Whenever you have something that would usually improve safety, but which presents a risk if it fails, then the rational response is to ask whether it demonstrably improves safety overall. This calculus depends on how much it improves safety when working, how much harm it does when failing, and how likely it is to fail. These considerations can be modified by limitations on operations both when things are working and when they fail, as is the case of twin-engined aircraft use on trans-oceanic flights.
If, in addition, this thing can be disabled, the principle is the same, but there are more cases: what are the chances it be disabled even though working, or (as in this case) not be disabled when failing.
Disabling MCAS does not itself put an airplane in a dangerous situation, it merely increases the risk somewhat. The part of the analysis that seems to have been flawed is that covering the risk introduced when it fails but is left engaged.