What should a public debug endpoint avoid exposing in API responses?