Armory
Source
Browse
MCPs

mcp01-token-mismanagement

A deliberately vulnerable MCP server demonstrating API key exposure through hardcoding, plaintext logging, and returning secrets to the model, part of the OWASP MCP Top 10 security lab.

Score
Unranked
Evidence
No signals yet
Last commit
as last read from GitHub; most reads are from 2 Sep 2026 or later
Listed

Install

No one-command install. Set it up from its source.

Alternatives · MCPs

  1. forest6511-secretctl9 stars · 6 forks68.921
  2. bishopfox-otto-support20 stars63.429
  3. brokenmcp14 stars59.854

What it is

A deliberately vulnerable MCP server demonstrating API key exposure through hardcoding, plaintext logging, and returning secrets to the model, part of the OWASP MCP Top 10 security lab.

When to use it

A deliberately vulnerable MCP server demonstrating API key exposure through hardcoding, plaintext logging, and returning secrets to the model, part of the OWASP MCP Top 10 security lab.

How to install / invoke

See Glama for the install config.

Notes

Listed from the Glama MCP registry.