Is exposing runtime working directory and config-presence flags in health endpoints considered information disclosure?