Gotcha: GitHub Custom Properties are public

I was speaking to someone the other day - while I've been at Open Source Summit (Europe) - about the great Custom Properties that GitHub added in ~2023.
However, they weren't aware that they're available to anyone with read access to the repo - which means for a public repo, that's everyone!
This was something we found at Elastic while we were rolling out something that sounds pretty juicy called security_level. This was a mandatory field across all our repos, which was set to a reasonable default value.
We ideally wanted to have our Custom Properties' descriptions include more context about what the security level fields meant, and a link to our internal docs for more in-depth information and how to change it.
At Elastic we had a lot of Open Source (and public repos which are not-Open Source), which meant that anyone would be able to look up the descriptions of these fields.
We can see this in action on i.e. github/gh-stack by using the API:
[
{
"property_name": "client-app",
"value": "false"
},
{
"property_name": "CodeQL-Block",
"value": "true"
},
{
"property_name": "dependency-review-action-enabled",
"value": "true"
},
{
"property_name": "deployable",
"value": "false"
},
{
"property_name": "durable-ownership-check-enabled",
"value": "false"
},
{
"property_name": "ownership-name",
"value": "@github/pull-requests"
},
{
"property_name": "ownership-type",
"value": "Team"
},
{
"property_name": "repo-mirror-ci",
"value": "disabled"
},
{
"property_name": "repo-mirror-strategy",
"value": "standard"
}
]
You can also see this in the web UI, which can be found on each repo's homepage, following the link to "Custom Properties".
Notice that in the web UI, you can see the description of the field, which isn't - as far as I can find - available through an API call if you're not part of the organisation.
This does appear to be visibly documented by GitHub - but is something folks seem to not be aware of!