Atlas / MCP servers / wheattoast11 / OpenRouter Agents

OpenRouter AgentsBLOCK

mcp/wheattoast11/openrouter-agents

A multi-agent research MCP server + mini client adapter - orchestrates a net of async agents or streaming swarm to conduct ensemble consensus-backed research. Each task builds its own indexed pglite database on the fly in web assembly. Includes semantic + hybrid search, SQL execution, semaphores, pr

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
23 21r · 2w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
55
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@terminals-tech/openrouter-agents) [](https://spec.modelcontextprotocol.io/specification/2025-11-25/) [](https://github.com/terminals-tech/openrouter-agents)

Production MCP server for multi-agent AI research. Plan, parallelize, synthesize.

Install

npx @terminals-tech/openrouter-agents --stdio

Claude Code one-liner:

claude mcp add openrouter-agents -- npx @terminals-tech/openrouter-agents --stdio

What's New (v2.0.0)

  • MCP SDK 1.27.1 — registerTool/registerPrompt/registerResource APIs, security fixes
  • Zod 4 — Upgraded from Zod 3; z.record() syntax, config schema fixes
  • Express 5 — Upgraded from Express 4; modern path patterns, req.query handling
  • Streamable HTTP — Primary transport (SSE deprecated as legacy fallback)
  • Circuit breaker — Model API fault tolerance with configurable thresholds
  • Embedding-based model routing — Local vector similarity for model selection (no LLM call)
  • Persistent storage — Reports, jobs, knowledge graph persist across sessions by default
macOS/Node 25 Note: A cosmetic libc++abi: mutex lock failed message may appear on shutdown. This is harmless — data is checkpointed before shutdown. Set DB_AUTO_HEAL=true for in-memory mode (no persistence, no message).

Full Changelog | Extensions Guide | MCP Compliance Report

Configuration

Set OPENROUTER_API_KEY in your environment, then configure via .env or .mcp.json:

Read from source at commit 5b6bb5815201OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add openrouter-agents --env ALLOW_NO_API_KEY=${ALLOW_NO_API_KEY} --env API_KEY=${API_KEY} --env AUTH_EXPECTED_AUD=${AUTH_EXPECTED_AUD} --env AUTH_JWKS_URL=${AUTH_JWKS_URL} -- npx -y @terminals-tech/[email protected]
claude-desktop
{
  "mcpServers": {
    "openrouter-agents": {
      "command": "npx",
      "args": [
        "-y",
        "@terminals-tech/[email protected]"
      ],
      "env": {
        "ALLOW_NO_API_KEY": "${ALLOW_NO_API_KEY}",
        "API_KEY": "${API_KEY}",
        "AUTH_EXPECTED_AUD": "${AUTH_EXPECTED_AUD}",
        "AUTH_JWKS_URL": "${AUTH_JWKS_URL}"
      }
    }
  }
}
03

Exposed tools (23)

21 read · 2 write · 0 destructive.

ToolRiskDescription
ActionreadDirect tool execution, file operations, or coding tasks
DialoguereadCasual conversation, greetings, and system meta-questions
ResearchreadDeep information retrieval, analysis, and synthesis
agentreadSingle entrypoint agent. Routes to research, follow_up, or retrieve/query with parameters.
batch_researchreadDispatch multiple research queries in single call. waitForCompletion:true waits and returns results.
calcreadEvaluate math: +,-,*,/,^,(), decimals. Accepts freeform expression or {expr}.
cancel_jobreadCancel running job. Requires job_id parameter.
conduct_researchreadSynchronous research; returns final text. Accepts freeform query or {query}.
date_timereadCurrent date/time. format:
get_job_statusreadAlias for job_status.
get_provider_healthreadProvider health metrics with model-level stats.
get_reportreadGet research report by ID. mode:
get_report_contentreadAlias for get_report.
get_server_statusreadServer health check - database, embedder, job queue status.
historyreadList recent research reports. Optional limit and queryFilter.
job_statusreadCheck async job progress. Requires job_id parameter. Returns terse status summary by default.
list_toolsreadShow all available tools with parameters.
pingreadHealth check. Returns pong, optionally with server info.
queryreadAlias for retrieve (sql mode): {sql, params?, explain?}.
researchwriteSubmit research query. async:true (default) returns job_id, async:false streams results. Requires query parameter.
retrievewriteSearch KB or run SQL. Freeform query = index; SQL text or mode:sql runs SELECT.
searchreadAlias for retrieve (index mode) with keys: q,k,scope.
search_toolsreadFind tools by semantic search. Requires query parameter.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (7 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (21)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
research_outputs/research-report-2.md:65
2.  **Context Loss:** Over long tasks, agents "forget" earlier instructions due to limited context windows.
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInventory / provenance · inv.symlink · CWE-1104
bin/openrouter-agents
bin/openrouter-agents
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
test-perplexity.js:5
console.log('API Key present:', Boolean(apiKey));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/server/elicitation.js:52
const isLocalhost = url.startsWith('http://localhost') || url.startsWith('http://127.0.0.1');
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/server/mcpServer.js:1800
allowedOrigins: ['http://localhost', 'http://127.0.0.1']
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcp.minimal.json
.mcp.minimal.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcp.optimized.json
.mcp.optimized.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please.json
.release-please.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/agents/contextAgent.js:3
const config = require('../../config');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/agents/contextAgent.js:307
const compact = require('../../config').prompts?.compact !== false;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/agents/planningAgent.js:3
const config = require('../../config');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/agents/researchAgent.js:2
const config = require('../../config');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/agents/researchAgent.js:16
const parallelism = require('../../config').models.parallelism || 4;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/OAUTH-SETUP.md:739
ARRAY['http://localhost:3000/oauth/callback', 'http://127.0.0.1:3000/oauth/callback'],
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/OAUTH-SETUP.md:1320
http://127.0.0.1:3000/oauth/callback  ✗ (different host)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@electric-sql/pglite, @inkjs/ui, @modelcontextprotocol/sdk, @terminals-tech/core, @terminals-tech/embeddings, @terminals-tech/graph, axios, chalk-animation
Why it matters. 26 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
research_outputs/research-report-2.md:62
*   **Metrics:** Academic benchmarks like **GAIA** and **AgentBench** measure performance based on task completion success rate, token cost, latency, and output accuracy [Source: GAIA Benchmark — http
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/OAUTH-SETUP.md:783
CREATE POLICY "Service role has full access to oauth_clients"
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/OAUTH-SETUP.md:788
CREATE POLICY "Service role has full access to device_codes"
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/OAUTH-SETUP.md:793
CREATE POLICY "Service role has full access to refresh_tokens"
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/OAUTH-SETUP.md:798
CREATE POLICY "Service role has full access to authorization_codes"

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 5b6bb5815201full audit observations/trust-audit/mcp-server/wheattoast11__openrouter-agents.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-085b6bb5815201BLOCKD69first audit
06

Questions

What is the OpenRouter Agents MCP server?

A multi-agent research MCP server + mini client adapter - orchestrates a net of async agents or streaming swarm to conduct ensemble consensus-backed research. Each task builds its own indexed pglite database on the fly in web assembly. Includes semantic + hybrid search, SQL execution, semaphores, pr

What tools does OpenRouter Agents expose?

23 in total: 21 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is OpenRouter Agents safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does OpenRouter Agents need?

It reads ALLOW_NO_API_KEY, API_KEY, AUTH_EXPECTED_AUD, AUTH_JWKS_URL, BING_API_KEY, BRAVE_API_KEY, ENTERPRISE_CLIENT_SECRET, GOOGLE_API_KEY, MIN_MAX_TOKENS, OPENROUTER_API_KEY, OPENROUTER_API_KEYS and OPENROUTER_KEY_COOLDOWN_MS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OpenRouter Agents run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @terminals-tech/openrouter-agents at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (5b6bb5815201), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement