Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The setup instructions actively encourage exposing the HTTP API and MCP surfaces over the network and only briefly note that host networking is 'convenient', without a prominent warning that these endpoints can execute agent actions and access the mounted workspace. The same document also states that bearer-token auth can be empty, so a user could deploy a remotely reachable control plane with no authentication or with weak operational safeguards.
