Dependency License Auditor

    1

    The same dependency is harmless in an internal tool and a problem in a hosted product. This tells you which case you are in.

    $5.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Dependency License Auditor

    Example session with this skill installed

    Run a license audit on this repository. We ship this as a distributed desktop application. The project is currently licensed under MIT.

    • Read your context and instructions
    • Compiled the dependency license auditor
    • Generated the document

    I have audited the dependencies for this project. Since this is a distributed binary under an MIT license, I have focused on copyleft triggers that would require source disclosure.

    Verdict: Ship with conditions. You have one strong copyleft conflict that must be resolved before distribution.

    License Compliance Report

    ClassCountHighest-risk package
    Strong Copyleft1lib-core-utils
    Weak Copyleft2fast-redact
    Permissive142N/A
    Unknown1internal-helper-tool

    Findings

    PackageVersionLicenseClassDirect/TransitiveRuntime/DevWhy it mattersAction
    lib-core-utils2.4.1GPL-3.0Strong CopyleftDirectRuntimeAs a distributed binary, including this library likely requires you to open-source your entire application.Replace with an MIT/Apache alternative.
    fast-redact3.1.0MPL-2.0Weak CopyleftTransitiveRuntimeRequires you to provide the source code for this library if modified.No action needed if the library is unmodified.
    internal-helper-tool0.0.1NoneUnknownDirectDevNo license detected. Without a grant of rights, usage is legally ambiguous.Verify if this is an internal repo or add a license file.

    Attribution Obligations
    The project requires an attribution file for 142 MIT/BSD dependencies. A THIRD_PARTY_LICENSES file was not found in the root directory. You are currently failing to meet the notice retention requirements of your permissive dependencies.

    Unknowns

    • internal-helper-tool: No license field in package.json and no LICENSE file found in the subfolder.

    Note: This is an engineering analysis of dependency metadata, not legal advice.

    Next steps

    1. Replace lib-core-utils with a permissively licensed alternative to maintain your proprietary status.
    2. Generate a THIRD_PARTY_LICENSES file to satisfy attribution requirements.
    3. Add a license file to the internal-helper-tool directory.

    dependency-license-auditor.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Identify GPL/AGPL contamination in proprietary codebases.Audit transitive dependencies before a company acquisition or exit.Generate attribution reports to satisfy MIT/Apache notice requirements.Flag unlicensed or "Unknown" packages that lack a legal grant of rights.

    About this skill

    The problem

    Engineering leads often ship products without knowing if a transitive dependency's license forces them to open-source their proprietary code. Manually auditing hundreds of deep-tree dependencies for copyleft contamination is slow and error-prone.

    What it does

    • Identifies the project's distribution model (SaaS, binary, or internal) to determine specific legal obligations.
    • Enumerates direct and transitive dependencies from lockfiles across npm, Python, Rust, Go, Java, and Ruby.
    • Classifies licenses into risk categories: Permissive, Weak Copyleft, Strong Copyleft, and Network Copyleft (AGPL).
    • Flags compatibility conflicts, such as Apache-2.0 in GPL-2.0 projects or AGPL-3.0 in SaaS deployments.
    • Generates a prioritized report with actionable steps for high-risk or unlicensed packages.

    Frameworks & tools

    Supports npm, yarn, pnpm, poetry, cargo, go-licenses, maven, and bundler.

    Why this beats prompting it yourself

    Generic prompts often hallucinate licenses based on package names or fail to distinguish between dev-dependencies and runtime code. This skill uses lockfile analysis and applies a specific risk framework based on how you actually distribute your software.

    Use cases

    • Pre-acquisition due diligence to ensure IP cleanliness.
    • Validating a new dependency before adding it to a proprietary binary.
    • Generating an SBOM-adjacent report for enterprise customers.
    • Checking for "network copyleft" (AGPL) risk in hosted SaaS environments.

    Known limitations

    Does not scan for security vulnerabilities. Requires an existing lockfile to accurately resolve transitive versions.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean today

    • Passed all security checks, Safe to install

    Listedtoday

    Frequently Asked Questions