The issue is the whole UX behind it. I have yet to see someone review the 30th prompt of "grep" - there is no same default or middle ground.
For example whitelist read actions or harness side limitations to the project folder.
This is just lazy - again. "Users don't use or very bad security feature so they just want us to disable it".
In short: yes. You can tune these values when self hosting - it basically changes the b chance which tokens will be used under which circumstances.