OpenRouter MCP Server (villagertim/universal-mcp-for-openrouter) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 24 tools. No publisher has claimed this listing.

D
Caution
56/100

OpenRouter MCP Server

An intelligent, agentic MCP server gateway to OpenRouter's 200+ AI models. It provides budget controls, security features, semantic memory, and code search capabilities.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

villagertim

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 7 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: OPENROUTER_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes24 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

get_balance

Check your OpenRouter credit balance

get_key_info

Get information about the current API key (limits, usage, etc.)

correlate_errors

Analyze log snippets from multiple systems to find root causes and correlations

dependency_graph

Analyze shared dependencies and semver conflicts across multiple projects

set_budget

Set a session-wide spending limit (in USD) and warning threshold

get_budget_status

Check the current session spending and budget status

chat_completion

Generate a chat completion using an OpenRouter model

chat_with_preset

Generate a chat completion using a predefined model preset (smart, cheap, creative, fast, coder)

recommend_model

Analyze a task and recommend the best model preset (smart, cheap, creative, fast, coder)

optimize_prompt

Refine and optimize a draft prompt using best practices for LLMs

chat_ensemble

Generate a consensus completion by querying multiple distinct models in parallel and synthesizing their responses using a synthesizer model.

chat_routed

Execute a chat completion with intelligent, automatic cost-aware model routing based on prompt size, required context length, and task attributes.

index_project

Scan a project directory to index symbols (functions, classes, variables) for cross-project awareness

search_symbols

Search for symbols across all indexed projects

reindex_project

Perform deep semantic indexing of a project (code chunking + embeddings) for code search

semantic_code_search

Search for code logic across indexed projects using natural language

pin_context

Store text with optional tags and project association for semantic retrieval

retrieve_context

Search for semantically similar information in memory

clear_context

Delete entries from semantic memory by tag or project

list_models

List available models on OpenRouter

filter_models

Filter and search available OpenRouter models based on requirements (e.g. cost, context window, vision)

get_session_usage

Get the total token usage and estimated cost for the current session

verify_setup

Perform diagnostic checks on OpenRouter credentials, files, and server environment

vision_analyze

Analyze an image (local file or URL) using a vision-capable model

// known CVEs in dependencies7 high9 medium2 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highaxios@1.15.2GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.15.2GHSA-777c-7fjr-54vf

Allocation of Resources Without Limits or Throttling in Axios

highaxios@1.15.2GHSA-gcfj-64vw-6mp9

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

highaxios@1.15.2GHSA-hfxv-24rg-xrqf

Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

highaxios@1.15.2GHSA-j5f8-grm9-p9fc

Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configDISABLE_FAILOVER
configDISABLE_REDACTION
🔐 secretOPENROUTER_API_KEYIn Docker, inject the variable directly via -e =... or compose environment: — no .env file required inside the container.
configOPENROUTER_MCP_DATA_DIR
configOPENROUTER_MCP_ENV_PATHThe server also checks ~/.config/openrouter-mcp/.env as a user-level override. Set to point to an alternative location if needed.
configPREFER_LOCAL_MODEL
configSITE_NAME
configSITE_URL
configVITEST
// quality suggestions

All four hints declared on every tool

24/24 tools missing one or more hints — get_balance (missing: destructiveHint, idempotentHint, openWorldHint); get_key_info (missing: destructiveHint, idempotentHint, openWorldHint); correlate_errors (missing: readOnlyHint, destructiveHint, idempotentHint), +21 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

18/24 tools referenced in tests (75%)

Write tests that reference each tool by name so every tool has at least one test.

Shell command execution

2 child_process calls — runs shell commands

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Production dependencies are patched

0 critical, 7 high severity in production deps — axios@1.15.2 (high), axios@1.15.2 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/villagertim/universal-mcp-for-openrouter?variant=verified)](https://m8ven.ai/mcp/villagertim/universal-mcp-for-openrouter)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 192ed3fc69b3bce619953e6435b6ce4284a113b8
code hash: 213aeca9b1ff81940be9e87c4669892f323a61eeac60e13da7cd1e8465b3fdd9
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client