# mcp-license-audit

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/webmoleai/mcp-license-audit  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/mcp-license-audit

## Description
Audit dependency licenses for compatibility issues. Flags GPL/AGPL conflicts.

## Claude Desktop Quick Installation
Heuristic fallback — verify the package name and runner against the repository README before running it. Uses `npx` (confidence: low):

```json
"mcpServers": {
  "mcp-license-audit": {
    "command": "npx",
    "args": ["-y","mcp-license-audit"]
  }
}
```

## Documentation & README

# mcp-license-audit

MCP server that audits your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.

## What It Does

- Parses a `package.json` file (dependencies + devDependencies)
- Fetches license info for each package from the npm registry
- Classifies licenses: permissive (MIT, Apache, BSD, ISC), copyleft (GPL, AGPL), weak-copyleft (LGPL, MPL), unknown
- Detects conflicts (e.g., GPL dependency in an MIT-licensed project)
- Returns a structured JSON report with risk level and summary

## Install

```bash
npm install -g mcp-license-audit
# or run directly:
npx mcp-license-audit
```

## Configure in Claude Code

Add to your `.claude/mcp.json` or `~/.claude/mcp.json`:

```json
{
  "mcpServers": {
    "license-audit": {
      "command": "npx",
      "args": ["mcp-license-audit"]
    }
  }
}
```

Or if installed globally:

```json
{
  "mcpServers": {
    "license-audit": {
      "command": "mcp-license-audit"
    }
  }
}
```

## Tool: `audit-licenses`

**Input:** `packageJson` — the full contents of a `package.json` file as a string.

**Output:** JSON report:

```json
{
  "totalDependencies": 15,
  "analyzed": 15,
  "licenses": {
    "MIT": ["express", "lodash"],
    "Apache-2.0": ["typescript"],
    "GPL-3.0": ["some-package"],
    "unknown": ["private-pkg"]
  },
  "conflicts": [
    {
      "package": "some-package",
      "license": "GPL-3.0",
      "issue": "GPL dependency in MIT project — must open-source your code if distributed"
    }
  ],
  "riskLevel": "medium",
  "summary": "15 deps analyzed. 1 GPL conflict found. 1 unknown license."
}
```

**Risk levels:** `low` (no copyleft), `medium` (weak copyleft or many unknowns), `high` (GPL/AGPL found).

## Limits

- Analyzes first 20 dependencies for speed
- Only supports npm packages (no pip/cargo/gem support yet)
- License data comes from the npm registry — private packages return "unknown"

## Build from Source

```bash
npm install
npm run build
node dist/index.js
```

