60-model races make G0DM0D3 a research interface, not ordinary chat
G0DM0D3 takes one prompt and can run it through several model and prompt combinations. GODMODE CLASSIC races 5 fixed combinations. ULTRAPLINIAN expands that idea across tiers containing 12 to 60 OpenRouter models, with optional Venice and local model entries. A scoring layer chooses a response. Parseltongue can transform input through 33 perturbation techniques, while AutoTune chooses sampling settings from 20 detected contexts. The product is built for comparison and red-team experiments rather than a quiet one-model conversation.
That breadth has an immediate operating consequence: one click may create many provider requests. The README warns that model catalogs change, so a listed entry may disappear before the repository catches up. Researchers should begin with the 12-model tier, inspect the exact roster, and set provider spending limits before trying larger races. A winning score is the project's own composite judgment. It does not establish factual accuracy, safety, or model quality outside the prompt that produced it.
What happened when we ran it
Our sandbox installed commit f630176 in 50 seconds, adding 817 npm packages and consuming 592 MB on disk. The Next.js build ran for 44 seconds and failed with exit code 1. npm audit reported 31 known vulnerabilities: 2 critical, 19 high, 8 moderate, and 2 low. Our test method used a fresh unprivileged Debian container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets.
The compiler stopped at HF/api/middleware/rateLimit.ts line 35. A for...of loop tries to iterate Map<string, RateBucket>, and TypeScript says that needs --downlevelIteration or a target of ES2015 or higher. The Next.js worker then exited with code 1. The log does not prove which configuration change the maintainers intend, so naming a cause beyond that message would be guesswork. The repository supplied no test script or target, which left the test step skipped.
The single-file UI avoids the failed Next.js build
The project README describes three distinct surfaces. The hosted core is one index.html file that can open directly or run behind a static server, with no package install or build. A separate React and Next.js frontend lives under src, and an Express API lives under api. Our failure applies to the measured root npm build. It does not show that opening the standalone HTML file fails.
Self-hosting the static UI still needs a model path. Users supply an OpenRouter or Venice key, or connect an OpenAI-compatible local server such as Ollama. A local server must allow browser CORS for the page origin. The API stack adds GODMODE_API_KEY or GODMODE_API_KEYS for callers and can use an OpenRouter key. API documentation says authentication is disabled when neither server auth variable is set, which is safe only on an intentionally private development endpoint.
Browser keys and default telemetry need an explicit decision
Provider credentials, settings, and chat history live in browser localStorage. The README says localStorage is not a secure secret vault. Clearing browser data deletes conversations, and there is no account backup or cross-device sync. App telemetry is enabled by default and sends metadata batches every 5 minutes, at 50 events, or on page unload. The documented fields exclude prompt text, response text, images, and API keys, subject to the project's stated allowlist limits.
One detail deserves a separate check before private use. When telemetry is enabled, the standalone app sends the raw prompt to an auxiliary model through OpenRouter or a local provider to create a harm-taxonomy label. No-Log mode disables that classifier and clears pending app telemetry. Local-only mode also excludes OpenRouter and Venice calls. Neither setting changes logs held by a model provider, hosting company, or network layer. Fully local use means self-hosting the page, enabling Local-only mode, and checking browser requests yourself.
The API can publish opted-in conversations without a PII scrubber
The optional API accepts contribute_to_dataset: true. With that flag, it stores non-system conversation messages and the response, then may publish them to a public Hugging Face dataset when publishing is configured. The README says this route has no automatic PII scrubber. The standalone site does not expose or send the flag, but API clients can. Any team exposing the API should remove that option or enforce a review policy before users send private records.
The API also has a separate failure report at commit f630176. Issue 97 says the /v1/research/batch/* route uses a wildcard form rejected by Express 5.2.1, then reads a positional parameter that the new router does not provide. The reporter supplies a small reproduction and says a named wildcard works locally. That report is independent of our Next.js compiler error, so repairing one does not establish that the other API surface is ready.
Repository health does not offset the lab findings. GitHub showed 11,545 stars and 80 combined open issues and pull requests, split into 50 issues and 30 pull requests in the API response. The default branch was last pushed on July 15, 2026, while issue and pull request activity continued into September. GitHub had no latest release to report. G0DM0D3 is interesting source for a careful researcher, but the failed build, 31 advisories, and absent test target make the full stack a repair job before deployment.