Agent skill

Licence Notice Auditor

by mohitagw15856 in mohitagw15856/pm-claude-skills

A skill your agent uses when asked to check a project's licences, audit dependencies before open-sourcing or selling, write a NOTICE file, find licence conflicts, or check whether bundled fonts…

MITAuto-check passed

Install Licence Notice Auditor

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill licence-notice-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills licence-notice-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/licence-notice-auditor .claude/skills/licence-notice-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
licence-notice-auditor
GitHub stars
1.4k
Token cost
~1.2k tokens
SKILL.md length
583 words
Files
2 (incl. references)
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when asked to check a project's licences, audit dependencies before open-sourcing or selling, write a NOTICE file, find licence conflicts, or check whether bundled fonts…

  • Works in 5 steps: Inventory commands → Inventory table → Findings → …
  • Asked to check a projects licences
  • SKILL.md covers Required Inputs, Output Structure, Quality Checks and Anti-Patterns, plus 1 more section
  • Calls npx and cargo

What it does

Licence Notice Auditor is an agent skill from mohitagw15856/pm-claude-skills. Use when asked to check a project's licences, audit dependencies before open-sourcing or selling, write a NOTICE file, find licence conflicts, or check whether bundled fonts, images or datasets can be shipped. Produces an inventory of code, data and media dependencies with their licences, flags for conflicts and unclear ownership, and a draft NOTICE.md, with a clear statement that the output is not legal advice.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/licence-compatibility.md`).

The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked to check a projects licences
  • Audit dependencies before open-sourcing
  • Write a NOTICE file
  • Find licence conflicts

Example prompts

  • “/licence-notice-auditor”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Inventory commands
  2. Inventory table
  3. Findings
  4. NOTICE.md draft
  5. Gaps to close

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Licence Notice Auditor loads about 1.2k tokens when it runs, and up to ~2k if it reads all its reference files. Until then it costs about 110 tokens; SKILL.md has 583 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 583 words, ~1,196 tokens.

Download SKILL.mdSave it as .claude/skills/licence-notice-auditor/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
licence-notice-auditor
description
Use when asked to check a project's licences, audit dependencies before open-sourcing or selling, write a NOTICE file, find licence conflicts, or check whether bundled fonts, images or datasets can be shipped. Produces an inventory of code, data and media dependencies with their licences, flags for conflicts and unclear ownership, and a draft NOTICE.md, with a clear statement that the output is not legal advice.
version
1.0.0

Licence and Notice Auditor

Before a project is open-sourced, sold or bundled into something else, someone has to know what is inside it and on what terms. The risks are rarely in the main dependencies: they hide in a copied snippet, a bundled font, a dataset scraped years ago, or a screenshot in the docs. This skill inventories everything the project ships, flags conflicts and unclear ownership, and drafts the NOTICE file.

This output is not legal advice. It is a structured inventory to take to a qualified lawyer when the stakes are real: a sale, a funding round, a commercial licence, or any conflict flagged red below.

Required Inputs

Ask for these if not provided:

  • The project's own licence, or the licence being considered
  • How it is distributed: source only, binaries, a hosted service, an app store, embedded in hardware
  • Dependency manifests: package.json, requirements.txt, go.mod, Cargo.toml, or the output of a licence tool
  • Bundled non-code assets: fonts, icons, images, audio, video, datasets, model weights
  • Copied code: snippets from blogs, Stack Overflow, other repos, or AI tools

Output Structure

1. Inventory commands

The commands to produce a machine-readable list for the stack, for example npx license-checker --summary (Node), pip-licenses --format=markdown (Python), go-licenses report ./... (Go), cargo about generate (Rust), and reuse lint for per-file headers.

2. Inventory table

| Component | Type (code, font, image, data, model) | Version | Licence (SPDX ID) | Source of truth (file or URL) | How it is used (bundled, linked, dev only) |

Dev-only dependencies are listed but marked, since they are usually not distributed.

3. Findings

Each finding rated red (conflict or unknown terms on something distributed), amber (an obligation to meet, such as attribution or a NOTICE carry-over) or green (no action):

| Rating | Component | Issue | Why it matters for this distribution | Suggested action |

Always check for:

  • copyleft code (GPL, AGPL, LGPL, MPL) and whether the distribution model triggers its terms (see references/licence-compatibility.md)
  • Apache-2.0 dependencies with their own NOTICE files, whose contents must be carried over
  • components with no licence, which means all rights reserved
  • non-commercial or no-derivatives terms (for example CC BY-NC) on anything in a commercial product
  • fonts, images and datasets with unclear origin or ownership
  • copied snippets with no recorded source
Show full SKILL.md (219 more words)Show less
4. NOTICE.md draft
markdown
# Notices

[Project] is licensed under [licence]. It includes the following third-party components:

## [Component] [version]
- Licence: [SPDX ID]
- Source: [URL]
- Copyright: [holder and year, as stated by the component]
[Any NOTICE text the component requires, copied verbatim]

One section per distributed component that requires attribution, sorted alphabetically.

5. Gaps to close

A short checklist of facts only the author can supply (the origin of a font, who drew the logo, where a dataset came from) and the decisions needing a lawyer.

Quality Checks

  • The not-legal-advice statement appears at the top of the output
  • Every distributed component has an SPDX ID or is marked unknown
  • Every finding is rated red, amber or green with a suggested action
  • Components with no licence are flagged red, not assumed permissive
  • Fonts, images, datasets and copied snippets are covered, not only package dependencies
  • NOTICE text from Apache-2.0 components is carried over verbatim
  • No licence term is stated without naming the source file or URL it came from

Anti-Patterns

  • Auditing only package.json. The riskiest items are often the assets.
  • "No licence" read as "free to use". It means the opposite.
  • Generic compatibility verdicts. Whether a licence conflicts depends on how the project is distributed; say how.
  • Presenting the audit as clearance. It finds problems; it does not grant permission.

Example Trigger Phrases

  • "Audit my project's licences before I open-source it."
  • "Draft a NOTICE file for this app."
  • "Can I ship these fonts and icons in a commercial product?"
  • "Check my dependencies for GPL conflicts, we distribute a desktop app."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/licence-notice-auditor of mohitagw15856/pm-claude-skills.

  • SKILL.md
  • references/licence-compatibility.md

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Licence Notice Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Licence Notice Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Licence Notice Auditor this skillmohitagw15856/pm-claude-skills1.4k—~1.2kAutomated safety check: PassMIT
Dependency Auditoralirezarezvani/claude-skills28k—~1.1kAutomated safety check: PassMIT
Dependency Scanningsickn33/agentic-awesome-skills47k1 repos~2.4kAutomated safety check: PassMIT
Dependency Auditoralirezarezvani/claude-code-tresor777—~1.2kAutomated safety check: NotesMIT
Dependency Checkruvnet/ruflo74k—~258Automated safety check: PassMIT
Dependency Updatecodewhale-hq/Codewhale41k—~142Automated safety check: PassMIT

Similar skills

  • Dependency Auditor

    alirezarezvani/claude-skills

    Audit and manage dependencies across multi-language projects.

    28k GitHub stars~1.1k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Dependency Scanning

    sickn33/agentic-awesome-skills

    Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.

    47k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Dependency Auditor

    alirezarezvani/claude-code-tresor

    Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

    777 GitHub stars~1.2k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: notes
  • Dependency Check

    ruvnet/ruflo

    Scan project dependencies for known vulnerabilities and CVEs.

    74k GitHub stars~258 tokensUpdated yesterday
    SecurityAuto-check passed
  • Dependency Update

    codewhale-hq/Codewhale

    Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify.

    41k GitHub stars~142 tokensUpdated today
    DevelopmentAuto-check passed
  • Dependency Auditor

    borghei/Claude-Skills

    Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust.

    891 GitHub stars~1.8k tokensUpdated 4 days ago
    SecurityAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Licence Notice Auditor

What does Licence Notice Auditor do?

A skill your agent uses when asked to check a project's licences, audit dependencies before open-sourcing or selling, write a NOTICE file, find licence conflicts, or check whether bundled fonts…. Licence Notice Auditor is an agent skill from mohitagw15856/pm-claude-skills. Use when asked to check a project's licences, audit dependencies before open-sourcing or selling, write a NOTICE file, find licence conflicts, or check whether bundled fonts, images or datasets can be shipped.

When should I use Licence Notice Auditor?

Licence Notice Auditor fits situations like: asked to check a projects licences; audit dependencies before open-sourcing; write a NOTICE file; find licence conflicts.

How do I install Licence Notice Auditor in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill licence-notice-auditor -a claude-code`. Or copy the skill folder (skills/licence-notice-auditor in mohitagw15856/pm-claude-skills) into .claude/skills/licence-notice-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Licence Notice Auditor in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill licence-notice-auditor -a codex`. Or copy the skill folder (skills/licence-notice-auditor in mohitagw15856/pm-claude-skills) into .agents/skills/licence-notice-auditor in your project. Codex loads it when a task matches its description.

Can I use Licence Notice Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill licence-notice-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/licence-notice-auditor, .gemini/skills/licence-notice-auditor, .github/skills/licence-notice-auditor and .opencode/skills/licence-notice-auditor in your project.

What does Licence Notice Auditor need to run?

Going by SKILL.md and its folder, Licence Notice Auditor needs the command-line tools its instructions call (npx and cargo). Our summary lists: Node.js.

Does Licence Notice Auditor access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Licence Notice Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Licence Notice Auditor use?

Licence Notice Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Licence Notice Auditor use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 766 tokens, read only when the agent opens those files.

What are the alternatives to Licence Notice Auditor?

Skills that share tags, products or a category with Licence Notice Auditor: Dependency Auditor (alirezarezvani/claude-skills, 28k stars), Dependency Scanning (sickn33/agentic-awesome-skills, 47k stars), Dependency Auditor (alirezarezvani/claude-code-tresor, 777 stars) and Dependency Check (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Licence Notice Auditor?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.