Skip to content
Back to skills

License Compliance

ASecurity

Inventory dependency licenses, normalize to SPDX identifiers, and flag licenses outside an allowlist (e.g. GPL/AGPL copyleft in proprietary code). Use when checking open-source license obligations or building a license inventory.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentsexpress

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add matthews-wong/claude-code-plugins --skill license-compliance --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of License Compliance?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for License Compliance
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/matthews-wong-license-compliance/badge)](https://www.skillsdirectory.com/skills/matthews-wong-license-compliance)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: license-compliance
description: Inventory dependency licenses, normalize to SPDX identifiers, and flag licenses outside an allowlist (e.g. GPL/AGPL copyleft in proprietary code). Use when checking open-source license obligations or building a license inventory.
---

# License compliance

Build a dependency license inventory, express licenses as SPDX identifiers, and flag ones that conflict with the project's licensing policy. This supports a compliance decision — it is not legal advice.

## Workflow

1. Inventory licenses with a real per-ecosystem tool (see `reference/tools.md`).
2. Normalize each to an SPDX identifier; mark truly unknown ones `UNKNOWN` (never guess).
3. Classify by obligation family (permissive / weak copyleft / strong copyleft / network copyleft / proprietary / unknown).
4. Compare against the allowlist/denylist policy.
5. Flag conflicts with options and required sign-offs.

## SPDX in one line

SPDX (Software Package Data Exchange) is an ISO/IEC 5962 standard; **SPDX license identifiers** are short, unambiguous strings — `MIT`, `Apache-2.0`, `GPL-3.0-only`, `AGPL-3.0-or-later` — that name a license precisely and can be combined with expressions like `(MIT OR Apache-2.0)`. See `reference/spdx.md`.

## Obligation families (why licenses get flagged)

- **Permissive** (MIT, BSD-2/3, Apache-2.0, ISC): usually allowlisted; Apache-2.0 adds a patent grant + NOTICE handling.
- **Weak copyleft** (LGPL, MPL-2.0, EPL): file/library-level reciprocity; often allowed with dynamic linking care.
- **Strong copyleft** (GPL-2.0, GPL-3.0): distributing a combined work can require releasing your source under the GPL — high risk in proprietary distributed software.
- **Network copyleft** (AGPL-3.0): the copyleft trigger extends to network/SaaS use — high risk for hosted services even without distributing binaries.
- **Unknown / missing / custom**: treat as blocking until resolved.

Full policy model and default allowlist in `reference/policy.md`.

## Honesty rules

- Report the actually declared license; if metadata and LICENSE file disagree, flag it and prefer verifying the source text for high-risk items.
- Do not render legal conclusions; recommend counsel for genuine legal questions.

## References (load on demand)

- `reference/spdx.md` — SPDX identifiers and expression syntax.
- `reference/tools.md` — per-ecosystem license inventory tools.
- `reference/policy.md` — allowlist/denylist model and a default policy.

Files in this skill

  • SKILL.md2.4 KB
  • reference/policy.md2.5 KB
  • reference/spdx.md1.7 KB
  • reference/tools.md1.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…