Skip to main content
Glama
TheoryofShadows

@mcpx-digital/license-scan

@mcpx-digital/license-scan

MCP server for dependency license awareness (advisory).

Scan package.json + lockfiles for dependency licenses. When the lockfile has no license field, optionally read the license metadata from the public npm registry (no tarball downloads). Flag GPL/AGPL/unknown licenses for commercial awareness.

ADVISORY ONLY — not legal advice. Metadata can be wrong or incomplete. Verify critical dependencies yourself before shipping.

Install

npx -y @mcpx-digital/license-scan

Related MCP server: Dependency Checker MCP Server

Cursor mcp.json example

{
  "mcpServers": {
    "license-scan": {
      "command": "npx",
      "args": ["-y", "@mcpx-digital/license-scan"]
    }
  }
}

Local clone:

{
  "mcpServers": {
    "license-scan": {
      "command": "node",
      "args": ["/absolute/path/to/license-scan-mcp/index.js"]
    }
  }
}

Tools

Tool

What it does

scan_licenses

Full scan of deps with classifications

flag_risky_licenses

GPL/AGPL/LGPL-family + unknown only

classify_license_string

Classify one license string

Example prompts

  • “Scan licenses in /path/to/my-app”

  • “Flag copyleft/unknown licenses for this project”

  • “Is GPL-3.0-or-later copyleft?”

Development

git clone https://github.com/TheoryofShadows/license-scan-mcp.git
cd license-scan-mcp
npm install
npm test

License

MIT

Available Tools

3 tools
classify_license_stringA

Classify a single license string as permissive / copyleft / unknown / other. ADVISORY ONLY — not legal advice. Uses lockfile metadata and/or the public npm registry license field (no tarball downloads).

ParametersJSON Schema
NameRequiredDescriptionDefault
licenseYesLicense string (e.g. MIT, Apache-2.0, GPL-3.0).

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full behavioral burden. It discloses that the result is advisory only and not legal advice, specifies the data sources, and clarifies that no tarball downloads occur — all useful traits for an agent deciding whether to trust or invoke this tool. It doesn't cover return format or failure modes, but for a simple classification tool this is strong disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences with zero waste: the first delivers the core purpose and output categories, the second adds the advisory caveat and data-source constraints. All information is essential and front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter tool with no output schema, the description covers the input semantics, the classification logic, and important caveats (advisory only, no tarball downloads). The return format is not described, but for a classification tool returning a category label this is a minor gap; the description is otherwise complete for correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% — the license parameter is already documented with examples (MIT, Apache-2.0, GPL-3.0). The description reinforces that it is a single license string but adds little beyond what the schema provides. Baseline 3 is appropriate when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action (classify) with a clear resource (a single license string) and enumerates the exact output categories (permissive / copyleft / unknown / other). It distinguishes itself from siblings by explicitly scoping to a single string, whereas scan_licenses and flag_risky_licenses imply bulk or risk-flagging workflows.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explains the data sources used (lockfile metadata, public npm registry license field) and a constraint (no tarball downloads), which helps an agent understand the operational context. However, it does not explicitly state when to prefer this tool over scan_licenses or flag_risky_licenses — the single-vs-bulk distinction is implied by the name but not spelled out.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

flag_risky_licensesA

Flag GPL/AGPL/LGPL-family and unknown licenses for commercial awareness. ADVISORY ONLY — not legal advice. Uses lockfile metadata and/or the public npm registry license field (no tarball downloads).

ParametersJSON Schema
NameRequiredDescriptionDefault
includeDevNoInclude devDependencies (default true).
projectDirYesPath to project directory containing package.json.
fetchMissingNoQuery npm registry for missing licenses (default true).

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden of behavioral disclosure. It explicitly states 'ADVISORY ONLY — not legal advice,' identifies the data sources (lockfile metadata and npm registry license field), and discloses network behavior with 'no tarball downloads.' This meaningfully informs the agent about side effects and limitations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact and front-loaded: it states the action and target first, then the advisory caveat, then the technical method. Each clause earns its place and there is no redundant or vague language.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only analysis tool with fully documented parameters, the description is nearly complete: it covers purpose, caveats, data sources, and network behavior. The main gap is that it does not describe the output/return format, and there is no output schema, but the verb 'Flag' sufficiently implies a list of flagged items for invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the parameters are already fully documented in the schema. The description adds some relevant context around registry lookups, which aligns with fetchMissing, but it doesn't add meaningful detail about projectDir or includeDev beyond what the schema provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb, 'Flag,' and a precise resource scope: 'GPL/AGPL/LGPL-family and unknown licenses.' It also clarifies the intended purpose, 'commercial awareness,' which separates it from broader tools like scan_licenses and from string-level tools like classify_license_string.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies when to use the tool (when assessing commercial risk of licenses) and provides technical context about using lockfile metadata and the npm registry. However, it never explicitly contrasts it with the sibling tools or states when to prefer scan_licenses or classify_license_string instead.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

scan_licensesA

Scan package.json (+ lockfile) for dependency licenses; optionally fill gaps via npm registry license field. ADVISORY ONLY — not legal advice. Uses lockfile metadata and/or the public npm registry license field (no tarball downloads).

ParametersJSON Schema
NameRequiredDescriptionDefault
maxFetchNoMax registry lookups (default 80, max 200).
includeDevNoInclude devDependencies (default true).
projectDirYesPath to project directory containing package.json.
includePeerNoInclude peerDependencies (default false).
fetchMissingNoQuery npm registry for deps missing license in lockfile (default true).

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It discloses that it uses lockfile metadata and the npm registry license field, avoids tarball downloads, and includes an advisory-only caveat. It implies a read-only operation via 'scan' but could further clarify that it makes no file modifications.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, front-loaded with the main action and then the caveat about advisory nature. Efficient and to the point with no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema, and the description does not specify what the tool returns (e.g., a list of licenses, a report). It also omits details about network requirements when fetchMissing is true. Given the moderate complexity (5 params, optional network calls), this is a significant gap for an agent to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description mentions 'fill gaps' which relates to fetchMissing, but it does not add new meaning beyond what the schema already provides for each parameter.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb ('scan') and resource (package.json + lockfile) focused on dependency licenses. It clearly distinguishes from siblings like flag_risky_licenses and classify_license_string, which handle risk assessment and individual string classification respectively.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies its use case (scanning licenses in a project) and mentions optional registry fetching, but it does not explicitly contrast with sibling tools or state when to prefer this over them. No when-not-to-use guidance is given.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 3 tool updatesv0.1.0
    • First observedclassify_license_string
    • First observedflag_risky_licenses
    • First observedscan_licenses

TDQS

A4.1/5.0

Scored across 3 tools

Disambiguation4/5

The tools are mostly distinct: scan_licenses scans a project's dependencies, flag_risky_licenses filters for risky licenses, and classify_license_string handles a single license string. There is some conceptual overlap between scan_licenses and flag_risky_licenses since both operate on the same project data, but their outputs and purposes differ enough to avoid serious confusion.

Naming Consistency5/5

All three tools follow a consistent verb-first snake_case pattern: scan_, flag_, classify_. The names clearly describe the action and target, and there is no mixing of conventions or vague verbs.

Tool Count5/5

Three tools is well-scoped for a focused license-scanning utility. Each tool serves a distinct step in the workflow—scanning, flagging, and classifying—without unnecessary bloat.

Completeness4/5

The toolset covers the core license scanning workflow: scanning a project, flagging risky licenses, and classifying individual strings. A minor gap is the lack of a tool to retrieve full license texts or detailed compliance data, but for the stated advisory purpose the surface is reasonably complete.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables scanning of project dependencies across multiple package managers (npm, pip, cargo, etc.) and generates comprehensive markdown license reports. Supports automatic license detection from package registries with caching for improved performance.
    -
  • A
    license
    B
    quality
    C
    maintenance
    Enables security scanning for npm dependencies by checking manifest and lockfiles against the OSV.dev and Socket.dev vulnerability databases. It provides tools to detect vulnerabilities in specific packages and retrieve detailed technical reports for identified security issues.
    3
    15 npm
    MIT
  • -
    license
    Not graded
    quality
    B
    maintenance
    Audits npm dependencies for license compatibility, catching copyleft and source-available traps before shipping.
    -