License Scanner MCP Server
Scans PHP Composer dependencies from composer.json and composer.lock files to analyze licenses and generate license reports
Scans Java Gradle dependencies from build.gradle files to analyze licenses and generate license reports
Scans npm/Node.js dependencies from package.json files using the npm registry API to analyze licenses and generate license reports
Scans pnpm dependencies from pnpm-lock.yaml files to analyze licenses and generate license reports
Scans Python dependencies from requirements.txt, pyproject.toml, and Pipfile using the PyPI JSON API to analyze licenses and generate license reports
Scans Ruby dependencies from Gemfile and Gemfile.lock files to analyze licenses and generate license reports
Scans Rust dependencies from Cargo.toml and Cargo.lock files using the crates.io API to analyze licenses and generate license reports
Scans Yarn dependencies from yarn.lock files to analyze licenses and generate license reports
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@License Scanner MCP Serverscan my project for dependencies and generate a license report"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
License Scanner MCP Server
A Model Context Protocol (MCP) server built with FastMCP that scans project dependencies and generates license reports in markdown format.
Features
Multi-package manager support: npm, pip, cargo, and more
Automatic license detection: Fetches license information from package registries
Markdown report generation: Creates comprehensive license reports
Caching: Avoids repeated API calls for better performance
Error handling: Robust error handling and informative error messages
Related MCP server: license-compliance-mcp
Supported Package Managers
npm/yarn/pnpm:
package.json,yarn.lock,pnpm-lock.yamlPython:
requirements.txt,pyproject.toml,PipfileRust:
Cargo.toml,Cargo.lockPHP:
composer.json,composer.lockRuby:
Gemfile,Gemfile.lockGo:
go.mod,go.sumJava:
pom.xml,build.gradle
Installation
Install dependencies:
pip install -r requirements.txtRun the MCP server:
python license_scanner.pyAvailable Tools
1. scan_dependencies(project_path: str)
Scans a project for dependencies and returns detailed license information.
Parameters:
project_path: Path to the project directory to scan
Returns: JSON string containing dependency and license information
2. generate_license_report(project_path: str, output_file: str = None)
Generates a markdown license report for a project.
Parameters:
project_path: Path to the project directory to scanoutput_file: Optional path to save the markdown report
Returns: Markdown content of the license report
3. list_package_managers(project_path: str)
Lists all package manager files found in a project.
Parameters:
project_path: Path to the project directory to scan
Returns: JSON string containing list of package manager files
Example Usage
Using the MCP server with Claude Desktop
Add the server to your Claude Desktop configuration:
{
"mcpServers": {
"license-scanner": {
"command": "python",
"args": ["/path/to/license_scanner.py"],
"cwd": "/path/to/project"
}
}
}Use the tools in Claude Desktop:
"Scan the dependencies in my project"
"Generate a license report for this project"
"List the package managers used in this project"
Example Project
The example_project/ directory contains sample files for different package managers:
package.json- npm dependenciesrequirements.txt- Python dependenciesCargo.toml- Rust dependencies
License Information Sources
npm packages: npm registry API
Python packages: PyPI JSON API
Rust crates: crates.io API
Output Format
The license report includes:
Project information: Path, total dependencies, package files found
Dependencies by manager: Organized by package manager with license details
License summary: Count of dependencies by license type
Sample Markdown Output
# License Report
**Project:** /path/to/project
**Total Dependencies:** 8
**Package Files Found:** package.json, requirements.txt
## NPM Dependencies
Found 5 dependencies
| Package | Version | License | Author | Homepage |
|---------|---------|---------|--------|----------|
| express | ^4.18.2 | MIT | TJ Holowaychuk | https://expressjs.com/ |
| lodash | ^4.17.21 | MIT | John-David Dalton | https://lodash.com/ |
## License Summary
| License | Count |
|---------|-------|
| MIT | 6 |
| Apache-2.0 | 2 |Error Handling
The server includes comprehensive error handling:
Invalid project paths
Missing package files
Network errors when fetching license information
Malformed package files
Performance
Caching: License information is cached to avoid repeated API calls
Parallel processing: Multiple package files are processed efficiently
Timeout handling: API requests have timeout protection
Contributing
Fork the repository
Create a feature branch
Add tests for new functionality
Submit a pull request
License
This project is licensed under the MIT License.
This server cannot be deployed
Maintenance
Related MCP Connectors
Open-source licence risk checks for AI coding agents and dependency trees.
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
- mcpOAuthco.policyforge
Generate, audit, and maintain legal policies that match what your code actually does.
Trust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems.
Related MCP Servers
AlicenseAqualityDmaintenanceScans project dependencies for license compliance, classifying 60+ licenses and detecting conflicts and copyleft risks.426 npm1MIT- AlicenseAqualityFmaintenanceScans npm project dependencies for license compliance issues, detecting GPL contamination and generating detailed reports.241 npmMIT
- AlicenseAqualityDmaintenanceAudits project dependency licenses for compatibility issues, flags GPL/AGPL conflicts, and generates compliance reports.139 npmMIT
- AlicenseAqualityBmaintenanceEnables AI coding agents to audit Python and npm dependency licenses against your distribution context before shipping, returning CLEAN, REVIEW, or BLOCK verdicts with plain-language reasons and supporting notice generation.323 PyPI1MIT