OpenRouter MCP Server (villagertim/universal-mcp-for-openrouter) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 24 tools. No publisher has claimed this listing.
An intelligent, agentic MCP server gateway to OpenRouter's 200+ AI models. It provides budget controls, security features, semantic memory, and code search capabilities.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
villagertim
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
get_balanceCheck your OpenRouter credit balance
get_key_infoGet information about the current API key (limits, usage, etc.)
correlate_errorsAnalyze log snippets from multiple systems to find root causes and correlations
dependency_graphAnalyze shared dependencies and semver conflicts across multiple projects
set_budgetSet a session-wide spending limit (in USD) and warning threshold
get_budget_statusCheck the current session spending and budget status
chat_completionGenerate a chat completion using an OpenRouter model
chat_with_presetGenerate a chat completion using a predefined model preset (smart, cheap, creative, fast, coder)
recommend_modelAnalyze a task and recommend the best model preset (smart, cheap, creative, fast, coder)
optimize_promptRefine and optimize a draft prompt using best practices for LLMs
chat_ensembleGenerate a consensus completion by querying multiple distinct models in parallel and synthesizing their responses using a synthesizer model.
chat_routedExecute a chat completion with intelligent, automatic cost-aware model routing based on prompt size, required context length, and task attributes.
index_projectScan a project directory to index symbols (functions, classes, variables) for cross-project awareness
search_symbolsSearch for symbols across all indexed projects
reindex_projectPerform deep semantic indexing of a project (code chunking + embeddings) for code search
semantic_code_searchSearch for code logic across indexed projects using natural language
pin_contextStore text with optional tags and project association for semantic retrieval
retrieve_contextSearch for semantically similar information in memory
clear_contextDelete entries from semantic memory by tag or project
list_modelsList available models on OpenRouter
filter_modelsFilter and search available OpenRouter models based on requirements (e.g. cost, context window, vision)
get_session_usageGet the total token usage and estimated cost for the current session
verify_setupPerform diagnostic checks on OpenRouter credentials, files, and server environment
vision_analyzeAnalyze an image (local file or URL) using a vision-capable model
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
Allocation of Resources Without Limits or Throttling in Axios
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
DISABLE_FAILOVERDISABLE_REDACTIONOPENROUTER_API_KEYIn Docker, inject the variable directly via -e =... or compose environment: — no .env file required inside the container.OPENROUTER_MCP_DATA_DIROPENROUTER_MCP_ENV_PATHThe server also checks ~/.config/openrouter-mcp/.env as a user-level override. Set to point to an alternative location if needed.PREFER_LOCAL_MODELSITE_NAMESITE_URLVITESTAll four hints declared on every tool
24/24 tools missing one or more hints — get_balance (missing: destructiveHint, idempotentHint, openWorldHint); get_key_info (missing: destructiveHint, idempotentHint, openWorldHint); correlate_errors (missing: readOnlyHint, destructiveHint, idempotentHint), +21 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
18/24 tools referenced in tests (75%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
2 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 7 high severity in production deps — axios@1.15.2 (high), axios@1.15.2 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/villagertim/universal-mcp-for-openrouter)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check