Security audit
OrcaRouter Provider
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent OrcaRouter provider plugin that sends model requests to OrcaRouter as advertised, with only a minor privacy-transparency note about attribution headers.
Install only if you are comfortable sending prompts, model inputs, and your OrcaRouter API key to OrcaRouter. Review the attribution-header behavior if your organization has strict outbound metadata policies; otherwise the package behavior appears disclosed and purpose-aligned.
Static analysis
No suspicious patterns detected.
