mcp-license-audit
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-license-auditAudit licenses in my package.json for conflicts"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-license-audit
MCP server that audits your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.
What It Does
Parses a
package.jsonfile (dependencies + devDependencies)Fetches license info for each package from the npm registry
Classifies licenses: permissive (MIT, Apache, BSD, ISC), copyleft (GPL, AGPL), weak-copyleft (LGPL, MPL), unknown
Detects conflicts (e.g., GPL dependency in an MIT-licensed project)
Returns a structured JSON report with risk level and summary
Related MCP server: gridwork-license
Install
npm install -g mcp-license-audit
# or run directly:
npx mcp-license-auditConfigure in Claude Code
Add to your .claude/mcp.json or ~/.claude/mcp.json:
{
"mcpServers": {
"license-audit": {
"command": "npx",
"args": ["mcp-license-audit"]
}
}
}Or if installed globally:
{
"mcpServers": {
"license-audit": {
"command": "mcp-license-audit"
}
}
}Tool: audit-licenses
Input: packageJson — the full contents of a package.json file as a string.
Output: JSON report:
{
"totalDependencies": 15,
"analyzed": 15,
"licenses": {
"MIT": ["express", "lodash"],
"Apache-2.0": ["typescript"],
"GPL-3.0": ["some-package"],
"unknown": ["private-pkg"]
},
"conflicts": [
{
"package": "some-package",
"license": "GPL-3.0",
"issue": "GPL dependency in MIT project — must open-source your code if distributed"
}
],
"riskLevel": "medium",
"summary": "15 deps analyzed. 1 GPL conflict found. 1 unknown license."
}Risk levels: low (no copyleft), medium (weak copyleft or many unknowns), high (GPL/AGPL found).
Limits
Analyzes first 20 dependencies for speed
Only supports npm packages (no pip/cargo/gem support yet)
License data comes from the npm registry — private packages return "unknown"
Build from Source
npm install
npm run build
node dist/index.jsAvailable Tools
1 toolaudit-licensesA
Audit your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.
| Name | Required | Description | Default |
|---|---|---|---|
| packageJson | Yes | Contents of a package.json file as a string |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description bears full responsibility for disclosing behavioral traits. It states it flags conflicts and generates reports, but does not mention side effects (e.g., whether it modifies files, requires network access, or is read-only). The agent is left guessing about permissions, mutability, and output format.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that directly states the tool's purpose and key features. It contains no redundant information or filler. Every word contributes to understanding, making it highly efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description is adequate for a tool with one parameter and no siblings. It covers the core function but omits details about the output format of compliance reports (e.g., stdout, file) and any prerequisites. Given the lack of output schema, additional context on return values would improve completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage for the only parameter ('packageJson'), which already explains it is the contents of a package.json file. The description adds no further meaning or constraints beyond what the schema provides. Baseline score is appropriate given full schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool audits dependency licenses for compatibility issues, specifically flags GPL/AGPL conflicts and generates compliance reports. It uses a specific verb ('audit') and resource (dependency licenses), effectively communicating its purpose. With no sibling tools, differentiation is unnecessary.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for projects with dependencies and mentions specific outcomes (flagging GPL/AGPL conflicts, generating reports). However, it does not explicitly state when to use or not use this tool, nor does it provide alternative tools or context. Without siblings, the lack of guidance is acceptable but limits clarity for complex scenarios.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
1 tool update
v0.1.0- First observed
audit-licenses
TDQS
Only one tool exists, so there is no possible confusion between tools.
The sole tool name 'audit-licenses' follows a clear verb_noun pattern, consistent with itself.
With only one tool, the server feels thin for a license audit domain, which might benefit from separate reporting or configuration tools. However, the single tool may suffice for basic use.
The tool covers scanning and report generation, but lacks tools for managing license policies, viewing history, or handling exceptions, leaving notable gaps.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
- mcpOAuthco.policyforge
Generate, audit, and maintain legal policies that match what your code actually does.
Open-source licence risk checks for AI coding agents and dependency trees.
Check if a dependency's license obligates you, based on how you ship. npm, PyPI, Go.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables scanning of project dependencies across multiple package managers (npm, pip, cargo, etc.) and generates comprehensive markdown license reports. Supports automatic license detection from package registries with caching for improved performance.-

gridwork-licenseofficial
AlicenseAqualityDmaintenanceScans project dependencies for license compliance, classifying 60+ licenses and detecting conflicts and copyleft risks.4561MIT- -licenseNot gradedqualityBmaintenanceAudits npm dependencies for license compatibility, catching copyleft and source-available traps before shipping.-
- AlicenseAqualityDmaintenanceDependency security & health auditing for AI agents with no account or API key required.22MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/webmoleai/mcp-license-audit'
If you have feedback or need assistance with the MCP directory API, please join our Discord server