They have this "documented", so, according to them, it's all good. Like, phishing is not a thing anymore, and everyone reads the cookie policies.
I reported a few vulnerabilities to them (and the other major players), and the official answer is "it is part of a threat model, all is documented"
As part of that, I created CodeGate to at least detect potential malicious files and configs (Skills, Plugins, Hooks, etc.)