Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Code License Position

ASecurity

Check a vendor's licence FAQ and discussion threads before calling a LICENSE restriction a blocker. Use when a model or dependency licence seems to forbid use.

59 stars
0 votes
0 copies
0 views
Added 9/29/2026
developmentgobashgitapi

Works with

api

Security Analysis

A96/100
mediumUses curl or wget to download content

Pro shows the line behind each finding and how to fix it

Scanned 9/29/2026

$npx -y skills add laurigates/claude-plugins --skill code-license-position --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code License Position?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Code License Position
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/laurigates-code-license-position/badge)](https://www.skillsdirectory.com/skills/laurigates-code-license-position)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: code-license-position
description: Check a vendor's licence FAQ and discussion threads before calling a LICENSE restriction a blocker. Use when a model or dependency licence seems to forbid use.
allowed-tools: Bash, Read, WebFetch, Grep, TodoWrite
created: 2026-09-29
modified: 2026-09-29
reviewed: 2026-09-29
---

# Verify the Licensing *Position*, Not Just the LICENSE File

## When to Use This Skill

| Use this skill when... | Use something else when... |
|---|---|
| A `LICENSE` for an open-weights model or source-available dependency seems to forbid your use (territory, entity, field-of-use carve-out) | Auditing a whole dependency tree for licence compatibility — use `code-quality-plugin:code-dep-audit` |
| A licence conclusion is about to land in a public issue, PR, or doc | Deciding whether to contribute upstream at all — use `git-plugin:git-issue-scoping` |

A `LICENSE` reads complete and authoritative, so a restriction found in it gets
reported as settled fact. But for source-available models and dependencies the
vendor's *actual* position routinely lives in two other places **in the same
repo**: a licence FAQ, and the discussion tab. Read the licence, then go find
those, before telling anyone a licence blocks the work.

> Canonical break (2026-08, `MiniMaxAI/MiniMax-H3`): `LICENSE` §I.5 excludes the
> EU, UK, South Korea and USA from the "Applicable Territory", and §V.4 bars use
> — even distribution of *Outputs* — outside it. That was reported as a hard
> blocker in a public issue. The same repo's `docs/QA-about-License.md` frames
> the carve-out as regulatory caution, *"not yet, not ever"*, and links an
> application form; a maintainer in HF discussion #12 wrote **"apply will auto
> get access"** and told individuals to put `Personal/None` in the mandatory
> Company Name field. The blocker was a form. Corrected twice, publicly.

## Execution

1. **List the repo's own licence docs** alongside `LICENSE`:

   ```
   curl -s https://huggingface.co/api/models/<owner>/<repo> | jq -r '.siblings[].rfilename' | grep -iE 'licen|faq|qa|terms'
   ```

   GitHub analogue: `gh api repos/<owner>/<repo>/contents` for a licence FAQ.

2. **Read the discussion threads** that mention the licence:

   ```
   curl -s https://huggingface.co/api/models/<owner>/<repo>/discussions/<n> | jq -r '.events[] | select(.type=="comment") | "=== \(.author.name)\n\(.data.latest.raw)\n"'
   ```

   GitHub analogue: the issue and Discussions tabs.

3. **Establish who speaks for the vendor.** HuggingFace's `isOwner` is **not**
   the authority test — it reads `false` for every human commenter, staff
   included. Check **commit authorship**; write access, especially authorship
   of the licence or FAQ commit itself, is the signal:

   ```
   curl -s https://huggingface.co/api/models/<owner>/<repo>/commits/main | jq -r '.[] | "\(.date)\t\(.authors[]?.user // "?")\t\(.title)"'
   ```

   GitHub analogue: `author_association` (`MEMBER` / `OWNER`) — not a field on
   `gh pr view --json`; read it from `gh api`.

4. **Act on the written grant, not the forum reply.** In the canonical case the
   informal replies were **looser than the documents they explained**: the QA
   doc said MiniMax *"may authorize"* after review, the maintainer said *"auto
   get access"*, and one reply ("you don't need apply" to distribute Outputs
   into excluded regions) contradicts §V.4 on its face. A reply is evidence a
   path exists, not the path. Report the divergence rather than silently
   adopting the permissive reading.

5. **Report the position**, not just the clause: licence text, FAQ framing,
   application path (if any), who said what with their authority, and where
   they diverge.

## When it bites

- Evaluating an open-weights model or source-available dependency as a project
  target — exactly where a "we can't use this" verdict gates real work.
- **Geography or entity carve-outs specifically.** These are usually regulatory
  caution with an application path attached (AI Act, pending litigation), not
  prohibition. Treat "Excluded Territories" as "ask", not "no".
- Any licence conclusion about to be written into a public artifact. The
  correction is public too.

Do not design around the restriction (jurisdiction shopping, hosting in a
non-excluded region) before checking whether the vendor simply grants
exceptions. The workaround is usually more effort *and* more risk than the form.

Attribution

laurigateslaurigates
View sourceSee grades on GitHubMore from laurigates →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

286712 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Writing Plans

Use when you have a spec or requirements for a multi-step task, before touching code

2927051 votes
View all in development →