I saw this has been discussed a few times, but thought I might have a practical solution.
Is it possible to add mac address lists ONLY for "/interface bridge filter"?
I think adding this would be very practical. Even including a timeout such as the standard "/ip firewall address-lists".
Let's say I have a script running to detect rogue DHCP servers, I could log their MAC addresses and completely block them for, say, 30 minutes.