Atlas / MCP servers / 0xzr / FreeLLM Pool

FreeLLM PoolCAUTION

mcp/0xzr/freellm-pool

Free LLM gateway: 22 LLM providers, 178 enabled chat routes, 431 cataloged chat models; keyless start when available.

Verdict
CAUTION
Grade
D
Trust score
68 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
120
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

freellmpool catalogs 23 LLM providers as distinct groups spanning recurring free tiers, keyless endpoints, finite trials, pin-only routes, and disabled candidates. It exposes 178 enabled chat routes and 443 cataloged chat models, and automatically pools only enabled routes you can access behind one OpenAI-compatible endpoint — as a CLI, a Python library, or a local proxy. It can start without credentials when an enabled keyless route is available.

[](https://pypi.org/project/freellmpool/) [](https://github.com/0xzr/freellmpool/actions/workflows/ci.yml) [](LICENSE) [](https://0xzr.github.io/freellmpool/)

FAQ: where prompts go, ToS posture, failover, bans, and comparisons.

Release and distribution status

  • Latest release: 0.13.0. The GitHub release and PyPI package are both

0.13.0; pip install freellmpool and uvx freellmpool install the audited provider catalog, bounded streaming and sentinel hardening, Hermes profile, proxy readiness/provider APIs, spread routing, and OpenCode registry-readiness hardening.

  • Registry publication status: pending. opencode-freellmpool and

opencode-freellmpool-tui are tested but not published on npm as of 2026-08-29. Use their repository-local installation instructions for now.

30-second quickstart

Fresh install to first free-model reply is measured at about 19 seconds under the 30-second target on a clean Linux/Python 3.12 environment, with no API keys when a keyless provider is u

Read from source at commit 75d19dda9f4bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add freellmpool -- uvx freellmpool==0.13.0 mcp
03

Trust audit

CAUTIONgrade D · trust 68/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (24)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:30
CMD python -c "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8080/healthz', timeout=2)"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_catalog_sentinel.py:791
secret = "super-secret-provider-key"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_cli.py:367
secret = "provider-secret-value"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_cli.py:940
secret = "doctor-provider-secret"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_cli.py:973
secret = "malformed-secret-must-not-appear"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_cli.py:1653
secret = "sentinel-playground-proxy-secret"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coverage-thresholds.json
.coverage-thresholds.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_supply_chain.py:574
({"id": "../../escape"}, "id"),
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
tests/test_security.py:92
assert _client().follow_redirects is False  # SSRF-via-redirect / key-exfil guard
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/test_security.py:19
"http://169.254.169.254/latest/meta-data",  # cloud metadata (link-local)
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/ci.yml:187
if response=$(curl --fail --silent http://127.0.0.1:18080/healthz) && \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/docker.yml:113
if response=$(curl --fail --silent http://127.0.0.1:18080/healthz) && \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:96
loopback URLs such as `http://127.0.0.1:1234/v1`; hostnames, LAN addresses,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CAPACITY.md:151
http://127.0.0.1:8080/dashboard
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/audit_frontier_sources.py:70
raw = base64.b64decode(blob.get("content", ""), validate=False)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_conformance.py:397
raw = base64.b64decode(encoded, validate=True)
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:241
For the bundled Open WebUI stack, place any provider credentials in `.env` and
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/ACCOUNTS.md:38
2. Open **API Keys** → **Generate key**, copy it (`csk-...`).
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/mcp-listings/glama-submission.md:55
secrets. Optional provider keys are read from environment variables or local
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
.beads/README.md:64
curl -sSL https://raw.githubusercontent.com/steveyegge/beads/main/scripts/install.sh | bash
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
FAQ.md:17
| `pollinations` | `https://text.pollinations.ai/openai` | Keyless | Not stated in the catalog; Pollinations publishes privacy and terms pages. | Anonymous keyless endpoint; do not send secrets unless
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
FAQ.md:63
## Does freellmpool share my API keys?
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 75d19dda9f4bfull audit observations/trust-audit/mcp-server/0xzr__freellm-pool.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0875d19dda9f4bCAUTIOND68first audit
05

Questions

What is the FreeLLM Pool MCP server?

Free LLM gateway: 22 LLM providers, 178 enabled chat routes, 431 cataloged chat models; keyless start when available.

Is FreeLLM Pool safe to connect to an agent?

With care. The audit graded it D (68/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does FreeLLM Pool need?

It reads FREELLMPOOL_AA_API_KEY, FREELLMPOOL_CONFORMANCE_KEYS_JSON, FREELLMPOOL_KEYS_PATH and FREELLMPOOL_PROXY_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does FreeLLM Pool run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as opencode-freellmpool at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (75d19dda9f4b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement