LlmtrimCAUTION
Local proxy that compresses your LLM API requests so you pay less, with no change to the answers. Trims wasted tokens from prompts, history, tool output, and code before they're sent: -31% input / -74% output, measured live. Any provider, no extra model calls. Also an MCP server and embeddable libra
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
llmtrim
Local proxy that compresses LLM API traffic so you pay less. Same answers, smaller bill.
−31% input · −74% output · −66% round-trip cost · 112 live A/B cases · ~5 ms/call · no model to load
Using Claude Code? One install also gets you /sub to serve it through CLIProxyAPI.
Proxy · CLI · MCP · library (Python · Ruby · Swift · Kotlin · JS/WASM)
What it does • Install •
382be9d3fbd6OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cli -- npx -y @llmtrim/[email protected] mcp
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (23)
icon.icns
gradle-wrapper.jar
return __import__(mod).__version__
" $env:HTTPS_PROXY = \"http://127.0.0.1:{}\"",println!("\nllmtrim input-side eval (Stage D only):");println!("\nllmtrim output-side eval (terse instruction input cost):");REPO := ../../..
.join("../../assets")let p = marker_path(dir, "../../etc/passwd");
serde_json::from_str(include_str!("../../bench/pricing.json")).unwrap_or(Value::Null)let input = include_str!("../../fixtures/tool_desc_workflow.txt");headroom on a different port (e.g. `http://127.0.0.1:9999`).
export HTTPS_PROXY=http://127.0.0.1:43117
export HTTP_PROXY=http://127.0.0.1:43117
HTTPS_PROXY=http://127.0.0.1:43117 curl --cacert ~/.llmtrim/ca.pem \
@tauri-apps/api, typescript, vite
export PATH="$HOME/.local/bin:$PATH" # add to ~/.bashrc or ~/.zshrc
exits non-zero, `update` prints the manual command for that channel (the `curl ... | sh`
curl -fsSL https://raw.githubusercontent.com/fkiene/llmtrim/main/install.sh | sh
curl -fsSL https://raw.githubusercontent.com/fkiene/llmtrim/main/install.sh | sh
| Binary (`curl \| sh`) | Re-runs the installer, restarts the daemon, runs `ensure` |
curl -fsSL https://raw.githubusercontent.com/fkiene/llmtrim/main/install.sh | sh
Gates applied: no_behavioural_pass.
382be9d3fbd6full audit observations/trust-audit/mcp-server/fkiene__llmtrim.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 382be9d3fbd6 | CAUTION | B | 81 | first audit |
Questions
What is the Llmtrim MCP server?
Local proxy that compresses your LLM API requests so you pay less, with no change to the answers. Trims wasted tokens from prompts, history, tool output, and code before they're sent: -31% input / -74% output, measured live. Any provider, no extra model calls. Also an MCP server and embeddable libra
Is Llmtrim safe to connect to an agent?
With care. The audit graded it B (81/100) and found 23 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Llmtrim need?
It reads OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Llmtrim run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as llmtrim-tray-ui at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (382be9d3fbd6), read on 2026-10-06. The repository is watched and re-audited when it changes.