OpenRouter AgentsBLOCK
A multi-agent research MCP server + mini client adapter - orchestrates a net of async agents or streaming swarm to conduct ensemble consensus-backed research. Each task builds its own indexed pglite database on the fly in web assembly. Includes semantic + hybrid search, SQL execution, semaphores, pr
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@terminals-tech/openrouter-agents) [](https://spec.modelcontextprotocol.io/specification/2025-11-25/) [](https://github.com/terminals-tech/openrouter-agents)
Production MCP server for multi-agent AI research. Plan, parallelize, synthesize.
Install
npx @terminals-tech/openrouter-agents --stdio
Claude Code one-liner:
claude mcp add openrouter-agents -- npx @terminals-tech/openrouter-agents --stdio
What's New (v2.0.0)
- MCP SDK 1.27.1 — registerTool/registerPrompt/registerResource APIs, security fixes
- Zod 4 — Upgraded from Zod 3; z.record() syntax, config schema fixes
- Express 5 — Upgraded from Express 4; modern path patterns, req.query handling
- Streamable HTTP — Primary transport (SSE deprecated as legacy fallback)
- Circuit breaker — Model API fault tolerance with configurable thresholds
- Embedding-based model routing — Local vector similarity for model selection (no LLM call)
- Persistent storage — Reports, jobs, knowledge graph persist across sessions by default
macOS/Node 25 Note: A cosmeticlibc++abi: mutex lock failedmessage may appear on shutdown. This is harmless — data is checkpointed before shutdown. SetDB_AUTO_HEAL=truefor in-memory mode (no persistence, no message).
Full Changelog | Extensions Guide | MCP Compliance Report
Configuration
Set OPENROUTER_API_KEY in your environment, then configure via .env or .mcp.json:
5b6bb5815201OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add openrouter-agents --env ALLOW_NO_API_KEY=${ALLOW_NO_API_KEY} --env API_KEY=${API_KEY} --env AUTH_EXPECTED_AUD=${AUTH_EXPECTED_AUD} --env AUTH_JWKS_URL=${AUTH_JWKS_URL} -- npx -y @terminals-tech/[email protected]{
"mcpServers": {
"openrouter-agents": {
"command": "npx",
"args": [
"-y",
"@terminals-tech/[email protected]"
],
"env": {
"ALLOW_NO_API_KEY": "${ALLOW_NO_API_KEY}",
"API_KEY": "${API_KEY}",
"AUTH_EXPECTED_AUD": "${AUTH_EXPECTED_AUD}",
"AUTH_JWKS_URL": "${AUTH_JWKS_URL}"
}
}
}
}Exposed tools (23)
21 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Action | read | Direct tool execution, file operations, or coding tasks |
Dialogue | read | Casual conversation, greetings, and system meta-questions |
Research | read | Deep information retrieval, analysis, and synthesis |
agent | read | Single entrypoint agent. Routes to research, follow_up, or retrieve/query with parameters. |
batch_research | read | Dispatch multiple research queries in single call. waitForCompletion:true waits and returns results. |
calc | read | Evaluate math: +,-,*,/,^,(), decimals. Accepts freeform expression or {expr}. |
cancel_job | read | Cancel running job. Requires job_id parameter. |
conduct_research | read | Synchronous research; returns final text. Accepts freeform query or {query}. |
date_time | read | Current date/time. format: |
get_job_status | read | Alias for job_status. |
get_provider_health | read | Provider health metrics with model-level stats. |
get_report | read | Get research report by ID. mode: |
get_report_content | read | Alias for get_report. |
get_server_status | read | Server health check - database, embedder, job queue status. |
history | read | List recent research reports. Optional limit and queryFilter. |
job_status | read | Check async job progress. Requires job_id parameter. Returns terse status summary by default. |
list_tools | read | Show all available tools with parameters. |
ping | read | Health check. Returns pong, optionally with server info. |
query | read | Alias for retrieve (sql mode): {sql, params?, explain?}. |
research | write | Submit research query. async:true (default) returns job_id, async:false streams results. Requires query parameter. |
retrieve | write | Search KB or run SQL. Freeform query = index; SQL text or mode:sql runs SELECT. |
search | read | Alias for retrieve (index mode) with keys: q,k,scope. |
search_tools | read | Find tools by semantic search. Requires query parameter. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (21)
2. **Context Loss:** Over long tasks, agents "forget" earlier instructions due to limited context windows.
bin/openrouter-agents
console.log('API Key present:', Boolean(apiKey));const isLocalhost = url.startsWith('http://localhost') || url.startsWith('http://127.0.0.1');allowedOrigins: ['http://localhost', 'http://127.0.0.1']
.mcp.minimal.json
.mcp.optimized.json
.release-please.json
const config = require('../../config');const compact = require('../../config').prompts?.compact !== false;const config = require('../../config');const config = require('../../config');const parallelism = require('../../config').models.parallelism || 4;ARRAY['http://localhost:3000/oauth/callback', 'http://127.0.0.1:3000/oauth/callback'],
http://127.0.0.1:3000/oauth/callback ✗ (different host)
@electric-sql/pglite, @inkjs/ui, @modelcontextprotocol/sdk, @terminals-tech/core, @terminals-tech/embeddings, @terminals-tech/graph, axios, chalk-animation
* **Metrics:** Academic benchmarks like **GAIA** and **AgentBench** measure performance based on task completion success rate, token cost, latency, and output accuracy [Source: GAIA Benchmark — http
CREATE POLICY "Service role has full access to oauth_clients"
CREATE POLICY "Service role has full access to device_codes"
CREATE POLICY "Service role has full access to refresh_tokens"
CREATE POLICY "Service role has full access to authorization_codes"
Gates applied: instruction_override, no_behavioural_pass.
5b6bb5815201full audit observations/trust-audit/mcp-server/wheattoast11__openrouter-agents.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 5b6bb5815201 | BLOCK | D | 69 | first audit |
Questions
What is the OpenRouter Agents MCP server?
A multi-agent research MCP server + mini client adapter - orchestrates a net of async agents or streaming swarm to conduct ensemble consensus-backed research. Each task builds its own indexed pglite database on the fly in web assembly. Includes semantic + hybrid search, SQL execution, semaphores, pr
What tools does OpenRouter Agents expose?
23 in total: 21 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is OpenRouter Agents safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does OpenRouter Agents need?
It reads ALLOW_NO_API_KEY, API_KEY, AUTH_EXPECTED_AUD, AUTH_JWKS_URL, BING_API_KEY, BRAVE_API_KEY, ENTERPRISE_CLIENT_SECRET, GOOGLE_API_KEY, MIN_MAX_TOKENS, OPENROUTER_API_KEY, OPENROUTER_API_KEYS and OPENROUTER_KEY_COOLDOWN_MS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does OpenRouter Agents run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @terminals-tech/openrouter-agents at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (5b6bb5815201), read on 2026-10-08. The repository is watched and re-audited when it changes.