Skip to main content
Glama

mcp-license-audit

MCP server that audits your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.

What It Does

  • Parses a package.json file (dependencies + devDependencies)

  • Fetches license info for each package from the npm registry

  • Classifies licenses: permissive (MIT, Apache, BSD, ISC), copyleft (GPL, AGPL), weak-copyleft (LGPL, MPL), unknown

  • Detects conflicts (e.g., GPL dependency in an MIT-licensed project)

  • Returns a structured JSON report with risk level and summary

Related MCP server: dependency-health

Install

npm install -g mcp-license-audit
# or run directly:
npx mcp-license-audit

Configure in Claude Code

Add to your .claude/mcp.json or ~/.claude/mcp.json:

{
  "mcpServers": {
    "license-audit": {
      "command": "npx",
      "args": ["mcp-license-audit"]
    }
  }
}

Or if installed globally:

{
  "mcpServers": {
    "license-audit": {
      "command": "mcp-license-audit"
    }
  }
}

Analytics

This server supports MCPcat analytics. To enable usage tracking, session replay, and error monitoring, set the MCPCAT_PROJECT_ID environment variable in your MCP client config:

{
  "mcpServers": {
    "license-audit": {
      "command": "npx",
      "args": ["mcp-license-audit"],
      "env": {
        "MCPCAT_PROJECT_ID": "proj_your_id_here"
      }
    }
  }
}

Without it, the server runs normally with no analytics. See the MCPcat setup guide for details.

Tool: audit-licenses

Input: packageJson — the full contents of a package.json file as a string.

Output: JSON report:

{
  "totalDependencies": 15,
  "analyzed": 15,
  "licenses": {
    "MIT": ["express", "lodash"],
    "Apache-2.0": ["typescript"],
    "GPL-3.0": ["some-package"],
    "unknown": ["private-pkg"]
  },
  "conflicts": [
    {
      "package": "some-package",
      "license": "GPL-3.0",
      "issue": "GPL dependency in MIT project — must open-source your code if distributed"
    }
  ],
  "riskLevel": "medium",
  "summary": "15 deps analyzed. 1 GPL conflict found. 1 unknown license."
}

Risk levels: low (no copyleft), medium (weak copyleft or many unknowns), high (GPL/AGPL found).

Limits

  • Analyzes first 20 dependencies for speed

  • Only supports npm packages (no pip/cargo/gem support yet)

  • License data comes from the npm registry — private packages return "unknown"

Build from Source

npm install
npm run build
node dist/index.js

Available Tools

1 tool
audit-licensesA

Audit your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.

ParametersJSON Schema
NameRequiredDescriptionDefault
packageJsonYesContents of a package.json file as a string

TDQS

A3.6/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must fully disclose behavior. It mentions auditing, flagging, and generating reports, but does not indicate whether the tool is read-only, requires network access, or has side effects. A score of 2 reflects this significant gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is extremely concise with two sentences that front-load the purpose and key actions. Every phrase adds value with no wasted words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given low complexity (one parameter, no output schema), the description covers the essential purpose and outputs. However, it lacks behavioral details, which slightly reduces completeness for an unannotated tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema has 100% description coverage for the single parameter, so the description does not need to add meaning. The baseline is 3, and the description provides no additional parameter semantics beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool audits dependency licenses for compatibility issues, specifically flags GPL/AGPL conflicts, and generates compliance reports. This is a specific verb+resource combination with clear scope.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies the tool should be used when you need to audit licenses, but it does not provide explicit guidance on when to use it versus alternatives or what prerequisites are needed. With no sibling tools, the need is lower, but still missing explicit context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 1 tool updatev0.2.0
    • First observedaudit-licenses

TDQS

A3.7/5.0
Disambiguation5/5

Only one tool exists, so there is no possibility of confusion with other tools. The purpose is clearly defined.

Naming Consistency5/5

With a single tool, naming is trivially consistent. The name 'audit-licenses' is clear and follows a verb-noun pattern.

Tool Count3/5

One tool is on the low side for typical server scope, but it may be sufficient for a focused license audit task. However, it feels thin compared to the 3-15 tool sweet spot.

Completeness3/5

The single tool covers the primary audit and compliance report function, but lacks related capabilities such as managing policies or reviewing historical audits, leaving notable gaps.

Maintenance

ActivityInactive
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Comprehensive dependency audit MCP server supporting 9 languages and 23 tools for scanning, updating, security auditing, and migration detection.
    25
    24
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    An MCP server that performs comprehensive health checks on project dependencies for JavaScript and Python projects, detecting outdated packages and fetching changelogs.
    1
    -
  • A
    license
    A
    quality
    D
    maintenance
    MCP server providing dependency and package management tools for AI agents. Analyze licenses, find outdated packages, visualize dependency trees, estimate bundle sizes, and audit security vulnerabilities.
    5
    49
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/webmoleai/mcp-check-licenses'

If you have feedback or need assistance with the MCP directory API, please join our Discord server