Skip to main content
Glama
TheoryofShadows

@mcpx-digital/license-scan

README.md
# @mcpx-digital/license-scan

**MCP server for dependency license awareness (advisory).**

Scan `package.json` + lockfiles for dependency licenses. When the lockfile has no license field, optionally read the **license** metadata from the public npm registry (no tarball downloads). Flag GPL/AGPL/unknown licenses for commercial awareness.

> **ADVISORY ONLY — not legal advice.** Metadata can be wrong or incomplete. Verify critical dependencies yourself before shipping.

## Install

```bash
npx -y @mcpx-digital/license-scan
```

## Cursor `mcp.json` example

```json
{
  "mcpServers": {
    "license-scan": {
      "command": "npx",
      "args": ["-y", "@mcpx-digital/license-scan"]
    }
  }
}
```

Local clone:

```json
{
  "mcpServers": {
    "license-scan": {
      "command": "node",
      "args": ["/absolute/path/to/license-scan-mcp/index.js"]
    }
  }
}
```

## Tools

| Tool | What it does |
|------|----------------|
| `scan_licenses` | Full scan of deps with classifications |
| `flag_risky_licenses` | GPL/AGPL/LGPL-family + unknown only |
| `classify_license_string` | Classify one license string |

## Example prompts

- “Scan licenses in `/path/to/my-app`”
- “Flag copyleft/unknown licenses for this project”
- “Is `GPL-3.0-or-later` copyleft?”

## Development

```bash
git clone https://github.com/TheoryofShadows/license-scan-mcp.git
cd license-scan-mcp
npm install
npm test
```

## License

MIT

TDQS

A4.1/5.0

Scored across 3 tools

Disambiguation4/5

The tools are mostly distinct: scan_licenses scans a project's dependencies, flag_risky_licenses filters for risky licenses, and classify_license_string handles a single license string. There is some conceptual overlap between scan_licenses and flag_risky_licenses since both operate on the same project data, but their outputs and purposes differ enough to avoid serious confusion.

Naming Consistency5/5

All three tools follow a consistent verb-first snake_case pattern: scan_, flag_, classify_. The names clearly describe the action and target, and there is no mixing of conventions or vague verbs.

Tool Count5/5

Three tools is well-scoped for a focused license-scanning utility. Each tool serves a distinct step in the workflow—scanning, flagging, and classifying—without unnecessary bloat.

Completeness4/5

The toolset covers the core license scanning workflow: scanning a project, flagging risky licenses, and classifying individual strings. A minor gap is the lack of a tool to retrieve full license texts or detailed compliance data, but for the stated advisory purpose the surface is reasonably complete.

Maintenance

ActivityMaintained
ResponsivenessNo issues