flag_risky_licenses
Detect GPL, AGPL, LGPL, and unknown licenses in project dependencies to assess commercial risk. Uses lockfile and npm registry metadata; advisory only.
Instructions
Flag GPL/AGPL/LGPL-family and unknown licenses for commercial awareness. ADVISORY ONLY — not legal advice. Uses lockfile metadata and/or the public npm registry license field (no tarball downloads).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| includeDev | No | Include devDependencies (default true). | |
| projectDir | Yes | Path to project directory containing package.json. | |
| fetchMissing | No | Query npm registry for missing licenses (default true). |