Dependency Scanning
seb1n/awesome-ai-agent-skills
Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.
Open source license compliance check for a dependency list, a single library, or outbound code.
$ npx skills add anthropics/claude-for-legal --skill oss-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install anthropics/claude-for-legal oss-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ip-legal/skills/oss-review .claude/skills/oss-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "oss-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ip-legal/skills/oss-review into .claude/skills/oss-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/anthropics/claude-for-legal/tree/main/ip-legal/skills/oss-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add anthropics/claude-for-legal --skill oss-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install anthropics/claude-for-legal oss-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ip-legal/skills/oss-review .agents/skills/oss-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "oss-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ip-legal/skills/oss-review into .agents/skills/oss-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill oss-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install anthropics/claude-for-legal oss-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ip-legal/skills/oss-review .cursor/skills/oss-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "oss-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ip-legal/skills/oss-review into .cursor/skills/oss-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/anthropics/claude-for-legal.git --path ip-legal/skills/oss-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add anthropics/claude-for-legal --skill oss-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install anthropics/claude-for-legal oss-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ip-legal/skills/oss-review .gemini/skills/oss-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "oss-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ip-legal/skills/oss-review into .gemini/skills/oss-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install anthropics/claude-for-legal oss-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add anthropics/claude-for-legal --skill oss-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .github/skills && cp -r skills-src/ip-legal/skills/oss-review .github/skills/oss-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "oss-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ip-legal/skills/oss-review into .github/skills/oss-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill oss-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install anthropics/claude-for-legal oss-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ip-legal/skills/oss-review .opencode/skills/oss-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "oss-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ip-legal/skills/oss-review into .opencode/skills/oss-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oss-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
oss-reviewOpen source license compliance check for a dependency list, a single library, or outbound code.
Oss Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Open source license compliance check for a dependency list, a single library, or outbound code. Use when reviewing a manifest, SBOM, or repo for copyleft obligations and license compatibility, when asked whether a library can ship, or when preparing code to be open-sourced.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering Regulatory compliance and Supply chain security. The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Oss Review loads about 5k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 2,345 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 2,345 words, ~4,961 tokens.
.claude/skills/oss-review/SKILL.md (or your agent's skills folder).Runs an open source license compliance check against the practice profile in ~/.claude/plugins/config/claude-for-legal/ip-legal/CLAUDE.md. Classifies dependencies by license family, maps obligations to the deployment model, flags license-unknown and non-OSI-posing-as-OSS packages, and recommends actions — comply, replace, remove, seek legal review, seek commercial license.
Load ~/.claude/plugins/config/claude-for-legal/ip-legal/CLAUDE.md. If placeholders present, stop and prompt: "Run /ip-legal:cold-start-interview first — I need to learn your practice profile (and OSS policy, if any) before I can review." If the practice profile points at an uploaded OSS policy, read that too — it is the source of truth for accepted / review / banned licenses on this team.
Establish the scope: a dependency list (package.json, requirements.txt, go.mod, Gemfile, Cargo.toml, pom.xml, SBOM), a single library, or outbound code the team is preparing to open-source. If the user passed a path, infer from the file; otherwise ask.
Establish the deployment model before classifying obligations — SaaS, distributed binary, internal only, or embedded. The same dependency list triggers different obligations depending on this.
Follow the workflow below. In particular:
Output the memo per the template below — work-product header first, bottom line, top-of-memo flags, per-package blocks grouped by severity, jurisdiction note, outbound check (if applicable), approval routing.
Respect the decision posture. When a copyleft-trigger analysis turns on a contested question (AGPL's "interacts over a network," GPL-3.0's "conveying," LGPL linking scope), flag for attorney review and surface the factors cutting both ways. Anything flagged as strong copyleft or license-unknown goes to an attorney before the dependency ships or the code is released.
/ip-legal:oss-review ~/code/my-project/package.json
/ip-legal:oss-review ~/code/my-project/requirements.txt
/ip-legal:oss-review redis
/ip-legal:oss-review ~/code/my-project # repo root — scan all manifestsOSS clearance requests usually come in via a ticketing system. Connected to Jira, Linear, or Asana, this skill can: monitor incoming OSS requests, respond with guidance directly in the ticket (flagging incomplete info, asking for the repo link, returning the license-family classification), and track clearance status across requests.
Without a connector, paste the ticket or describe the request and I'll handle
it one at a time. See CONNECTORS.md at the repo root for how to add a
ticketing connector.
Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /ip-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/ip-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.
Tell the user what licenses are in their dependency tree, what obligations those licenses trigger given how the code will be deployed, and what to do about each one. The output is a memo the lawyer (or the engineer with attorney access) can act on — comply, replace, remove, seek legal review, seek commercial license.
This is a first-pass classification. Copyleft analysis depends on the deployment model, the degree of linking, the jurisdiction, and sometimes on legal questions that have not been tested in court (notably AGPL's "interacts over a network," GPL-3.0's patent clause). For anything that classifies as strong copyleft or license-unknown, an attorney evaluates before the dependency ships or the code is released. The skill reports what it found; the lawyer decides what to do.
Before scanning dependencies, read ~/.claude/plugins/config/claude-for-legal/ip-legal/CLAUDE.md. If it is missing or still contains placeholders, stop and run /ip-legal:cold-start-interview. The practice profile tells you:
If the practice profile has an OSS policy uploaded, read that too — it is the source of truth for which licenses the team accepts, which trigger review, and which are banned.
Ask (or infer from what the user provided):
What are we reviewing?
- A dependency list —
package.json,requirements.txt,go.mod,Gemfile,Cargo.toml,pom.xml, an SBOM (SPDX / CycloneDX), a lockfile- A single library — one specific package you're considering adding
- Our own code — we're planning to open-source this and need to check what's embedded
The analysis path differs:
This is the single most important input after the license list — the same library carries different obligations depending on how the software is delivered. Ask:
How will this be deployed?
- SaaS / hosted service — users access over a network; nothing ships to the user
- Distributed binary — we ship compiled code to users (desktop app, mobile app, on-prem server, CLI tool)
- Internal only — used only inside the company, not distributed outside
- Embedded / firmware — shipped in hardware or as closed-system firmware
| Deployment | Licenses that materially matter |
|---|---|
| SaaS | AGPL (network-trigger), permissive attribution in any UI, SSPL/BUSL/Elastic if repurposing as competing service |
| Distributed binary | GPL, LGPL, MPL, EPL (all trigger on distribution), permissive attribution |
| Internal only | Most copyleft does not trigger — no distribution. Permissive attribution still good hygiene. AGPL still triggers if users outside the company interact over the network. |
| Embedded / firmware | GPL is especially hard to comply with here (source disclosure + reproducible build + installation information in some cases). Plan for this before shipping, not after. |
Flag the deployment model in the output memo — the same dependency list reviewed against "SaaS" vs. "distributed binary" yields different obligations.
For every package, determine the license. Read the actual license text, not just the metadata — LICENSE files can be wrong (the file says MIT but the headers say GPL; the README claims Apache but there's no license file), and package manager metadata can be stale.
Classify into:
| Bucket | Examples | Key obligations |
|---|---|---|
| Permissive | MIT, BSD-2-Clause, BSD-3-Clause, Apache-2.0, ISC, Zlib, Unlicense | Attribution, preserve license text, Apache-2.0 adds patent grant + NOTICE requirement |
| Weak copyleft | LGPL-2.1, LGPL-3.0, MPL-2.0, EPL-1.0, EPL-2.0, CDDL | File-level or library-level source disclosure; linking rules vary |
| Strong copyleft | GPL-2.0, GPL-3.0, AGPL-3.0, OSL, EUPL (depending on version) | Broad source disclosure; AGPL extends to network use |
| Public domain / dedication | CC0, Unlicense, WTFPL | Typically no obligations, but some are contested in jurisdictions that don't recognize dedication to public domain |
| Non-OSI source-available | SSPL, BUSL, Commons Clause, Elastic License, Confluent Community, fair-source family | Not open source — restrict commercial use, competing-service use, or both. Read the specific license. |
| Other / custom / unknown | vendor-specific, proprietary, missing license file, license conflict between file and headers | Stop — do not treat as permissive by default |
Flag:
For each classified dependency, state what the deployment model triggers:
### [package@version] — [License]
**Classification:** [Permissive / Weak copyleft / Strong copyleft / Public domain / Non-OSI / Unknown]
**Obligations for our deployment ([SaaS / binary / internal / embedded]):**
- [ ] [Specific obligation — e.g., "Include attribution in a NOTICES file shipped with the app"]
- [ ] [e.g., "If we modify and distribute, publish source of our modifications"]
- [ ] [e.g., "AGPL network trigger — if users access our modified version over a network, source must be offered to them"]
**Risk:** 🔴 Critical | 🟠 High | 🟡 Medium | 🟢 Low
**Recommendation:** [Comply with obligations | Replace with [alternative] | Remove | Attorney review before shipping | Seek commercial license from [vendor]]How is the copyleft dependency consumed? The linking relationship determines whether copyleft actually triggers. Ask or determine:
- Static linking / compilation together: The works are combined into one binary. Strong signal that copyleft triggers (LGPL "work based on the Library," GPL derivative work).
- Dynamic linking / shared library: The works remain separable at runtime. LGPL explicitly permits this ("work that uses the Library"). GPL's position is contested (FSF says derivative, others disagree).
- Header inclusion / inline functions: Can create a derivative work depending on how much is included.
- Subprocess / IPC: Separate processes communicating over well-defined interfaces. Generally not derivative.
- Network API call: For most licenses, no. For AGPL, the network-interaction clause means serving the software over a network IS distribution. In a microservices architecture, an AGPL component behind an API still triggers.
- File-scope copyleft (MPL): Only the modified files carry copyleft, not the whole work. Check whether any copyleft files were modified.
The severity rating depends on this. "LGPL — weak copyleft, linking rules vary" without the linking analysis is the answer that gets an engineer sued. Static-linked LGPL in a proprietary product is 🔴 Critical. Dynamic-linked LGPL is 🟢 Low. Same license, opposite rating.
Severity calibration:
| Level | Means |
|---|---|
| 🔴 Critical | Strong copyleft in a deployment that triggers it (e.g., GPL in a distributed binary, AGPL in a SaaS). Non-OSI license that the business model actually conflicts with (e.g., SSPL while we're building a managed service). License cannot be determined and the package is load-bearing. |
| 🟠 High | Weak copyleft with obligations the team hasn't set up for (file-level disclosure, NOTICE requirements). Dual-licensed where the chosen license is ambiguous. License file says one thing, headers say another. |
| 🟡 Medium | Permissive with attribution requirements that haven't been wired into the build (missing NOTICES file, missing LICENSE in distribution). Transitive copyleft in a position that may or may not trigger, depending on how the library is consumed. |
| 🟢 Low | Permissive with obligations already satisfied. Copyleft in a deployment model that doesn't trigger it (e.g., GPL library used internally only, with no redistribution). |
Call out any of the following in a top-of-memo section:
If the user is preparing to open-source code:
Prepend the work-product header from ~/.claude/plugins/config/claude-for-legal/ip-legal/CLAUDE.md → ## Outputs (differs by user role — see ## Who's using this).
This memo and any dependency list reviewed may be privileged, confidential, or both. The output inherits that status from the source. Distribute only within the privilege circle; strip the work-product header before any external delivery (including before attaching the memo to an engineering ticket outside the privilege circle).
No silent supplement. If a research query to the configured legal research tool returns few or no results for a rule the memo needs (enforceability of AGPL's network trigger in a given jurisdiction, scope of GPL-3.0's patent grant, latest license text for a recently-relicensed package), report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: "The search returned [N] results from [tool]. Coverage appears thin for [rule / license / jurisdiction]. Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be tagged
[web search — verify]and should be checked against a primary source before relying, or (4) flag as unverified and stop. Which would you like?" A lawyer decides whether to accept lower-confidence sources.Source attribution. Where the memo cites a license text, a court decision interpreting a license, or guidance from a steward (FSF, OSI, SPDX, SFLC), tag the citation:
[OSI],[SPDX],[FSF],[SFC/SFLC],[Westlaw], or the MCP tool name for citations retrieved from a connector;[web search — verify]for web-search citations;[model knowledge — verify]for citations recalled from training data;[user provided]for license text read directly from the repo. Citations taggedverifycarry higher fabrication risk. Never strip or collapse the tags.
[WORK-PRODUCT HEADER — per plugin config ## Outputs]
# OSS Review: [Project / Dependency List / Package]
**Reviewed:** [date]
**Scope:** [Dependency list / Single library / Outbound code]
**Deployment model:** [SaaS / Binary / Internal / Embedded]
---
## Bottom line
[Two sentences. Can this ship? What has to happen first?]
**Packages reviewed:** [N]
**By classification:** [N permissive, N weak copyleft, N strong copyleft, N public domain, N non-OSI, N unknown]
**Issues:** [N]🔴 [N]🟠 [N]🟡 [N]🟢
**Approval needed from:** [name, per practice profile]
---
## Top-of-memo flags
[License-unknown list, license-conflict list, non-OSI-posing-as-OSS list, incompatible combinations]
---
## By package
[Blocks from Step 4, grouped by severity]
---
## Jurisdiction note
OSS license enforceability varies — AGPL's network trigger has not been broadly tested in court; GPL-3.0's patent clause reads differently under US vs. EU patent law; dedications to public domain are not universally recognized. State the governing-law choice for any downstream distribution (e.g., vendor agreements incorporating the code) and flag jurisdictions the practice profile marks as escalate.
---
## Outbound check (if applicable)
[From Step 6]
---
## Approval routing
[From practice profile — who approves, what triggers automatic escalation]When a license cannot be confidently classified, flag it as "needs review" — do not call it permissive. Under-classifying license risk is a one-way door: a ship decision made on a permissive-by-default assumption becomes a source-disclosure obligation or an injunction months later. Over-flagging is a two-way door — the attorney narrows the list in review.
Likewise, when the copyleft-trigger analysis turns on a contested question (AGPL's "interacts over a network," GPL-3.0's "conveying," the scope of LGPL linking), flag for attorney review and surface the factors cutting both ways.
verify tagsEnd with the next-steps decision tree per CLAUDE.md ## Outputs. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.
If the scan surfaced more than ~10 packages, or any time the user asks: offer the dashboard (see CLAUDE.md ## Outputs → Dashboard offer for data-heavy outputs). Shape the offer to what's useful here — counts by license family (permissive / weak copyleft / strong copyleft / AGPL / proprietary / unknown), risk distribution, and a table of findings with severity and package version.
© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in ip-legal/skills/oss-review of anthropics/claude-for-legal.
Open the folder on GitHubat commit 4a6c651
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.
Oss Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Oss Review this skillanthropics/claude-for-legal | 9.6k | 3 repos | ~5k | Automated safety check: Pass | Apache-2.0 | |
| Dependency Scanningseb1n/awesome-ai-agent-skills | 206 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Bom Convert Validatecdxgen/cdxgen | 1.1k | — | ~1.5k | Automated safety check: Warn | Apache-2.0 | |
| Sbom Generate686f6c61/alfred-dev | 117 | — | ~780 | Automated safety check: Pass | MIT | |
| Codebase Cleanup Deps Auditaiskillstore/marketplace | 433 | 7 repos | ~490 | Automated safety check: Pass | None | |
| Open Source PolicyHack23/cia | 239 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 |
seb1n/awesome-ai-agent-skills
Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.
cdxgen/cdxgen
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…
686f6c61/alfred-dev
Usar para generar Software Bill of Materials para cumplimiento del CRA.
aiskillstore/marketplace
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.
Hack23/cia
Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development
Mathews-Tom/armory
Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.
anthropics/claude-for-legal
Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.
anthropics/claude-for-legal
Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.
anthropics/claude-for-legal
Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.
anthropics/claude-for-legal
Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.
anthropics/claude-for-legal
Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.
anthropics/claude-for-legal
Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.
Categories
Open source license compliance check for a dependency list, a single library, or outbound code. Oss Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Open source license compliance check for a dependency list, a single library, or outbound code.
Oss Review fits situations like: reviewing a manifest; repo for copyleft obligations and license compatibility; asked whether a library can ship; preparing code to be open-sourced.
Run `npx skills add anthropics/claude-for-legal --skill oss-review -a claude-code`. Or copy the skill folder (ip-legal/skills/oss-review in anthropics/claude-for-legal) into .claude/skills/oss-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add anthropics/claude-for-legal --skill oss-review -a codex`. Or copy the skill folder (ip-legal/skills/oss-review in anthropics/claude-for-legal) into .agents/skills/oss-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill oss-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oss-review, .gemini/skills/oss-review, .github/skills/oss-review and .opencode/skills/oss-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Oss Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Oss Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Oss Review: Dependency Scanning (seb1n/awesome-ai-agent-skills, 206 stars), Bom Convert Validate (cdxgen/cdxgen, 1.1k stars), Sbom Generate (686f6c61/alfred-dev, 117 stars) and Codebase Cleanup Deps Audit (aiskillstore/marketplace, 433 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,633 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.
Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.