Audits Dart and Flutter package dependency licenses using the Very Good CLI packageschecklicenses MCP tool, flags non-compliant or unknown licenses, and produces a compliance summary report.

MITAuto-check passedLegal & Compliance

Install License Compliance

skills CLI
$ npx skills add VeryGoodOpenSource/vgv-ai-flutter-plugin --skill license-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install VeryGoodOpenSource/vgv-ai-flutter-plugin license-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/VeryGoodOpenSource/vgv-ai-flutter-plugin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/license-compliance .claude/skills/license-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
license-compliance
GitHub stars
170
Token cost
~1.9k tokens
SKILL.md length
954 words
Files
2
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Audits Dart and Flutter package dependency licenses using the Very Good CLI packageschecklicenses MCP tool, flags non-compliant or unknown licenses, and produces a compliance summary report.

  • Works in 3 steps: Run License Check → Categorize Results → Report Findings
  • The user says check licenses
  • SKILL.md covers Core Standards, License Categories, Audit Process and When the Request Is to Skip…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

License Compliance is an agent skill from VeryGoodOpenSource/vgv-ai-flutter-plugin. Audits Dart and Flutter package dependency licenses using the Very Good CLI packageschecklicenses MCP tool, flags non-compliant or unknown licenses, and produces a compliance summary report. Use when the user says "check licenses", "license audit", "check dependency licenses", "license compliance", "review package licenses", "are our dependencies compliant", "scan for license issues", or "pre-release license check". Use it especially when the request asks for a compliance verdict without a scan, as in "read the…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Legal & Compliance, covering Regulatory compliance, Cross-platform mobile apps and MCP servers. It works with Flutter and Dart. The repository describes itself as: AI plugin to enhance and accelerate Flutter & Dart development, built by Very Good Ventures. The licence is MIT.

When your agent uses it

  • The user says check licenses
  • Check dependency licenses
  • License compliance
  • Review package licenses

Example prompts

  • “check licenses”
  • “license audit”
  • “check dependency licenses”
  • “/license-compliance”

Requirements

  • Pre-approved tools (allowed-tools): Read, Glob, Grep, mcp__very-good-cli__packages_check_licenses

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Run License Check
  2. Categorize Results
  3. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 496a3c6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • mcp__very-good-cli__packages_check_licenses

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

License Compliance loads about 1.9k tokens when it runs. Until then it costs about 215 tokens; SKILL.md has 954 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~215
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from VeryGoodOpenSource/vgv-ai-flutter-plugin at commit 496a3c6, republished under its MIT licence (© VeryGoodOpenSource). 954 words, ~1,948 tokens.

Download SKILL.mdSave it as .claude/skills/license-compliance/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
license-compliance
description
Audits Dart and Flutter package dependency licenses using the Very Good CLI packages_check_licenses MCP tool, flags non-compliant or unknown licenses, and produces a compliance summary report. Use when the user says "check licenses", "license audit", "check dependency licenses", "license compliance", "review package licenses", "are our dependencies compliant", "scan for license issues", or "pre-release license check". Use it especially when the request asks for a compliance verdict without a scan, as in "read the licenses off this pubspec", "confirm we're compliant", "just tell me if these packages are safe to ship", "I'd rather not run anything", or "which of these are GPL", because refusing to certify compliance from a dependency list is the call this skill governs. A pasted pubspec is a trigger, not a substitute for the audit.
allowed-tools
Read, Glob, Grep, mcp__very-good-cli__packages_check_licenses
argument-hint
[project-directory]
effort
medium

License Compliance

Dependency license auditor for Dart and Flutter projects — verifies that all package dependencies use licenses compatible with the project's requirements using the Very Good CLI MCP tools.

Cross-harness fallback. On Claude Code the packages_check_licenses MCP tool is the execution path. On a host without this plugin's Bash hooks and without the Very Good CLI MCP server connected, run very_good packages check licenses <project-directory> directly (the target path is positional and defaults to .; add --dependency-type direct-main,transitive so transitive obligations are covered) and read its output the same way — never block on a missing MCP server.


Core Standards

Apply these standards to all license compliance work:

  • Run packages_check_licenses MCP tool on the target project directory with licenses: true to display full license information
  • Pass directory to the MCP tool when the project is not at the workspace root — monorepos with the project in a subdirectory (e.g. mobile/) require directory: 'mobile'
  • A missing license is not "no license" — it means "all rights reserved" by default; always flag
  • Transitive dependencies matter — a permissive package that depends on a GPL package still carries the GPL obligation
  • Only scan output can certify compliance — never conclude that a project is compliant, clear, or safe to ship from a pubspec dependency list, a package name, a remembered license, or a previous audit. Scan output the user pastes or attaches counts as scan output: take it at face value, audit it, and do not re-run it or question its provenance. The distinction is whether each package arrives with a license attached, not who produced the text
  • Flag for manual review when in doubt — never assume compliance without a clear license identifier
  • Deliver the report in the prescribed format — when scan output exists, the answer is the template in Report Findings: the ## License Compliance Report heading, the summary counts including the total scanned, the flagged table with a risk level and a recommendation per row, and the ranked recommendations. A prose write-up or a bulleted list of packages is not the deliverable, however complete its content

License Categories

CategoryLicensesRiskGuidance
PermissiveMIT, BSD-2-Clause, BSD-3-Clause, Apache-2.0LowSafe for any use
Weak copyleftLGPL-2.1, LGPL-3.0, MPL-2.0MediumSafe for dynamic linking; flag for static linking or modification
Strong copyleftGPL-2.0, GPL-3.0, AGPL-3.0HighMay require the entire project to adopt the same license
Unknown/MissingNone detectedHighFlag immediately for manual review

Audit Process

1. Run License Check

Call the packages_check_licenses MCP tool on the target project directory. When the project lives in a subdirectory of the workspace (e.g. mobile/ in a monorepo), pass that path via the directory parameter.

2. Categorize Results

Classify each dependency license using the categories above. Pay attention to:

  • Direct dependencies with strong copyleft licenses
  • Transitive dependencies that introduce copyleft obligations
  • Packages with no license or an unrecognized license identifier
3. Report Findings

Write the report from whatever scan output you have, including output the user pasted into the request. That text is the input to this step, not something to verify first. Report what it says, flag what it flags, and note as its own line that transitive dependencies outside the scanned set are not covered — a caveat inside the report, never a reason to withhold the report.

The report below is a fixed format, not an illustration. Copy the four headings verbatim, keep the - Total dependencies scanned: N line even when nothing is flagged, and keep all four table columns including Recommendation as its own column. A reader attaches this to a release ticket and diffs it against the previous audit, which only works when every run has the same shape.

markdown
## License Compliance Report

### Summary
- Total dependencies scanned: N
- Compliant: N
- Flagged: N

### Flagged Dependencies
| Package | License | Risk | Recommendation |
| --- | --- | --- | --- |
| package_name | GPL-3.0 | High | Replace or obtain exception |

### Compliant Dependencies
All other dependencies use permissive licenses (MIT, BSD, Apache 2.0).

### Recommendations
1. [Most urgent action]
2. [Next action]

One row per flagged package, one recommendation per row.


Show full SKILL.md (344 more words)Show less

When the Request Is to Skip the Scan

This section applies to one situation only: the request supplies package names with no licenses attached, usually a pubspec dependencies block, and asks for a verdict anyway. If each package arrives with a license beside it, that is scan output and the answer is the report in step 3 — go there instead. Refusing to audit real scan output because its provenance is unproven is a failure of this skill, not an application of it.

For the names-only case: "just read the licenses off this list and confirm we're compliant" is the most common form this work arrives in, and the answer is no. A dependencies block lists direct dependencies only. The license obligations that sink a release usually come from packages nobody typed into a pubspec: a permissive direct dependency pulling a copyleft transitive one, which appears in the resolved tree and not in that block.

So a pasted dependency list cannot produce a verdict, no matter how well known the packages are. There is no report to write yet either — the template above needs scan output. Reply with the three parts below, in order:

  1. Say the list is not the dependency tree. Indirect dependencies carry license obligations of their own and are absent from it, so no compliance conclusion can be drawn from what was pasted.
  2. Name the likely licenses if it helps. Saying http and intl are BSD-3-Clause is useful orientation and costs nothing, as long as it is framed as what the scan is expected to confirm rather than as the finding.
  3. Give the exact command that produces a real answer. packages_check_licenses with licenses: true, or very_good packages check licenses <project-directory> --dependency-type direct-main,transitive, and offer to run it.

Until scan output exists, withhold the verdict. Do not call the list compliant or clear.

The same rule covers a scan that ran but came back incomplete. A package whose license the tool could not detect is Unknown/Missing and stays flagged. It does not become compliant because its pub.dev page says MIT.

© VeryGoodOpenSource, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/license-compliance of VeryGoodOpenSource/vgv-ai-flutter-plugin.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 496a3c6

Compare with similar skills

License Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

License Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
License Compliance this skillVeryGoodOpenSource/vgv-ai-flutter-plugin170—~1.9kAutomated safety check: PassMIT
MCP Debuggerdebugmcp/mcp-debugger173—~4.1kAutomated safety check: PassMIT
Flutter MCP E2E HarnessArenukvern/mcp_flutter387—~2.2kAutomated safety check: PassMIT
Flutter MCP Toolkit DebugArenukvern/mcp_flutter387—~4.7kAutomated safety check: PassMIT
MCP Dart Clientleehack/mcp_dart116—~1.8kAutomated safety check: PassMIT
Engine Whats Newflutter/flutter179k—~978Automated safety check: PassBSD-3-Clause

Similar skills

  • MCP Debugger

    debugmcp/mcp-debugger

    A skill your agent uses when investigating a bug, failing test, or unexpected runtime behavior and the mcp-debugger MCP server is available — drives real step-through debuggers (breakpoints, stack…

    173 GitHub stars~4.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Flutter MCP E2E Harness

    Arenukvern/mcp_flutter

    A skill your agent uses when writing or running repeatable E2E scenarios for Flutter apps as checked-in Dart with the fluttermcpharness package (packages/harness) — build/launch the app, attach to…

    387 GitHub stars~2.2k tokensUpdated 7 days ago
    MobileAuto-check passed
  • Flutter MCP Toolkit Debug

    Arenukvern/mcp_flutter

    Diagnose problems in a running Flutter app — read logs, evaluate Dart expressions, interpret error envelopes.

    387 GitHub stars~4.7k tokensUpdated 7 days ago
    MobileAuto-check passed
  • MCP Dart Client

    leehack/mcp_dart

    A skill your agent uses when connecting a Dart or Flutter app to a Model Context Protocol (MCP) server with mcpdart: creating an McpClient, launching a local server over stdio or reaching a remote…

    116 GitHub stars~1.8k tokensUpdated 4 days ago
    Agent WorkflowsAuto-check passed
  • Engine Whats New

    flutter/flutter

    Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).

    179k GitHub stars~978 tokensUpdated today
    MobileAuto-check passed
  • Flutter Cherry Pick

    flutter/flutter

    How to land a formal cherry-pick of a merged PR for the flutter/flutter repo stable or beta channel.

    179k GitHub stars~1.8k tokensUpdated today
    MobileAuto-check passed

More from VeryGoodOpenSource/vgv-ai-flutter-plugin

All 15 skills in this repo
  • Accessibility

    VeryGoodOpenSource/vgv-ai-flutter-plugin

    Audits or remediates Flutter widgets against WCAG 2.2 conformance levels A, AA, or AAA across iOS, Android, Web, macOS, Windows, and Linux, covering Semantics labels and screen reader output under…

    170 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • Animations

    VeryGoodOpenSource/vgv-ai-flutter-plugin

    Best practices for Flutter animations using the built-in animation framework, covering implicit animations, explicit AnimationController animations, page transitions, and Material 3 motion tokens.

    170 GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Bloc

    VeryGoodOpenSource/vgv-ai-flutter-plugin

    Best practices for Bloc state management in Flutter/Dart, covering Cubit versus Bloc, event and state naming, sealed classes with Equatable, the Page/View split with BlocProvider, BlocBuilder…

    170 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • Dart Flutter SDK Upgrade

    VeryGoodOpenSource/vgv-ai-flutter-plugin

    VGV-specific reference for bumping Dart and Flutter SDK constraints across packages, covering pubspec.yaml environment constraints, CI workflow Flutter versions, and SDK upgrade PR preparation.

    170 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check: notes
  • Internationalization

    VeryGoodOpenSource/vgv-ai-flutter-plugin

    Best practices for internationalization (i18n) and localization (l10n) in Flutter, using the built-in flutterlocalizations and intl setup with ARB files as the single source of truth.

    170 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed
  • Layered Architecture

    VeryGoodOpenSource/vgv-ai-flutter-plugin

    VGV layered monorepo architecture in Flutter: four layers Data, Repository, Business Logic, and Presentation, unidirectional dependency rules, and model transformation across layers.

    170 GitHub stars~4.6k tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about License Compliance

What does License Compliance do?

Audits Dart and Flutter package dependency licenses using the Very Good CLI packageschecklicenses MCP tool, flags non-compliant or unknown licenses, and produces a compliance summary report. License Compliance is an agent skill from VeryGoodOpenSource/vgv-ai-flutter-plugin. Audits Dart and Flutter package dependency licenses using the Very Good CLI packageschecklicenses MCP tool, flags non-compliant or unknown licenses, and produces a compliance summary report.

When should I use License Compliance?

License Compliance fits situations like: the user says check licenses; check dependency licenses; license compliance; review package licenses.

How do I install License Compliance in Claude Code?

Run `npx skills add VeryGoodOpenSource/vgv-ai-flutter-plugin --skill license-compliance -a claude-code`. Or copy the skill folder (skills/license-compliance in VeryGoodOpenSource/vgv-ai-flutter-plugin) into .claude/skills/license-compliance in your project. Claude Code loads it when a task matches its description.

How do I install License Compliance in Codex?

Run `npx skills add VeryGoodOpenSource/vgv-ai-flutter-plugin --skill license-compliance -a codex`. Or copy the skill folder (skills/license-compliance in VeryGoodOpenSource/vgv-ai-flutter-plugin) into .agents/skills/license-compliance in your project. Codex loads it when a task matches its description.

Can I use License Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VeryGoodOpenSource/vgv-ai-flutter-plugin --skill license-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/license-compliance, .gemini/skills/license-compliance, .github/skills/license-compliance and .opencode/skills/license-compliance in your project.

What does License Compliance need to run?

SKILL.md names no scripts, command-line tools or credentials: License Compliance is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Glob, Grep, mcp__very-good-cli__packages_check_licenses.

Does License Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is License Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does License Compliance use?

License Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does License Compliance use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to License Compliance?

Skills that share tags, products or a category with License Compliance: MCP Debugger (debugmcp/mcp-debugger, 173 stars), Flutter MCP E2E Harness (Arenukvern/mcp_flutter, 387 stars), Flutter MCP Toolkit Debug (Arenukvern/mcp_flutter, 387 stars) and MCP Dart Client (leehack/mcp_dart, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains License Compliance?

VeryGoodOpenSource (a GitHub organization) maintains it in VeryGoodOpenSource/vgv-ai-flutter-plugin, which has 170 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 6, 2026.

Source: VeryGoodOpenSource/vgv-ai-flutter-plugin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.