A java engineer who has worked in a large company for 10 years provided me with an interface to send sql statements to him for execution. I cautiously asked him whether he had made a mechanism to prevent malicious code injection, and the answer was no, so I warned him not to be taken seriously, how should I report it to the leader?