Atlas / MCP servers / fkiene / Llmtrim

LlmtrimCAUTION

mcp/fkiene/llmtrim

Local proxy that compresses your LLM API requests so you pay less, with no change to the answers. Trims wasted tokens from prompts, history, tool output, and code before they're sent: -31% input / -74% output, measured live. Any provider, no extra model calls. Also an MCP server and embeddable libra

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
—
Transport
stdio
License
MPL-2.0
Stars
244
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

llmtrim

Local proxy that compresses LLM API traffic so you pay less. Same answers, smaller bill.

−31% input · −74% output · −66% round-trip cost · 112 live A/B cases · ~5 ms/call · no model to load

Using Claude Code? One install also gets you /sub to serve it through CLIProxyAPI.

Proxy · CLI · MCP · library (Python · Ruby · Swift · Kotlin · JS/WASM)

What it does • Install •

Read from source at commit 382be9d3fbd6OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add cli -- npx -y @llmtrim/[email protected] mcp
03

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (6 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (23)

MEDIUMInventory / provenance · inv.binary · CWE-1104
crates/llmtrim-tray/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
crates/llmtrim-uniffi/packaging/kotlin/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
crates/llmtrim-cli/bench/scripts/benchkit/gate.py:97
return __import__(mod).__version__
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/llmtrim-cli/src/main.rs:2055
"  $env:HTTPS_PROXY = \"http://127.0.0.1:{}\"",
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/llmtrim-core/tests/eval.rs:43
println!("\nllmtrim input-side eval (Stage D only):");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/llmtrim-core/tests/output.rs:110
println!("\nllmtrim output-side eval (terse instruction input cost):");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/llmtrim-cli/bench/Makefile:12
REPO     := ../../..
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/llmtrim-cli/src/breakdown/app.rs:3535
.join("../../assets")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/llmtrim-cli/src/guard.rs:1015
let p = marker_path(dir, "../../etc/passwd");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/llmtrim-cli/src/reroute/catalog.rs:16
serde_json::from_str(include_str!("../../bench/pricing.json")).unwrap_or(Value::Null)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/llmtrim-core/src/provider/mod.rs:1306
let input = include_str!("../../fixtures/tool_desc_workflow.txt");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CHANGELOG.md:1296
headroom on a different port (e.g. `http://127.0.0.1:9999`).
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
HERMES.md:30
export HTTPS_PROXY=http://127.0.0.1:43117
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
HERMES.md:31
export HTTP_PROXY=http://127.0.0.1:43117
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
HERMES.md:104
HTTPS_PROXY=http://127.0.0.1:43117 curl --cacert ~/.llmtrim/ca.pem \
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
crates/llmtrim-tray/package.json
@tauri-apps/api, typescript, vite
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
INSTALL.md:42
export PATH="$HOME/.local/bin:$PATH"   # add to ~/.bashrc or ~/.zshrc
Why it matters. instructs the agent to persist itself in the user's environment
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CHANGELOG.md:1197
exits non-zero, `update` prints the manual command for that channel (the `curl ... | sh`
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL.md:27
curl -fsSL https://raw.githubusercontent.com/fkiene/llmtrim/main/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL.md:36
curl -fsSL https://raw.githubusercontent.com/fkiene/llmtrim/main/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL.md:137
| Binary (`curl \| sh`) | Re-runs the installer, restarts the daemon, runs `ensure` |
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:105
curl -fsSL https://raw.githubusercontent.com/fkiene/llmtrim/main/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 382be9d3fbd6full audit observations/trust-audit/mcp-server/fkiene__llmtrim.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06382be9d3fbd6CAUTIONB81first audit
05

Questions

What is the Llmtrim MCP server?

Local proxy that compresses your LLM API requests so you pay less, with no change to the answers. Trims wasted tokens from prompts, history, tool output, and code before they're sent: -31% input / -74% output, measured live. Any provider, no extra model calls. Also an MCP server and embeddable libra

Is Llmtrim safe to connect to an agent?

With care. The audit graded it B (81/100) and found 23 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Llmtrim need?

It reads OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Llmtrim run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as llmtrim-tray-ui at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (382be9d3fbd6), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement