MCP01 Token MismanagementSecurityPenetration TestingAnita-aniFlicense-Not gradedqualityBmaintenanceA deliberately vulnerable MCP server demonstrating API key exposure through hardcoding, plaintext logging, and returning secrets to the model, part of the OWASP MCP Top 10 security lab. Updated a month ago (2026-07-24 08:49 UTC)-