Audit Python and npm dependency licenses before you ship, judged against how you distribute.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Audit Python and npm dependency licenses for compliance before you ship β an MCP server for AI coding agents.
An AI agent can add pdf-renderer to your project in one second. It will not tell you that
pdf-renderer is AGPL-3.0 and that shipping it inside a closed-source product is a license
violation. License data and compatibility rules are things a model cannot reliably recall β
packages relicense between versions (MongoDB β SSPL, Redis β BUSL, Elasticsearch β Elastic-2.0),
and "the source is on GitHub" does not mean "free to ship".
license-sentinel reads what is actually on your disk and judges it against how you
distribute your product.
CLEAN / REVIEW / BLOCK, each with the reason in plain language.| Tool | What it does |
|---|---|
audit_project(path, context) | Scan a project's dependencies and return counts plus every BLOCKING and REVIEW item with reasons. |
check_package(names, context) | Check specific packages or messy license strings before installing. Accepts AGPL-3.0, BUSL-1.1, GPLv3, Apache License 2.0, MIT OR Apache-2.0. |
generate_notices(path, output) | Write a THIRD-PARTY-NOTICES.md attribution document for client hand-off. |
There is also a pre_release_license_review prompt that chains the audit into a go/no-go review.
Claude Desktop / Cursor / Windsurf / VS Code Copilot / Zed all read the same shape:
If you installed with pip instead, use "command": "license-sentinel" with no args.
Restart the client and the three tools appear.
The same dependency is fine in one context and fatal in another, so every tool takes a
context argument:
| Context | Meaning | What it blocks |
|---|---|---|
proprietary (default) | Closed-source product you distribute | GPL/AGPL/SSPL, BUSL/Elastic, non-commercial |
saas-backend | Never distributed, only runs on your servers | AGPL/SSPL (network trigger), BUSL/Elastic |
permissive | Your own project is MIT/Apache/BSD | Anything copyleft that would contaminate your terms |
copyleft-ok | Your own project is GPL family | Only source-available and non-commercial |
.venv/ / venv/ / env/ installed packages (dist-info/METADATA), requirements.txt, pyproject.toml (PEP 621, poetry, dependency-groups)node_modules/*/package.json (including scoped packages), package.json dependenciesIf a dependency is declared but not installed, it is reported with an UNKNOWN license rather
than silently dropped β an unlicensed dependency is all-rights-reserved by default.
No HTTP client is imported anywhere in this package. The scan is read-only (except
generate_notices, which writes the file you name). Nothing is uploaded.
.venv and no
node_modules, declared-only dependencies come back UNKNOWN.LICENSE_SENTINEL_SCAN_CURRENT_ENV=1 to change that.MIT
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/license-sentinel)<a href="https://allmcps.com/mcp/license-sentinel"><img src="https://allmcps.com/api/badge/license-sentinel?style=directory" alt="License Sentinel on AllMCPs" /></a>