More screenshots

    Works with the AI tools you already use

    CClaude CodeCCursorCCodex CLIGGitHub CopilotGGemini CLI+17 more

    License & Dependency Compliance Auditor

    2

    Automated open-source license audit and risk assessment based on your project's specific distribution model.

    Secure checkout via Stripe

    0 installsSecurity scanned

    See it in action

    You say

    We're a proprietary SaaS about to raise a round. Audit our dependencies for any license that could be a problem in due diligence.

    Your agent does

    **Detected**: npm (pnpm-lock) + Go modules. Project license: none found. Distribution model: proprietary hosted SaaS. Analyzed 47 direct / 612 transitive deps. Writing the full report to LICENSE_AUDIT.md. **Summary**: 10 findings — 2 Critical, 3 High, 3 Medium, 2 Low. **Deal-breaker for due diligence**: `rrweb@2.0.0` is AGPL-3.0 and you ship as hosted SaaS. AGPL's network clause means using it obligates open-sourcing your entire application — exactly what an acquirer's counsel flags. Replace it with a permissive session-replay library before the raise. **Also Critical**: `fast-geoip-pro@1.4.2` has no license at all — that's all-rights-reserved, you have no right to ship it. **High**: project has no LICENSE declared; 96 Apache-2.0 deps ship to the browser with no aggregated NOTICE; a BUSL-1.1 Terraform provider needs its internal-use grant confirmed. **First moves**: swap rrweb, resolve the unlicensed geoip dep, add a project LICENSE. Full details with versions, SPDX ids, and fixes in LICENSE_AUDIT.md. This is an engineering analysis, not legal counsel — have an attorney confirm before the raise.

    What you get

    Find AGPL or GPL dependencies that conflict with a proprietary or SaaS productAudit dependency licenses before a release, fundraise, or acquisitionDetect source-available licenses (BUSL, SSPL) used against their termsIdentify missing attribution and NOTICE obligations before distributingFlag dependencies with no license that you have no right to shipCheck whether the project's own license is compatible with what it bundles

    About this skill

    A single GPL or AGPL dependency can force you to open-source your entire product, or sink an acquisition in due diligence. This skill audits your dependency tree for license risk — scoped to how your project actually ships, because the same dependency can be perfectly fine in one model and a violation in another.

    What makes it different

    It detects your distribution model first — hosted SaaS, distributed app/binary, open source, or internal tool — then judges every dependency against it. AGPL is a non-issue for a CLI tool but a Critical violation in proprietary SaaS. GPL is fine in your backend but not in a distributed binary. Generic license scanners ignore this; this one leads with it.

    What it checks

    • Copyleft conflicts AGPL in proprietary SaaS (the #1 startup trap — network use counts as distribution), GPL in distributed proprietary software, LGPL static-linking nuances, MPL file-level reciprocity
    • Source-available licenses: BUSL, SSPL, Elastic License, FSL, Confluent — used commercially against their terms. Tracks the version whipsaw (Redis → AGPL 2025, Elasticsearch → AGPL 2024, Terraform → BUSL 2023)
    • Attribution duties: missing NOTICE files (Apache-2.0), stripped copyright headers, no aggregated third-party licenses when distributing (including browser-shipped frontend bundles)
    • Unknown / no license: dependencies that are all-rights-reserved by default — no legal right to use
    • Your own project: missing or mismatched LICENSE, outbound/inbound incompatibility for open-source projects

    Ecosystems

    npm/yarn/pnpm, PyPI (pip/poetry/pipenv), Cargo, Go modules, Maven/Gradle, RubyGems, Composer, NuGet, pub.dev — reads direct and transitive dependencies from lock files, distinguishes shipped vs dev/build-only.

    How it works

    1. Detects ecosystems + your project license + distribution model (asks if ambiguous).
    2. Builds the dependency license map from lock files, with SPDX identifiers.
    3. Audits each against the distribution model and per-license obligations.
    4. Writes LICENSE_AUDIT.md graded by legal risk (Critical/High/Medium/Low) with the dependency, version, SPDX id, the exact conflict, and a concrete fix — replace with X, comply by Y, or get a commercial license.

    Why buy it

    • Distribution-aware — the only framing that gives correct answers; avoids both false alarms and missed violations
    • Due-diligence ready — run it before a release, fundraise, or acquisition; the report is the artifact reviewers ask for
    • Concrete fixes — named permissive replacements and exact compliance steps, not "remove GPL stuff"
    • Current — knows the 2023–2025 source-available relicensing wave and pins findings to the version in your lock file
    • Agent-agnostic — Claude Code, Cursor, Codex CLI, Copilot, Gemini CLI

    Limitations

    Analyzes declared licenses statically. Not legal advice — license interpretation is fact-specific. Doesn't scan for security CVEs (use an SCA tool for that), doesn't auto-generate NOTICE files, and doesn't verify that a declared license matches the actual code.

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 3 months ago

    Listed3 months ago

    Frequently Asked Questions