Is it safe to install pbm-agent on server with public IP address?

I wanted to know if it is safe from a security point of view to install the pbm-agent on machines with a public IP address. I don’t really understand how the security mechanism works between the pbm-agent and the pbm cli.
pbm-agent connects to mongodb with a mongodb user and password but how do they communicate securely between the pbm cli and the pbm-agent?

Thank you for support