ive seen too many devs treat a
Disallow
rule like its some kind of magic cloak. the real danger is when people accidentally leak sensitive paths in the file itself, basically providing a
roadmap for attackers to find the stuff you actually want to hide. if its not behind an auth wall or restricted by ip, its essentially public knowledge.