openrouter-compliance-review
Installation
SKILL.md
OpenRouter Compliance Review
Overview
OpenRouter is a proxy that routes requests to upstream providers (OpenAI, Anthropic, Google, etc.). Compliance depends on both OpenRouter's data handling and the selected provider's policies. Key considerations: data transit through OpenRouter infrastructure, provider-specific data retention, model selection for regulated data, and audit trail requirements.
Prerequisites
- An OpenRouter API key (
sk-or-v1-...) exported asOPENROUTER_API_KEY— see theopenrouter-install-authskill for setup - Python 3.8+ with the OpenAI SDK for provider-pinned requests and the automated checker in the references
curlandjqto run the Compliance Audit Script- An existing OpenRouter integration to review — the audit script scans its source tree for hardcoded
sk-or-v1-keys - Knowledge of which regimes apply (SOC2, GDPR, HIPAA) and how your data is classified