scan_licenses
Scan package.json and lockfiles to identify dependency licenses, flag GPL/AGPL or unknown ones, and fill missing license details from the npm registry. Advisory only, not legal advice.
Instructions
Scan package.json (+ lockfile) for dependency licenses; optionally fill gaps via npm registry license field. ADVISORY ONLY — not legal advice. Uses lockfile metadata and/or the public npm registry license field (no tarball downloads).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| maxFetch | No | Max registry lookups (default 80, max 200). | |
| includeDev | No | Include devDependencies (default true). | |
| projectDir | Yes | Path to project directory containing package.json. | |
| includePeer | No | Include peerDependencies (default false). | |
| fetchMissing | No | Query npm registry for deps missing license in lockfile (default true). |