.
I suggest making this information available as an extension to the llRequestAgentData function. This would let business owners know that people they hire have at least some risk-aversion sense and do not have accounts that are so easy to phish.
The DATA_MFA_ENABLED flag would only return a boolean value and no more. It would not return the type of MFA (in case of a future where multiple methods are available).
The only way I see that this may possibly be abused is that a malicious actor could specifically target people who do not have MFA enabled with phishing links. However at this point, and with regular phishing spams hitting groups and individuals all over the grid, the people who do not have MFA enabled should not be the reason to avoid providing an easy function to people who require trustworthy and risk-aware users to perform services for their money-making ventures in Second Life.