I now assume you talk about vulnerability of
important information, like password hashes and extended profile data like mails and clear names. The examples that you give are not really important information. Extended server info and
PPI are not really a big deal... (I guess you mean PPI in context of the programmable periphal interface. Or do you mean personal profile information? Because if you mean the second, then you should edit your OP and clarify this. This isnt an IT-professional forum, most people here are foreign language gamers and don't know what you mean with this fancy acronym.)
Yes, ofcourse you should look for such stuff. Shine is grateful if you send them information about such leaks via a private channel.
And if you put the word ethical into the context: It's also
very ethical to reveal
dangerous exploits to the public, if they don't get fixed in a reasonable time. I mean if you can find them, others can too. But be aware, dangerous is a broad term. I wouldn't call an IP reveal, or the reveal of client's Java version as dangerous. Dangerous exploits are for example vulnerability of extended login data, like password hashes, or extended Starmade profile information, like mail and clear names.
If you reveal how to hack the game to reveal client's IP adresses you are not helping, as this is not a major security flaw. It's a minor one, and fixing it can happen over time. (IP adresses can be read by every server owner and website owner, and is visitting any website in the www dangerous in itself?)
Please explain to me, why you think extended server information can be harmful though. It's just like knowing the IP or the client's browser version imo. If Starmade reveals critical server data it's another road ofcourse. But I doubt that the vague information about the server as you give them in your example, are really harmfull.