Agent skill

Checking License Compliance

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Audit a project's dependency licenses against an explicit policy (allow-list / deny-list / review-required) and flag incompatibilities before they ship to production.

MITAuto-check: notesLegal & Compliance

Install Checking License Compliance

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-license-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace checking-license-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/checking-license-compliance .claude/skills/checking-license-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
checking-license-compliance
GitHub stars
2.8k
Token cost
~2.1k tokens
SKILL.md length
756 words
Files
4 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Audit a project's dependency licenses against an explicit policy (allow-list / deny-list / review-required) and flag incompatibilities before they ship to production.

  • Works in 4 steps: Identify the project's own declared… → Identify policy → Run the scanner → …
  • : pre-release legal review
  • SKILL.md covers Overview, When the skill produces findings, Prerequisites and Instructions, plus 4 more sections
  • Runs Python scripts from its folder; calls python3 and jq

What it does

Checking License Compliance is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit a project's dependency licenses against an explicit policy (allow-list / deny-list / review-required) and flag incompatibilities before they ship to production. Reads SPDX license identifiers from npm package manifests, Python METADATA / PKG-INFO files, and pyproject.toml; classifies each license by family (permissive, weak-copyleft, strong-copyleft, proprietary, unknown); detects copyleft contamination and SPDX-incompatible license combinations. Use when: pre-release legal review, M&A code-audit due…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/check_licenses.py`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Regulatory compliance. It works with npm and Python. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • : pre-release legal review
  • M&A code-audit due diligence
  • Preparing an OSS attribution NOTICE file
  • Switching a projects own license

Example prompts

  • “check licenses”
  • “license compliance audit”
  • “SPDX scan”
  • “/checking-license-compliance”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Bash(python3:*), Bash(pip:*), Bash(npm:*), Glob

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify the project's own declared license
  2. Identify policy
  3. Run the scanner
  4. Interpret findings

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(python3:*)
    • Bash(pip:*)
    • Bash(npm:*)
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Checking License Compliance loads about 2.1k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 219 tokens; SKILL.md has 756 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~219
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:29
    - Write(.env)
  • NoteMentions a .env fileSKILL.md:30
    - Edit(.env)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 756 words, ~2,147 tokens.

Download SKILL.mdSave it as .claude/skills/checking-license-compliance/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
checking-license-compliance
description
Audit a project's dependency licenses against an explicit policy (allow-list / deny-list / review-required) and flag incompatibilities before they ship to production. Reads SPDX license identifiers from npm package manifests, Python METADATA / PKG-INFO files, and pyproject.toml; classifies each license by family (permissive, weak-copyleft, strong-copyleft, proprietary, unknown); detects copyleft contamination and SPDX-incompatible license combinations. Use when: pre-release legal review, M&A code-audit due diligence, preparing an OSS attribution NOTICE file, or switching a project's own license. Threshold: any GPL-family license in a project declaring MIT or Apache-2.0; any UNKNOWN-license package; any metadata-vs-source license mismatch. Trigger with: "check licenses", "license compliance audit", "SPDX scan", "GPL contamination check".
allowed-tools
Read, Bash(python3:*), Bash(pip:*), Bash(npm:*), Glob
compatibility
Designed for Claude Code
disallowed-tools
Bash(rm:*), Bash(curl:*), Bash(wget:*), Write(.env), Edit(.env)
version
3.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, licensing, spdx, compliance, pentest

Checking License Compliance

Overview

License compliance is a security concern only in the indirect sense that an unintended license obligation can force you to release proprietary source code, retroactively invalidate a customer contract, or render an M&A transaction infeasible. The cost is legal and contractual rather than exploitative — but the consequence ladder is real.

The most-stepped-on landmine is copyleft contamination: unintentionally including a GPL or AGPL-licensed package in a codebase the rest of which is permissively licensed (MIT, Apache-2.0, BSD). The terms of the GPL family say that any project distributing GPL code MUST itself release source under a GPL-compatible license. If your package.json says MIT and one of your transitive deps is GPL-2.0, you may be obligated to either re-license your code or remove the dep.

This skill audits the resolved dependency tree against an explicit policy file and emits findings for:

  • Direct deps with deny-listed licenses
  • Transitive deps with deny-listed licenses
  • Packages with UNKNOWN license metadata (no SPDX identifier)
  • License conflicts between metadata and source headers
  • Combinations of licenses that are mutually incompatible (e.g. GPL-2.0 + Apache-2.0 without a patent grant)

When the skill produces findings

FindingSeverityThresholdAffected control
Strong-copyleft in permissive projectCRITICALGPL-2.0/3.0, AGPL-3.0, or similar in a project declaring MIT/Apache-2.0/BSD(legal)
Weak-copyleft requiring source disclosureHIGHLGPL family in a project where the obligation isn't being met (no source-availability commitment)(legal)
Custom / non-SPDX licenseHIGHLicense field doesn't match SPDX expression syntax; requires legal review(legal)
Unknown licenseMEDIUMPackage has no license field, no LICENSE file detected(legal)
Deny-listed license (per policy)HIGHPackage license is in the explicit deny-list in the policy file(legal)
Review-required license (per policy)MEDIUMPackage license is in the review-list (e.g. MPL-2.0)(legal)
Incompatible license combinationHIGHDetected pair of licenses known to conflict (e.g. GPL-2.0-only + Apache-2.0)(legal)
License declared differently in metadata vs source headersMEDIUMLICENSE file says one license; per-file SPDX-License-Identifier headers say another(legal)
Permissive license requiring attributionINFOMIT/BSD/Apache-2.0 — emit reminder that NOTICE / attribution file should list the package(informational)

Prerequisites

  • Python 3.9+
  • Target project with EITHER a package.json + node_modules/ OR a Python project (pyproject.toml/requirements.txt/ installed venv)
  • Policy file at ./.license-policy.json (auto-detected) or passed via --policy. If absent, the skill uses a built-in default policy that flags strong copyleft for permissive parent projects.

Instructions

Step 1 — Identify the project's own declared license

The skill reads the project's top-level license from:

  • npm: package.json's license field
  • Python: pyproject.toml's [project].license table OR setup.cfg's license field

If the project's own license isn't declared, the skill emits a FATAL operational finding — license compliance can't be checked without a baseline. Add a license field before running.

Show full SKILL.md (318 more words)Show less
Step 2 — Identify policy

The policy file is JSON:

json
{
  "allow": ["MIT", "BSD-3-Clause", "Apache-2.0", "ISC", "BSD-2-Clause"],
  "deny":  ["GPL-2.0-only", "GPL-3.0-only", "AGPL-3.0-only", "AGPL-3.0-or-later"],
  "review": ["MPL-2.0", "EPL-2.0", "CDDL-1.0", "LGPL-3.0-or-later"],
  "project_license": "MIT"
}

allow: licenses that pass without comment. deny: licenses that produce a finding regardless of project license. review: licenses that produce a MEDIUM-severity finding for legal review. project_license: enforced — if the project declares this but a dep is in deny, finding is CRITICAL.

Step 3 — Run the scanner
bash
python3 ./scripts/check_licenses.py /path/to/project

Options:

Usage: check_licenses.py PATH [OPTIONS]

Options:
  --output FILE      Write findings to FILE (default: stdout)
  --format FMT       json | jsonl | markdown (default: markdown)
  --min-severity SEV (default: info)
  --policy FILE      Override default policy
  --emit-attribution  Also emit an attribution file (NOTICE.md) listing
                     every permissive-licensed dep that requires attribution
Step 4 — Interpret findings

CRITICAL findings block release pending legal review. Either remove the offending dep, replace it with a permissively-licensed alternative, or escalate to legal for a written exception.

HIGH findings require legal sign-off but don't necessarily block release if the legal posture (e.g. service-only deployment under AGPL) makes the obligation moot.

MEDIUM findings should be reviewed quarterly and either resolved or moved into an explicit exception list.

INFO findings are reminders that an attribution / NOTICE file should reference these packages.

Examples

bash
python3 ./scripts/check_licenses.py . --min-severity high --format json --output license-audit.json
jq -e '. == []' license-audit.json || { echo "License finding — legal review required"; exit 1; }
Example 2 — Generate attribution file
bash
python3 ./scripts/check_licenses.py . --emit-attribution --format markdown --output NOTICE.md
Example 3 — M&A due diligence
bash
mkdir -p evidence/legal/
python3 ./scripts/check_licenses.py target-acquisition-codebase/ \
    --format json \
    --output evidence/legal/license-audit-$(date +%Y%m%d).json

Output

JSON / JSONL / Markdown per lib/report.py. Exit codes: 0 clean, 1 high/critical, 2 error.

Each Finding includes:

  • id — license-compliance::<package>::<license-id>
  • severity — CRITICAL / HIGH / MEDIUM / LOW / INFO
  • category — license-compliance
  • summary — what's wrong
  • evidence — package name, declared license, project license, policy match
  • references — SPDX URL for the license, package home page

Error Handling

  • No project license → emits an INFO/operational finding recommending the operator add a license field, exits 2.
  • Unparseable policy file → exits 2 with a parser error message.
  • Package with malformed license field → treated as UNKNOWN license, emits MEDIUM finding.
  • No SPDX identifier in source headers → emits INFO finding reminding that SPDX header convention catches contamination at the file level.

Resources

  • references/THEORY.md — SPDX license expression syntax, family classifications, copyleft propagation theory, common license incompatibilities, when LGPL static linking matters, AGPL service-distribution clauses, public-domain edge cases (CC0 vs unlicense)
  • references/PLAYBOOK.md — Default policy templates per project type (proprietary product, OSS library, internal-only tool, SaaS service), attribution file generation, legal-counsel handoff templates, replacing copyleft deps with permissive alternatives

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/.curated/checking-license-compliance of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/PLAYBOOK.md
  • references/THEORY.md
  • scripts/check_licenses.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Checking License Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Checking License Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Checking License Compliance this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT
PCI DSS Compliancewshobson/agents40k11 repos~1.9kAutomated safety check: PassMIT
Review Op Docs APICVCUDA/CV-CUDA2.7k—~270Automated safety check: PassCustom licence
Dependency Auditoralirezarezvani/claude-skills28k—~1.1kAutomated safety check: PassMIT
Dependency Auditmohitagw15856/pm-claude-skills1.4k—~3.7kAutomated safety check: PassMIT
Dependency Audit Assistantaiskillstore/marketplace433—~2.2kAutomated safety check: NotesNone

Similar skills

  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 11 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Review Op Docs API

    CVCUDA/CV-CUDA

    Review a CV-CUDA operator's DOCS & API artifacts — operatorlist row, Python autofunction (fn + into), Limitations-table-vs-code consistency, docstrings, and SPDX headers.

    2.7k GitHub stars~270 tokensUpdated 24 days ago
    Legal & ComplianceAuto-check passed
  • Dependency Auditor

    alirezarezvani/claude-skills

    Audit and manage dependencies across multi-language projects.

    28k GitHub stars~1.1k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Dependency Audit

    mohitagw15856/pm-claude-skills

    Audits project dependencies for security vulnerabilities, license compliance issues, outdated packages, and transitive dependency risk.

    1.4k GitHub stars~3.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Dependency Audit Assistant

    aiskillstore/marketplace

    Reviews package dependencies for security vulnerabilities, outdated versions, and license compliance.

    433 GitHub stars~2.2k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Enterprise Tax Profile Matching

    Serein-81/financial_rag

    Builds a six-dimension profile of a company and matches it against tax policies to find applicable incentives, obligations, risks and optimization options.

    148 GitHub stars~1.5k tokensUpdated 4 mo ago
    Business, Finance & HRAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Checking License Compliance

What does Checking License Compliance do?

Audit a project's dependency licenses against an explicit policy (allow-list / deny-list / review-required) and flag incompatibilities before they ship to production. Checking License Compliance is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit a project's dependency licenses against an explicit policy (allow-list / deny-list / review-required) and flag incompatibilities before they ship to production.

When should I use Checking License Compliance?

Checking License Compliance fits situations like: : pre-release legal review; M&A code-audit due diligence; preparing an OSS attribution NOTICE file; switching a projects own license.

How do I install Checking License Compliance in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-license-compliance -a claude-code`. Or copy the skill folder (skills/.curated/checking-license-compliance in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/checking-license-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Checking License Compliance in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-license-compliance -a codex`. Or copy the skill folder (skills/.curated/checking-license-compliance in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/checking-license-compliance in your project. Codex loads it when a task matches its description.

Can I use Checking License Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-license-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/checking-license-compliance, .gemini/skills/checking-license-compliance, .github/skills/checking-license-compliance and .opencode/skills/checking-license-compliance in your project.

What does Checking License Compliance need to run?

Going by SKILL.md and its folder, Checking License Compliance needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and jq). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash(python3:*), Bash(pip:*), Bash(npm:*), Glob. Compatibility (from SKILL.md): Designed for Claude Code.

Does Checking License Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Checking License Compliance safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Checking License Compliance use?

Checking License Compliance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Checking License Compliance use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.

What are the alternatives to Checking License Compliance?

Skills that share tags, products or a category with Checking License Compliance: PCI DSS Compliance (wshobson/agents, 40k stars), Review Op Docs API (CVCUDA/CV-CUDA, 2.7k stars), Dependency Auditor (alirezarezvani/claude-skills, 28k stars) and Dependency Audit (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Checking License Compliance?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.