MCPs โบ Data & APIs โบ MCP01 Token Mismanagement
A deliberately vulnerable MCP server demonstrating API key exposure through hardcoding, plaintext logging, and returning secrets to the model, part of the OWASP MCP Top 10 security lab.
Install MCP01 Token Mismanagement
For anyone using MCP01 Token Mismanagement โ no Lulu account needed# stdio server โ install per the repository README: https://github.com/anita-ani/mcp-security-lab
Real-time weather for any city, built on the lulu-ads widget gallery. First-party, free forever.
View server โFAQ
MCP01 Token Mismanagement installs from source โ follow the repository README.
3 out of 100, computed from cross-registry traction signals (installs, stars, registry presence) โ never influenced by sponsorship.
Similar servers
Works well together
Your server?
This is for the person who owns MCP01 Token Mismanagement โ adds Lulu Ads to your own code. Not the install steps above, those are for your users.
Copies a ready prompt: your coding agent installs the lulu-ads SDK, wires the slot, and applies the widget design guide.
or set up manually at getlulu.dev/publishers
Get verified so you can edit the page. Your badge is already live below โ no claim needed for that.
Managed hosting with monetization built in โ waitlist.
[](https://getlulu.dev/mcps/mcp01-token-mismanagement)