OP

openrouter-compliance-review

Reviews OpenRouter data handling and security posture to ensure alignment with compliance standards like GDPR and SOC2.

Install

mkdir -p .claude/skills/openrouter-compliance-review && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/6906" && unzip -o skill.zip -d .claude/skills/openrouter-compliance-review && rm skill.zip

Installs to .claude/skills/openrouter-compliance-review

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Review OpenRouter integration for regulatory compliance (SOC2, GDPR,
68 charsno explicit “when” trigger
Advanced

Key capabilities

  • Perform compliance checklist reviews
  • Classify workloads using a data classification matrix
  • Pin regulated traffic to specific providers
  • Scan source code for hardcoded API keys

How it works

The skill provides a checklist and scanning scripts to evaluate data handling, access control, and audit logging, while enforcing provider-pinned routing for regulated data.

Inputs & outputs

You give it
Integration source tree
You get back
Compliance review report

When to use openrouter-compliance-review

  • Perform SOC2 compliance review
  • Evaluate GDPR data handling
  • Conduct security audits
  • Document compliance posture

About this skill

OpenRouter Compliance Review

Overview

OpenRouter is a proxy that routes requests to upstream providers (OpenAI, Anthropic, Google, etc.). Compliance depends on both OpenRouter's data handling and the selected provider's policies. Key considerations: data transit through OpenRouter infrastructure, provider-specific data retention, model selection for regulated data, and audit trail requirements.

Prerequisites

  • An OpenRouter API key (sk-or-v1-...) exported as OPENROUTER_API_KEY — see the openrouter-install-auth skill for setup
  • Python 3.8+ with the OpenAI SDK for provider-pinned requests and the automated checker in the references
  • curl and jq to run the Compliance Audit Script
  • An existing OpenRouter integration to review — the audit script scans its source tree for hardcoded sk-or-v1- keys
  • Knowledge of which regimes apply (SOC2, GDPR, HIPAA) and how your data is classified

Instructions

  1. Work through the four areas of the Compliance Checklist — data_handling, access_control, audit_trail, and provider_selection — recording pass/fail per item.
  2. Classify each workload with the Data Classification Matrix (Public → Internal → Confidential → Restricted/PHI) to determine allowed providers and required controls.
  3. Pin regulated traffic per Provider Routing for Compliance: set provider.order plus allow_fallbacks: False, then verify response.model confirms the approved provider actually served the request.
  4. For data-sovereignty requirements, configure BYOK per BYOK for Data Sovereignty so inference runs on your own provider account and OpenRouter only routes.
  5. Run the Compliance Audit Script: key label/limit check via GET /api/v1/auth/key, a free-tier warning (free tier is unsuitable for regulated data), and the hardcoded-key scan.
  6. Document the data flow for auditors — client → OpenRouter (routing) → provider (inference) — per Enterprise Considerations.

Compliance Checklist

COMPLIANCE_CHECKLIST = {
    "data_handling": [
        "Verify OpenRouter does NOT train on your data (confirmed in their privacy policy)",
        "Confirm provider-level data policies (OpenAI, Anthropic, Google each differ)",
        "Document data flow: your app -> OpenRouter -> provider -> OpenRouter -> your app",
        "Identify if prompts contain PII, PHI, or regulated data",
        "Implement PII redaction before sending to API",
    ],
    "access_control": [
        "Use per-service API keys (not shared keys)",
        "Set credit limits per key to isolate blast radius",
        "Rotate keys on a 90-day schedule",
        "Store keys in secrets manager (not .env files in repos)",
        "Enable management keys for programmatic key provisioning",
    ],
    "audit_trail": [
        "Log every API call with generation_id, model, user_id, cost",
        "Hash prompts (SHA-256) instead of logging raw content",
        "Retain audit logs per regulation (90d operational, 7yr financial)",
        "Ship logs to append-only storage (S3, immutable DB)",
    ],
    "provider_selection": [
        "Route regulated data only to compliant providers",
        "Use provider routing to exclude non-compliant providers",
        "Document which models are approved for which data classifications",
        "Test that fallback routing doesn't route to unapproved providers",
    ],
}

Provider Routing for Compliance

import os
from openai import OpenAI

client = OpenAI(
    base_url="https://openrouter.ai/api/v1",
    api_key=os.environ["OPENROUTER_API_KEY"],
    default_headers={"HTTP-Referer": "https://my-app.com", "X-Title": "my-app"},
)

# Route ONLY to specific providers (e.g., Anthropic for SOC2)
response = client.chat.completions.create(
    model="anthropic/claude-3.5-sonnet",
    messages=[{"role": "user", "content": "Analyze this contract..."}],
    max_tokens=2048,
    extra_body={
        "provider": {
            "order": ["Anthropic"],        # Only Anthropic's infrastructure
            "allow_fallbacks": False,       # Do NOT fall back to other providers
        },
    },
)

# Verify which provider actually served the request
print(f"Served by: {response.model}")  # Should match anthropic/claude-3.5-sonnet

Data Classification Matrix

ClassificationAllowed ProvidersControls
PublicAny (including :free)Standard logging
InternalTier 1 (OpenAI, Anthropic, Google)Audit logging, key limits
ConfidentialAnthropic, OpenAI (API-only)PII redaction, no free models
Restricted/PHIBYOK only or self-hostedFull audit, encryption at rest

BYOK for Data Sovereignty

# Bring Your Own Key -- requests go directly to provider
# OpenRouter acts as router only; data doesn't persist on OpenRouter
response = client.chat.completions.create(
    model="openai/gpt-4o",
    messages=[{"role": "user", "content": "Process this..."}],
    max_tokens=1024,
    extra_body={
        "provider": {
            "order": ["OpenAI"],
            "allow_fallbacks": False,
        },
    },
    # With BYOK, configure your provider key in OpenRouter dashboard
    # Data flows: your app -> OpenRouter (routing only) -> OpenAI (your account)
)

Compliance Audit Script

#!/bin/bash
echo "=== OpenRouter Compliance Audit ==="

# 1. Verify API key has credit limit set
echo "1. Key configuration:"
curl -s https://openrouter.ai/api/v1/auth/key \
  -H "Authorization: Bearer $OPENROUTER_API_KEY" | \
  jq '{label: .data.label, limit: .data.limit, is_free_tier: .data.is_free_tier}'

# 2. Check if using free tier (not suitable for regulated data)
IS_FREE=$(curl -s https://openrouter.ai/api/v1/auth/key \
  -H "Authorization: Bearer $OPENROUTER_API_KEY" | jq -r '.data.is_free_tier')
[ "$IS_FREE" = "true" ] && echo "WARNING: Free tier. Not suitable for regulated data."

# 3. Scan for hardcoded keys in source
FOUND=$(grep -r "sk-or-v1-" --include="*.py" --include="*.ts" --include="*.js" . 2>/dev/null | grep -v node_modules | wc -l)
echo "Hardcoded keys found: $FOUND"

Output

  • A pass/fail/warn compliance report from the automated checker in the references, one line per control (API key storage, HTTPS enforcement, max_tokens, error handling, audit logging)
  • Key-configuration JSON (label, limit, is_free_tier) plus a free-tier warning and a count of hardcoded keys found in source, from the Compliance Audit Script
  • A provider-pinned client configuration (provider.order + allow_fallbacks: False) that cannot route regulated data to unapproved providers
  • A filled-in markdown compliance checklist (template in the references) covering security, data privacy, reliability, observability, and cost controls

Examples

Running run_compliance_review() from the references against a healthy integration:

Compliance: 5/5 passed, 0 failed, 0 warnings
  [OK] api_key_storage: Key loaded from environment variable
  [OK] https_enforcement: HTTPS enforced
  [OK] max_tokens: max_tokens set to 500
  [OK] error_handling: Error handling present
  [OK] audit_logging: Audit logging configured

Any [FAIL] line maps to a checklist item above — fix it and re-run until clean. More worked examples: references/examples.md.

Error Handling

ErrorCauseFix
Request routed to unapproved providerallow_fallbacks: true (default)Set allow_fallbacks: false with explicit order
Key exposed in logsRaw API key loggedAdd PII redaction for sk-or-v1-* pattern
No audit trail for requestLogging middleware bypassedMake audit logging a required wrapper
Free model used for regulated dataNo model allowlistImplement model allowlist in client wrapper

Enterprise Considerations

  • OpenRouter does not train on API data, but upstream providers may have different terms for API vs consumer use
  • Use provider.order + allow_fallbacks: false to guarantee data only flows to approved providers
  • BYOK eliminates OpenRouter as a data processor for inference (routing metadata still transits)
  • Document the data flow diagram for auditors: client -> OpenRouter (routing) -> provider (inference)
  • Implement client-side PII redaction as defense-in-depth
  • Consider self-hosted or VPC deployments for restricted/PHI data

References

When not to use it

  • Non-regulated data environments

Prerequisites

OpenRouter API keyPython 3.8+curl and jq

Limitations

  • Free tier is unsuitable for regulated data

How it compares

It automates the validation of compliance controls and provider routing configurations, rather than relying on manual audit documentation.

Compared to similar skills

openrouter-compliance-review side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
openrouter-compliance-review (this skill)127dCautionAdvanced
senior-security317moReviewAdvanced
security-header-generator59moCautionIntermediate
backend-security-coder244moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

senior-security

davila7

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

3191

security-header-generator

Dexploarer

Generates security HTTP headers (CSP, HSTS, CORS, etc.) for web applications to prevent common attacks. Use when user asks to "add security headers", "setup CSP", "configure CORS", "secure headers", or "HSTS setup".

599

backend-security-coder

sickn33

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

2446

security-audit

ruvnet

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.

337

security-best-practices

openai

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

732

pcap-analysis

benchflow-ai

Guidance for analyzing network packet captures (PCAP files) and computing network statistics using Python, with tested utility functions.

713

Search skills

Search the agent skills registry