Nothing in the repository records that unrestricted bot webhook delivery is deliberate, so the missing private-network guard reads as an oversight next to the guarded unfurl path. Researchers report it as server-side request forgery, repeatedly.