mcp-license-audit
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-license-auditAudit licenses in my package.json for conflicts"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-license-audit
MCP server that audits your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.
What It Does
Parses a
package.jsonfile (dependencies + devDependencies)Fetches license info for each package from the npm registry
Classifies licenses: permissive (MIT, Apache, BSD, ISC), copyleft (GPL, AGPL), weak-copyleft (LGPL, MPL), unknown
Detects conflicts (e.g., GPL dependency in an MIT-licensed project)
Returns a structured JSON report with risk level and summary
Related MCP server: license-guardian
Install
npm install -g mcp-license-audit
# or run directly:
npx mcp-license-auditConfigure in Claude Code
Add to your .claude/mcp.json or ~/.claude/mcp.json:
{
"mcpServers": {
"license-audit": {
"command": "npx",
"args": ["mcp-license-audit"]
}
}
}Or if installed globally:
{
"mcpServers": {
"license-audit": {
"command": "mcp-license-audit"
}
}
}Tool: audit-licenses
Input: packageJson — the full contents of a package.json file as a string.
Output: JSON report:
{
"totalDependencies": 15,
"analyzed": 15,
"licenses": {
"MIT": ["express", "lodash"],
"Apache-2.0": ["typescript"],
"GPL-3.0": ["some-package"],
"unknown": ["private-pkg"]
},
"conflicts": [
{
"package": "some-package",
"license": "GPL-3.0",
"issue": "GPL dependency in MIT project — must open-source your code if distributed"
}
],
"riskLevel": "medium",
"summary": "15 deps analyzed. 1 GPL conflict found. 1 unknown license."
}Risk levels: low (no copyleft), medium (weak copyleft or many unknowns), high (GPL/AGPL found).
Limits
Analyzes first 20 dependencies for speed
Only supports npm packages (no pip/cargo/gem support yet)
License data comes from the npm registry — private packages return "unknown"
Build from Source
npm install
npm run build
node dist/index.jsAvailable Tools
1 toolaudit-licensesA
Audit your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.
| Name | Required | Description | Default |
|---|---|---|---|
| packageJson | Yes | Contents of a package.json file as a string |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description bears full responsibility for disclosing behavioral traits. It states it flags conflicts and generates reports, but does not mention side effects (e.g., whether it modifies files, requires network access, or is read-only). The agent is left guessing about permissions, mutability, and output format.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that directly states the tool's purpose and key features. It contains no redundant information or filler. Every word contributes to understanding, making it highly efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description is adequate for a tool with one parameter and no siblings. It covers the core function but omits details about the output format of compliance reports (e.g., stdout, file) and any prerequisites. Given the lack of output schema, additional context on return values would improve completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage for the only parameter ('packageJson'), which already explains it is the contents of a package.json file. The description adds no further meaning or constraints beyond what the schema provides. Baseline score is appropriate given full schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool audits dependency licenses for compatibility issues, specifically flags GPL/AGPL conflicts and generates compliance reports. It uses a specific verb ('audit') and resource (dependency licenses), effectively communicating its purpose. With no sibling tools, differentiation is unnecessary.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for projects with dependencies and mentions specific outcomes (flagging GPL/AGPL conflicts, generating reports). However, it does not explicitly state when to use or not use this tool, nor does it provide alternative tools or context. Without siblings, the lack of guidance is acceptable but limits clarity for complex scenarios.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v0.1.0- First observed
audit-licenses
TDQS
Scored across 1 tool
Only one tool exists, so there is no possible confusion between tools.
The sole tool name 'audit-licenses' follows a clear verb_noun pattern, consistent with itself.
With only one tool, the server feels thin for a license audit domain, which might benefit from separate reporting or configuration tools. However, the single tool may suffice for basic use.
The tool covers scanning and report generation, but lacks tools for managing license policies, viewing history, or handling exceptions, leaving notable gaps.
Maintenance
Related MCP Connectors
- mcpOAuthco.policyforge
Generate, audit, and maintain legal policies that match what your code actually does.
Open-source licence risk checks for AI coding agents and dependency trees.
Check if a dependency's license obligates you, based on how you ship. npm, PyPI, Go.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Related MCP Servers
AlicenseAqualityDmaintenanceScans project dependencies for license compliance, classifying 60+ licenses and detecting conflicts and copyleft risks.431 npm1MIT- -licenseNot gradedqualityBmaintenanceAudits npm dependencies for license compatibility, catching copyleft and source-available traps before shipping.-
- AlicenseAqualityFmaintenanceScans npm project dependencies for license compliance issues, detecting GPL contamination and generating detailed reports.221 npmMIT
- AlicenseAqualityDmaintenanceMCP server that audits your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.125 npm1MIT