mcp-license-audit
Audits npm dependency licenses, fetching license information from the npm registry to detect copyleft conflicts and generate compliance reports.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-license-auditAudit the licenses in my package.json for GPL conflicts."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-license-audit
MCP server that audits your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.
What It Does
Parses a
package.jsonfile (dependencies + devDependencies)Fetches license info for each package from the npm registry
Classifies licenses: permissive (MIT, Apache, BSD, ISC), copyleft (GPL, AGPL), weak-copyleft (LGPL, MPL), unknown
Detects conflicts (e.g., GPL dependency in an MIT-licensed project)
Returns a structured JSON report with risk level and summary
Related MCP server: dependency-health
Install
npm install -g mcp-license-audit
# or run directly:
npx mcp-license-auditConfigure in Claude Code
Add to your .claude/mcp.json or ~/.claude/mcp.json:
{
"mcpServers": {
"license-audit": {
"command": "npx",
"args": ["mcp-license-audit"]
}
}
}Or if installed globally:
{
"mcpServers": {
"license-audit": {
"command": "mcp-license-audit"
}
}
}Analytics
This server supports MCPcat analytics. To enable usage tracking, session replay, and error monitoring, set the MCPCAT_PROJECT_ID environment variable in your MCP client config:
{
"mcpServers": {
"license-audit": {
"command": "npx",
"args": ["mcp-license-audit"],
"env": {
"MCPCAT_PROJECT_ID": "proj_your_id_here"
}
}
}
}Without it, the server runs normally with no analytics. See the MCPcat setup guide for details.
Tool: audit-licenses
Input: packageJson — the full contents of a package.json file as a string.
Output: JSON report:
{
"totalDependencies": 15,
"analyzed": 15,
"licenses": {
"MIT": ["express", "lodash"],
"Apache-2.0": ["typescript"],
"GPL-3.0": ["some-package"],
"unknown": ["private-pkg"]
},
"conflicts": [
{
"package": "some-package",
"license": "GPL-3.0",
"issue": "GPL dependency in MIT project — must open-source your code if distributed"
}
],
"riskLevel": "medium",
"summary": "15 deps analyzed. 1 GPL conflict found. 1 unknown license."
}Risk levels: low (no copyleft), medium (weak copyleft or many unknowns), high (GPL/AGPL found).
Limits
Analyzes first 20 dependencies for speed
Only supports npm packages (no pip/cargo/gem support yet)
License data comes from the npm registry — private packages return "unknown"
Build from Source
npm install
npm run build
node dist/index.jsAvailable Tools
1 toolaudit-licensesA
Audit your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.
| Name | Required | Description | Default |
|---|---|---|---|
| packageJson | Yes | Contents of a package.json file as a string |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must fully disclose behavior. It mentions auditing, flagging, and generating reports, but does not indicate whether the tool is read-only, requires network access, or has side effects. A score of 2 reflects this significant gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise with two sentences that front-load the purpose and key actions. Every phrase adds value with no wasted words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given low complexity (one parameter, no output schema), the description covers the essential purpose and outputs. However, it lacks behavioral details, which slightly reduces completeness for an unannotated tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has 100% description coverage for the single parameter, so the description does not need to add meaning. The baseline is 3, and the description provides no additional parameter semantics beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool audits dependency licenses for compatibility issues, specifically flags GPL/AGPL conflicts, and generates compliance reports. This is a specific verb+resource combination with clear scope.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies the tool should be used when you need to audit licenses, but it does not provide explicit guidance on when to use it versus alternatives or what prerequisites are needed. With no sibling tools, the need is lower, but still missing explicit context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
1 tool update
v0.2.0- First observed
audit-licenses
TDQS
Only one tool exists, so there is no possibility of confusion with other tools. The purpose is clearly defined.
With a single tool, naming is trivially consistent. The name 'audit-licenses' is clear and follows a verb-noun pattern.
One tool is on the low side for typical server scope, but it may be sufficient for a focused license audit task. However, it feels thin compared to the 3-15 tool sweet spot.
The single tool covers the primary audit and compliance report function, but lacks related capabilities such as managing policies or reviewing historical audits, leaving notable gaps.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
Conformance checker for MCP servers. Free, no key, verdicts recomputable and re-measured daily.
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
Related MCP Servers
- AlicenseAqualityDmaintenanceComprehensive dependency audit MCP server supporting 9 languages and 23 tools for scanning, updating, security auditing, and migration detection.2524MIT
- FlicenseAqualityDmaintenanceAn MCP server that performs comprehensive health checks on project dependencies for JavaScript and Python projects, detecting outdated packages and fetching changelogs.1-
- AlicenseAqualityDmaintenanceMCP server providing dependency and package management tools for AI agents. Analyze licenses, find outdated packages, visualize dependency trees, estimate bundle sizes, and audit security vulnerabilities.549MIT
- AlicenseAqualityCmaintenanceMCP server that audits npm dependencies against the live registry, providing per-dependency reports on versions behind, deprecation, and license.217MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/webmoleai/mcp-check-licenses'
If you have feedback or need assistance with the MCP directory API, please join our Discord server