Gives Claude a single tool to scan package.json files for license compliance issues. Point it at your dependencies and it fetches license metadata from the npm registry, flags GPL or AGPL packages that conflict with permissive project licenses, and returns a structured report with risk levels. Useful when you need to catch copyleft contamination before shipping proprietary code or want a quick audit of what licenses you're actually bundling. Caps analysis at 20 dependencies for speed. Only works with npm packages, so Python or Rust projects are out of scope. Private packages show up as unknown since the registry won't have their license data.
MCP server that audits your project's dependency licenses for compatibility issues. Flags GPL/AGPL conflicts and generates compliance reports.
package.json file (dependencies + devDependencies)npm install -g mcp-license-audit
# or run directly:
npx mcp-license-audit
Add to your .claude/mcp.json or ~/.claude/mcp.json:
{
"mcpServers": {
"license-audit": {
"command": "npx",
"args": ["mcp-license-audit"]
}
}
}
Or if installed globally:
{
"mcpServers": {
"license-audit": {
"command": "mcp-license-audit"
}
}
}
audit-licensesInput: packageJson — the full contents of a package.json file as a string.
Output: JSON report:
{
"totalDependencies": 15,
"analyzed": 15,
"licenses": {
"MIT": ["express", "lodash"],
"Apache-2.0": ["typescript"],
"GPL-3.0": ["some-package"],
"unknown": ["private-pkg"]
},
"conflicts": [
{
"package": "some-package",
"license": "GPL-3.0",
"issue": "GPL dependency in MIT project — must open-source your code if distributed"
}
],
"riskLevel": "medium",
"summary": "15 deps analyzed. 1 GPL conflict found. 1 unknown license."
}
Risk levels: low (no copyleft), medium (weak copyleft or many unknowns), high (GPL/AGPL found).
npm install
npm run build
node dist/index.js