FreeLLM PoolCAUTION
Free LLM gateway: 22 LLM providers, 178 enabled chat routes, 431 cataloged chat models; keyless start when available.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
freellmpool catalogs 23 LLM providers as distinct groups spanning recurring free tiers, keyless endpoints, finite trials, pin-only routes, and disabled candidates. It exposes 178 enabled chat routes and 443 cataloged chat models, and automatically pools only enabled routes you can access behind one OpenAI-compatible endpoint — as a CLI, a Python library, or a local proxy. It can start without credentials when an enabled keyless route is available.
[](https://pypi.org/project/freellmpool/) [](https://github.com/0xzr/freellmpool/actions/workflows/ci.yml) [](LICENSE) [](https://0xzr.github.io/freellmpool/)
FAQ: where prompts go, ToS posture, failover, bans, and comparisons.
Release and distribution status
- Latest release: 0.13.0. The GitHub release and PyPI package are both
0.13.0; pip install freellmpool and uvx freellmpool install the audited provider catalog, bounded streaming and sentinel hardening, Hermes profile, proxy readiness/provider APIs, spread routing, and OpenCode registry-readiness hardening.
- Registry publication status: pending.
opencode-freellmpooland
opencode-freellmpool-tui are tested but not published on npm as of 2026-08-29. Use their repository-local installation instructions for now.
30-second quickstart
Fresh install to first free-model reply is measured at about 19 seconds under the 30-second target on a clean Linux/Python 3.12 environment, with no API keys when a keyless provider is u
75d19dda9f4bOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add freellmpool -- uvx freellmpool==0.13.0 mcp
Trust audit
CAUTIONgrade D · trust 68/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (24)
CMD python -c "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8080/healthz', timeout=2)"secret = "super-secret-provider-key"
secret = "provider-secret-value"
secret = "doctor-provider-secret"
secret = "malformed-secret-must-not-appear"
secret = "sentinel-playground-proxy-secret"
.coverage-thresholds.json
.nojekyll
({"id": "../../escape"}, "id"),assert _client().follow_redirects is False # SSRF-via-redirect / key-exfil guard
"http://169.254.169.254/latest/meta-data", # cloud metadata (link-local)
if response=$(curl --fail --silent http://127.0.0.1:18080/healthz) && \
if response=$(curl --fail --silent http://127.0.0.1:18080/healthz) && \
loopback URLs such as `http://127.0.0.1:1234/v1`; hostnames, LAN addresses,
http://127.0.0.1:8080/dashboard
raw = base64.b64decode(blob.get("content", ""), validate=False)raw = base64.b64decode(encoded, validate=True)
For the bundled Open WebUI stack, place any provider credentials in `.env` and
2. Open **API Keys** → **Generate key**, copy it (`csk-...`).
secrets. Optional provider keys are read from environment variables or local
curl -sSL https://raw.githubusercontent.com/steveyegge/beads/main/scripts/install.sh | bash
| `pollinations` | `https://text.pollinations.ai/openai` | Keyless | Not stated in the catalog; Pollinations publishes privacy and terms pages. | Anonymous keyless endpoint; do not send secrets unless
## Does freellmpool share my API keys?
Gates applied: no_behavioural_pass.
75d19dda9f4bfull audit observations/trust-audit/mcp-server/0xzr__freellm-pool.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 75d19dda9f4b | CAUTION | D | 68 | first audit |
Questions
What is the FreeLLM Pool MCP server?
Free LLM gateway: 22 LLM providers, 178 enabled chat routes, 431 cataloged chat models; keyless start when available.
Is FreeLLM Pool safe to connect to an agent?
With care. The audit graded it D (68/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does FreeLLM Pool need?
It reads FREELLMPOOL_AA_API_KEY, FREELLMPOOL_CONFORMANCE_KEYS_JSON, FREELLMPOOL_KEYS_PATH and FREELLMPOOL_PROXY_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does FreeLLM Pool run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as opencode-freellmpool at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (75d19dda9f4b), read on 2026-10-08. The repository is watched and re-audited when it changes.