Missing User Warnings
High
- Confidence
- 97% confidence
- Finding
- The documentation explicitly advises running the service in `--no-auth` mode and omitting the Authorization header, but provides no warning about the risk of exposing an unauthenticated endpoint. If the service is reachable beyond localhost or misconfigured, an attacker could retrieve sensitive status snapshots and raw metrics without credentials.
