Yes! I’m not aware of any aws cli command that gives you the host key of a new instance. I’d definitely use that.
The script is designed for ephemeral instances, where I don’t intend to ever connect to the instance again, so saving the host key doesn’t help anything. So, really, anyone not using this hypothetical API is just as vulnerable to such a MITM attack in my threat model.