ZeroLeaksDocs
ZeroLeaks Package

Installation

Install zeroleaks via bun or npm, then set an OpenRouter or OpenAI API key. Requires Node 18 or later.

Package manager

Install zeroleaks with bun (recommended) or npm:

# Bun
bun add zeroleaks

# npm
npm install zeroleaks

For the CLI alone, a global install or npx also works:

npm install -g zeroleaks
npx zeroleaks scan --prompt "You are a helpful assistant."

API keys

zeroleaks sends every model call through OpenRouter by default:

export OPENROUTER_API_KEY=sk-or-v1-...

To call OpenAI directly, also set OPENAI_API_KEY. Model ids such as openai/gpt-5, gpt-5, or o3-mini then go to the OpenAI API, and all other ids still go through OpenRouter. Set OPENAI_BASE_URL (or pass --base-url) to use an OpenAI-compatible endpoint such as Azure OpenAI, a gateway, or a local Ollama or vLLM server. OpenAI model ids then go to that endpoint, and with no OpenRouter key every model does.

VariableDescription
OPENROUTER_API_KEYOpenRouter key, used for all models by default
OPENAI_API_KEYOptional. Routes OpenAI model ids to the OpenAI API
OPENAI_BASE_URLOptional. An OpenAI-compatible endpoint, same as --base-url

The CLI requires at least one of the two keys, or a base URL for a local server that does not require a key. The default models are Anthropic models served by OpenRouter. If you only set OPENAI_API_KEY, specify OpenAI model ids for the attacker, target, and evaluator. Your provider bills for the multiple attacker, evaluator, and target calls made during each scan.

Requirements

  • Node.js 18 or later, or Bun
  • An OpenRouter or OpenAI API key, or an OpenAI-compatible endpoint

Verify installation

Run a short scan to confirm setup:

zeroleaks scan --prompt "You are a helpful assistant." --mode extraction --turns 3

If configured correctly, you should see a progress spinner and then a report with the vulnerability level, a score out of 100, and any findings.

On this page