Agent skill

Openrouter Compliance Review

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Review OpenRouter integration for regulatory compliance (SOC2, GDPR, HIPAA).

MITAuto-check: notesLegal & Compliance

Install Openrouter Compliance Review

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill openrouter-compliance-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace openrouter-compliance-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/openrouter-compliance-review .claude/skills/openrouter-compliance-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openrouter-compliance-review
GitHub stars
2.8k
Token cost
~2.3k tokens
SKILL.md length
556 words
Files
8 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Review OpenRouter integration for regulatory compliance (SOC2, GDPR, HIPAA).

  • Works in 6 steps: Work through the four areas of the… → Classify each workload with the Data… → Pin regulated traffic per Provider… → …
  • Preparing for audits
  • SKILL.md covers Overview, Prerequisites, Instructions and Compliance Checklist, plus 9 more sections
  • Calls curl and jq; reaches openrouter.ai; needs OPENROUTER_API_KEY

What it does

Openrouter Compliance Review is an agent skill from jeremylongshore/tons-of-skills-marketplace. Review OpenRouter integration for regulatory compliance (SOC2, GDPR, HIPAA). Use when preparing for audits, evaluating data handling, or documenting compliance posture. Triggers: 'openrouter compliance', 'openrouter gdpr', 'openrouter soc2', 'openrouter data residency'.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/compliance-checklist.md`, `references/data-flow-documentation.md` and `references/errors.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Model routing and gateways, Regulatory compliance and Privacy and GDPR. It works with OpenRouter. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Preparing for audits
  • Evaluating data handling
  • Documenting compliance posture

Example prompts

  • “openrouter compliance”
  • “openrouter gdpr”
  • “openrouter soc2”
  • “/openrouter-compliance-review”

Requirements

  • Python 3
  • A credential in OPENROUTER_API_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Bash(python3:*), Bash(curl:*), Bash(jq:*)

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Work through the four areas of the Compliance Checklist — data_handling, access_control, audit_trail, and provider_selection — recording…
  2. Classify each workload with the Data Classification Matrix (Public → Internal → Confidential → Restricted/PHI) to determine allowed…
  3. Pin regulated traffic per Provider Routing for Compliance: set provider.order plus allow_fallbacks: False, then verify response.model…
  4. For data-sovereignty requirements, configure BYOK per BYOK for Data Sovereignty so inference runs on your own provider account and…
  5. Run the Compliance Audit Script: key label/limit check via GET /api/v1/auth/key, a free-tier warning (free tier is unsuitable for…
  6. Document the data flow for auditors — client → OpenRouter (routing) → provider (inference) — per Enterprise Considerations.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Bash(python3:*)
    • Bash(curl:*)
    • Bash(jq:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • openrouter.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENROUTER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Openrouter Compliance Review loads about 2.3k tokens when it runs, and up to ~6.6k if it reads all its reference files. Until then it costs about 75 tokens; SKILL.md has 556 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:59
    "Store keys in secrets manager (not .env files in repos)",

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 556 words, ~2,285 tokens.

Download SKILL.mdSave it as .claude/skills/openrouter-compliance-review/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
openrouter-compliance-review
description
Review OpenRouter integration for regulatory compliance (SOC2, GDPR, HIPAA). Use when preparing for audits, evaluating data handling, or documenting compliance posture. Triggers: 'openrouter compliance', 'openrouter gdpr', 'openrouter soc2', 'openrouter data residency'.
allowed-tools
Read, Write, Edit, Grep, Bash(python3:*), Bash(curl:*), Bash(jq:*)
compatibility
Designed for Claude Code
version
1.20.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, openrouter, compliance, security, governance

OpenRouter Compliance Review

Overview

OpenRouter is a proxy that routes requests to upstream providers (OpenAI, Anthropic, Google, etc.). Compliance depends on both OpenRouter's data handling and the selected provider's policies. Key considerations: data transit through OpenRouter infrastructure, provider-specific data retention, model selection for regulated data, and audit trail requirements.

Prerequisites

  • An OpenRouter API key (sk-or-v1-...) exported as OPENROUTER_API_KEY — see the openrouter-install-auth skill for setup
  • Python 3.8+ with the OpenAI SDK for provider-pinned requests and the automated checker in the references
  • curl and jq to run the Compliance Audit Script
  • An existing OpenRouter integration to review — the audit script scans its source tree for hardcoded sk-or-v1- keys
  • Knowledge of which regimes apply (SOC2, GDPR, HIPAA) and how your data is classified

Instructions

  1. Work through the four areas of the Compliance Checklist — data_handling, access_control, audit_trail, and provider_selection — recording pass/fail per item.
  2. Classify each workload with the Data Classification Matrix (Public → Internal → Confidential → Restricted/PHI) to determine allowed providers and required controls.
  3. Pin regulated traffic per Provider Routing for Compliance: set provider.order plus allow_fallbacks: False, then verify response.model confirms the approved provider actually served the request.
  4. For data-sovereignty requirements, configure BYOK per BYOK for Data Sovereignty so inference runs on your own provider account and OpenRouter only routes.
  5. Run the Compliance Audit Script: key label/limit check via GET /api/v1/auth/key, a free-tier warning (free tier is unsuitable for regulated data), and the hardcoded-key scan.
  6. Document the data flow for auditors — client → OpenRouter (routing) → provider (inference) — per Enterprise Considerations.

Compliance Checklist

python
COMPLIANCE_CHECKLIST = {
    "data_handling": [
        "Verify OpenRouter does NOT train on your data (confirmed in their privacy policy)",
        "Confirm provider-level data policies (OpenAI, Anthropic, Google each differ)",
        "Document data flow: your app -> OpenRouter -> provider -> OpenRouter -> your app",
        "Identify if prompts contain PII, PHI, or regulated data",
        "Implement PII redaction before sending to API",
    ],
    "access_control": [
        "Use per-service API keys (not shared keys)",
        "Set credit limits per key to isolate blast radius",
        "Rotate keys on a 90-day schedule",
        "Store keys in secrets manager (not .env files in repos)",
        "Enable management keys for programmatic key provisioning",
    ],
    "audit_trail": [
        "Log every API call with generation_id, model, user_id, cost",
        "Hash prompts (SHA-256) instead of logging raw content",
        "Retain audit logs per regulation (90d operational, 7yr financial)",
        "Ship logs to append-only storage (S3, immutable DB)",
    ],
    "provider_selection": [
        "Route regulated data only to compliant providers",
        "Use provider routing to exclude non-compliant providers",
        "Document which models are approved for which data classifications",
        "Test that fallback routing doesn't route to unapproved providers",
    ],
}

Provider Routing for Compliance

python
import os
from openai import OpenAI

client = OpenAI(
    base_url="https://openrouter.ai/api/v1",
    api_key=os.environ["OPENROUTER_API_KEY"],
    default_headers={"HTTP-Referer": "https://my-app.com", "X-Title": "my-app"},
)

# Route ONLY to specific providers (e.g., Anthropic for SOC2)
response = client.chat.completions.create(
    model="anthropic/claude-3.5-sonnet",
    messages=[{"role": "user", "content": "Analyze this contract..."}],
    max_tokens=2048,
    extra_body={
        "provider": {
            "order": ["Anthropic"],        # Only Anthropic's infrastructure
            "allow_fallbacks": False,       # Do NOT fall back to other providers
        },
    },
)

# Verify which provider actually served the request
print(f"Served by: {response.model}")  # Should match anthropic/claude-3.5-sonnet

Data Classification Matrix

ClassificationAllowed ProvidersControls
PublicAny (including :free)Standard logging
InternalTier 1 (OpenAI, Anthropic, Google)Audit logging, key limits
ConfidentialAnthropic, OpenAI (API-only)PII redaction, no free models
Restricted/PHIBYOK only or self-hostedFull audit, encryption at rest

BYOK for Data Sovereignty

python
# Bring Your Own Key -- requests go directly to provider
# OpenRouter acts as router only; data doesn't persist on OpenRouter
response = client.chat.completions.create(
    model="openai/gpt-4o",
    messages=[{"role": "user", "content": "Process this..."}],
    max_tokens=1024,
    extra_body={
        "provider": {
            "order": ["OpenAI"],
            "allow_fallbacks": False,
        },
    },
    # With BYOK, configure your provider key in OpenRouter dashboard
    # Data flows: your app -> OpenRouter (routing only) -> OpenAI (your account)
)

Compliance Audit Script

bash
#!/bin/bash
echo "=== OpenRouter Compliance Audit ==="

# 1. Verify API key has credit limit set
echo "1. Key configuration:"
curl -s https://openrouter.ai/api/v1/auth/key \
  -H "Authorization: Bearer $OPENROUTER_API_KEY" | \
  jq '{label: .data.label, limit: .data.limit, is_free_tier: .data.is_free_tier}'

# 2. Check if using free tier (not suitable for regulated data)
IS_FREE=$(curl -s https://openrouter.ai/api/v1/auth/key \
  -H "Authorization: Bearer $OPENROUTER_API_KEY" | jq -r '.data.is_free_tier')
[ "$IS_FREE" = "true" ] && echo "WARNING: Free tier. Not suitable for regulated data."

# 3. Scan for hardcoded keys in source
FOUND=$(grep -r "sk-or-v1-" --include="*.py" --include="*.ts" --include="*.js" . 2>/dev/null | grep -v node_modules | wc -l)
echo "Hardcoded keys found: $FOUND"
Show full SKILL.md (252 more words)Show less

Output

  • A pass/fail/warn compliance report from the automated checker in the references, one line per control (API key storage, HTTPS enforcement, max_tokens, error handling, audit logging)
  • Key-configuration JSON (label, limit, is_free_tier) plus a free-tier warning and a count of hardcoded keys found in source, from the Compliance Audit Script
  • A provider-pinned client configuration (provider.order + allow_fallbacks: False) that cannot route regulated data to unapproved providers
  • A filled-in markdown compliance checklist (template in the references) covering security, data privacy, reliability, observability, and cost controls

Examples

Running run_compliance_review() from the references against a healthy integration:

text
Compliance: 5/5 passed, 0 failed, 0 warnings
  [OK] api_key_storage: Key loaded from environment variable
  [OK] https_enforcement: HTTPS enforced
  [OK] max_tokens: max_tokens set to 500
  [OK] error_handling: Error handling present
  [OK] audit_logging: Audit logging configured

Any [FAIL] line maps to a checklist item above — fix it and re-run until clean. More worked examples: references/examples.md.

Error Handling

ErrorCauseFix
Request routed to unapproved providerallow_fallbacks: true (default)Set allow_fallbacks: false with explicit order
Key exposed in logsRaw API key loggedAdd PII redaction for sk-or-v1-* pattern
No audit trail for requestLogging middleware bypassedMake audit logging a required wrapper
Free model used for regulated dataNo model allowlistImplement model allowlist in client wrapper

Enterprise Considerations

  • OpenRouter does not train on API data, but upstream providers may have different terms for API vs consumer use
  • Use provider.order + allow_fallbacks: false to guarantee data only flows to approved providers
  • BYOK eliminates OpenRouter as a data processor for inference (routing metadata still transits)
  • Document the data flow diagram for auditors: client -> OpenRouter (routing) -> provider (inference)
  • Implement client-side PII redaction as defense-in-depth
  • Consider self-hosted or VPC deployments for restricted/PHI data

References

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/.curated/openrouter-compliance-review of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/compliance-checklist.md
  • references/data-flow-documentation.md
  • references/errors.md
  • references/examples.md
  • references/openrouter-integration-security-questionnaire.md
  • references/security-assessment.md
  • references/vendor-assessment.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Openrouter Compliance Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openrouter Compliance Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openrouter Compliance Review this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: NotesMIT
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
Security Compliance Compliance Checkaiskillstore/marketplace4338 repos~600Automated safety check: PassNone
Ra Qm Skillsalirezarezvani/claude-skills28k—~833Automated safety check: PassMIT
Compliance Testingproffesor-for-testing/agentic-qe495—~1.8kAutomated safety check: PassMIT

Similar skills

  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Security Compliance Compliance Check

    aiskillstore/marketplace

    You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards.

    433 GitHub starsUsed in 8 repos~600 tokens
    Legal & ComplianceAuto-check passed
  • Ra Qm Skills

    alirezarezvani/claude-skills

    Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO…

    28k GitHub stars~833 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Testing

    proffesor-for-testing/agentic-qe

    Regulatory compliance testing for GDPR, CCPA, HIPAA, SOC2, PCI-DSS and industry-specific regulations.

    495 GitHub stars~1.8k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Cometchat Compliance

    cometchat/cometchat-skills

    Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…

    132 GitHub stars~1.7k tokensUpdated 5 days ago
    Legal & ComplianceAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Openrouter Compliance Review

What does Openrouter Compliance Review do?

Review OpenRouter integration for regulatory compliance (SOC2, GDPR, HIPAA). Openrouter Compliance Review is an agent skill from jeremylongshore/tons-of-skills-marketplace. Review OpenRouter integration for regulatory compliance (SOC2, GDPR, HIPAA).

When should I use Openrouter Compliance Review?

Openrouter Compliance Review fits situations like: preparing for audits; evaluating data handling; documenting compliance posture.

How do I install Openrouter Compliance Review in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill openrouter-compliance-review -a claude-code`. Or copy the skill folder (skills/.curated/openrouter-compliance-review in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/openrouter-compliance-review in your project. Claude Code loads it when a task matches its description.

How do I install Openrouter Compliance Review in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill openrouter-compliance-review -a codex`. Or copy the skill folder (skills/.curated/openrouter-compliance-review in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/openrouter-compliance-review in your project. Codex loads it when a task matches its description.

Can I use Openrouter Compliance Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill openrouter-compliance-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openrouter-compliance-review, .gemini/skills/openrouter-compliance-review, .github/skills/openrouter-compliance-review and .opencode/skills/openrouter-compliance-review in your project.

What does Openrouter Compliance Review need to run?

Going by SKILL.md and its folder, Openrouter Compliance Review needs the command-line tools its instructions call (curl and jq) and credentials named OPENROUTER_API_KEY. Our summary lists: Python 3; A credential in OPENROUTER_API_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Bash(python3:*), Bash(curl:*), Bash(jq:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Openrouter Compliance Review access the network?

SKILL.md names 1 domain. In commands or code: openrouter.ai; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Openrouter Compliance Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Openrouter Compliance Review use?

Openrouter Compliance Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openrouter Compliance Review use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.

What are the alternatives to Openrouter Compliance Review?

Skills that share tags, products or a category with Openrouter Compliance Review: Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars), Implementing Compliance (ancoleman/ai-design-components, 525 stars), Security Compliance Compliance Check (aiskillstore/marketplace, 433 stars) and Ra Qm Skills (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openrouter Compliance Review?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.