@mcpx-digital/license-scan
# @mcpx-digital/license-scan
**MCP server for dependency license awareness (advisory).**
Scan `package.json` + lockfiles for dependency licenses. When the lockfile has no license field, optionally read the **license** metadata from the public npm registry (no tarball downloads). Flag GPL/AGPL/unknown licenses for commercial awareness.
> **ADVISORY ONLY — not legal advice.** Metadata can be wrong or incomplete. Verify critical dependencies yourself before shipping.
## Install
```bash
npx -y @mcpx-digital/license-scan
```
## Cursor `mcp.json` example
```json
{
"mcpServers": {
"license-scan": {
"command": "npx",
"args": ["-y", "@mcpx-digital/license-scan"]
}
}
}
```
Local clone:
```json
{
"mcpServers": {
"license-scan": {
"command": "node",
"args": ["/absolute/path/to/license-scan-mcp/index.js"]
}
}
}
```
## Tools
| Tool | What it does |
|------|----------------|
| `scan_licenses` | Full scan of deps with classifications |
| `flag_risky_licenses` | GPL/AGPL/LGPL-family + unknown only |
| `classify_license_string` | Classify one license string |
## Example prompts
- “Scan licenses in `/path/to/my-app`”
- “Flag copyleft/unknown licenses for this project”
- “Is `GPL-3.0-or-later` copyleft?”
## Development
```bash
git clone https://github.com/TheoryofShadows/license-scan-mcp.git
cd license-scan-mcp
npm install
npm test
```
## License
MIT
TDQS
Scored across 3 tools
The tools are mostly distinct: scan_licenses scans a project's dependencies, flag_risky_licenses filters for risky licenses, and classify_license_string handles a single license string. There is some conceptual overlap between scan_licenses and flag_risky_licenses since both operate on the same project data, but their outputs and purposes differ enough to avoid serious confusion.
All three tools follow a consistent verb-first snake_case pattern: scan_, flag_, classify_. The names clearly describe the action and target, and there is no mixing of conventions or vague verbs.
Three tools is well-scoped for a focused license-scanning utility. Each tool serves a distinct step in the workflow—scanning, flagging, and classifying—without unnecessary bloat.
The toolset covers the core license scanning workflow: scanning a project, flagging risky licenses, and classifying individual strings. A minor gap is the lack of a tool to retrieve full license texts or detailed compliance data, but for the stated advisory purpose the surface is reasonably complete.