mrkeyoor.com_
Wed 07 Oct 14:39 UTC
AI Toolsevaluationupdated 07 Oct 2026

G0DM0D3 review

G0DM0D3 is an open-source chat interface that sends one prompt to several hosted or local language models, compares their replies, and returns a winner. Its main use is red-team prompt research, with a single-file browser app plus optional Next.js and Express surfaces.

Verdict

Our G0DM0D3 run installed 817 packages and used 592 MB, then failed its 44-second build while npm audit reported 31 vulnerabilities. The single-file interface is still a low-friction way for an experienced researcher to inspect its multi-model experiments without relying on the broken Next.js path. Do not deploy the full stack for other users until the compiler error, audit findings, missing tests, authentication defaults, and telemetry policy have been reviewed on your own infrastructure.

We ran it

Install✓ · 50s817 packages · 592 MB
Build✗ · 44s
Testsn/ano test script
Known vulns312 critical · 19 high · 8 moderate · 2 low (npm audit)
Repo111 files~28,353 lines of source · 2.8 MB · 0 CI workflows · Dockerfile

Answers from our run

Does G0DM0D3 build from source?

Dependencies installed in 50 seconds (817 packages), and the build failed. We cloned commit f630176 into a clean Debian container with 3 CPUs and no project-specific setup.

Does G0DM0D3 have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does G0DM0D3 have known vulnerabilities in its dependencies?

npm audit flagged 31 known advisories in the dependency tree, including 2 critical at the time of our run.

Who should not use G0DM0D3?

Teams requiring a green production build: our Next.js build failed on a TypeScript Map iteration error at commit f630176.

What are the alternatives to G0DM0D3?

Open WebUI, LibreChat, AnythingLLM. Our G0DM0D3 run installed 817 packages and used 592 MB, then failed its 44-second build while npm audit reported 31 vulnerabilities.

Setup2/5Static UI is simple, but the 44-second Next.js build failed
Docs4/5Detailed privacy, local model, API, and deployment explanations
Community3/511,545 stars, but 80 open issues and PRs and no release tag
Maturity1/5Failed build, no test target, and 31 audit findings

Who it’s for

Red-team researchers comparing how several models answer the same perturbed prompt.
Tinkerers who want to race OpenRouter, Venice, or local OpenAI-compatible models.
Developers prepared to inspect provider costs, telemetry behavior, and browser-stored credentials.
Self-hosters who can use the standalone index.html while repairing or avoiding the optional Next.js build.

Who it’s NOT for

Teams requiring a green production build: our Next.js build failed on a TypeScript Map iteration error at commit f630176.
Organizations with a zero-known-vulnerability gate: npm audit found 31 advisories, including 2 critical and 19 high.
Buyers who require repository tests and CI evidence: the package has no test target, our scan found no tests directory, and there were 0 CI workflow files.
Cost-sensitive users who may select the largest race casually: the README says ULTRAPLINIAN can query 60 OpenRouter models, with additional Venice or local entries.
Anyone treating browser localStorage as a secret vault: the README says provider keys are stored there and calls it convenient rather than secure.
Users handling private prompts without reading the data controls: app telemetry is on by default, and its classifier sends raw prompts to a configured provider unless No-Log or Local-only mode is enabled.

Setup reality

Our run installed commit f630176 in 50 seconds, pulling 817 packages and using 592 MB. The build failed after 44 seconds with exit code 1. npm audit found 31 vulnerabilities: 2 critical, 19 high, 8 moderate, and 2 low.

There was no test script or target, so tests were skipped. The root Next.js app needs provider configuration, while the API can use OpenRouter, server auth, and optional Hugging Face publishing variables. Local models need an OpenAI-compatible server and browser CORS.

The standalone index.html needs no npm build and can run from a static server. The repository also has a Dockerfile and compose file, but the measured Next.js build does not pass.

60-model races make G0DM0D3 a research interface, not ordinary chat

G0DM0D3 takes one prompt and can run it through several model and prompt combinations. GODMODE CLASSIC races 5 fixed combinations. ULTRAPLINIAN expands that idea across tiers containing 12 to 60 OpenRouter models, with optional Venice and local model entries. A scoring layer chooses a response. Parseltongue can transform input through 33 perturbation techniques, while AutoTune chooses sampling settings from 20 detected contexts. The product is built for comparison and red-team experiments rather than a quiet one-model conversation.

That breadth has an immediate operating consequence: one click may create many provider requests. The README warns that model catalogs change, so a listed entry may disappear before the repository catches up. Researchers should begin with the 12-model tier, inspect the exact roster, and set provider spending limits before trying larger races. A winning score is the project's own composite judgment. It does not establish factual accuracy, safety, or model quality outside the prompt that produced it.

What happened when we ran it

Our sandbox installed commit f630176 in 50 seconds, adding 817 npm packages and consuming 592 MB on disk. The Next.js build ran for 44 seconds and failed with exit code 1. npm audit reported 31 known vulnerabilities: 2 critical, 19 high, 8 moderate, and 2 low. Our test method used a fresh unprivileged Debian container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets.

The compiler stopped at HF/api/middleware/rateLimit.ts line 35. A for...of loop tries to iterate Map<string, RateBucket>, and TypeScript says that needs --downlevelIteration or a target of ES2015 or higher. The Next.js worker then exited with code 1. The log does not prove which configuration change the maintainers intend, so naming a cause beyond that message would be guesswork. The repository supplied no test script or target, which left the test step skipped.

The single-file UI avoids the failed Next.js build

The project README describes three distinct surfaces. The hosted core is one index.html file that can open directly or run behind a static server, with no package install or build. A separate React and Next.js frontend lives under src, and an Express API lives under api. Our failure applies to the measured root npm build. It does not show that opening the standalone HTML file fails.

Self-hosting the static UI still needs a model path. Users supply an OpenRouter or Venice key, or connect an OpenAI-compatible local server such as Ollama. A local server must allow browser CORS for the page origin. The API stack adds GODMODE_API_KEY or GODMODE_API_KEYS for callers and can use an OpenRouter key. API documentation says authentication is disabled when neither server auth variable is set, which is safe only on an intentionally private development endpoint.

Browser keys and default telemetry need an explicit decision

Provider credentials, settings, and chat history live in browser localStorage. The README says localStorage is not a secure secret vault. Clearing browser data deletes conversations, and there is no account backup or cross-device sync. App telemetry is enabled by default and sends metadata batches every 5 minutes, at 50 events, or on page unload. The documented fields exclude prompt text, response text, images, and API keys, subject to the project's stated allowlist limits.

One detail deserves a separate check before private use. When telemetry is enabled, the standalone app sends the raw prompt to an auxiliary model through OpenRouter or a local provider to create a harm-taxonomy label. No-Log mode disables that classifier and clears pending app telemetry. Local-only mode also excludes OpenRouter and Venice calls. Neither setting changes logs held by a model provider, hosting company, or network layer. Fully local use means self-hosting the page, enabling Local-only mode, and checking browser requests yourself.

The API can publish opted-in conversations without a PII scrubber

The optional API accepts contribute_to_dataset: true. With that flag, it stores non-system conversation messages and the response, then may publish them to a public Hugging Face dataset when publishing is configured. The README says this route has no automatic PII scrubber. The standalone site does not expose or send the flag, but API clients can. Any team exposing the API should remove that option or enforce a review policy before users send private records.

The API also has a separate failure report at commit f630176. Issue 97 says the /v1/research/batch/* route uses a wildcard form rejected by Express 5.2.1, then reads a positional parameter that the new router does not provide. The reporter supplies a small reproduction and says a named wildcard works locally. That report is independent of our Next.js compiler error, so repairing one does not establish that the other API surface is ready.

Repository health does not offset the lab findings. GitHub showed 11,545 stars and 80 combined open issues and pull requests, split into 50 issues and 30 pull requests in the API response. The default branch was last pushed on July 15, 2026, while issue and pull request activity continued into September. GitHub had no latest release to report. G0DM0D3 is interesting source for a careful researcher, but the failed build, 31 advisories, and absent test target make the full stack a repair job before deployment.

Alternatives

ProjectWhat it isPick it when
Open WebUI gh↗A self-hosted AI interface for local and hosted model providers.pick this instead when you want a general chat workspace rather than jailbreak-oriented model races.
LibreChat gh↗A multi-provider chat application with accounts, agents, tools, and administrative controls.pick this instead when multi-user access and an application-style deployment matter more than prompt perturbation research.
AnythingLLM gh↗A local-first AI workspace focused on documents, agents, and private model connections.pick this instead when document work and local knowledge are the main job.

What people are saying

  1. [github-trending] elder-plinius/G0DM0D3

Sources

  1. G0DM0D3 README and privacy disclosure
  2. G0DM0D3 API documentation
  3. G0DM0D3 local model guide
  4. Express 5 research route issue
  5. ULTRAPLINIAN failure report

More ai tools reviews

olmocr · embodied-jev · underclass · minecraft-agent · laya-coreml · CometixCode · the whole board →