Agents / Skills

Dependency Licence Check

Skill

Audits the licences across your dependency tree — including the transitive ones nobody chose on purpose — flags the obligations and conflicts that matter for how YOU ship, and leaves a policy so the next addition is checked at the door.

Best for

  • Due diligence, enterprise deals and the questionnaire that asks about licences
  • Products shipping binaries or embedding code, where copyleft terms bite differently
  • Replacing 'probably all fine' with a documented answer

What you give it

  • Your lockfiles and how you ship (service, distributed binary, embedded, SDK)

What you get back

  • The inventory: every dependency's licence, direct and transitive, with the unknowns flagged for resolution
  • Findings against YOUR shipping model: what obliges what, where conflicts live, ranked by real consequence
  • The going-forward policy: allowed, review-required and refused licence classes, wired as a pipeline check

How it works

  1. Scans the full tree from lockfiles — transitive dependencies carry licences too, and they arrived uninvited.
  2. Evaluates against your actual shipping model: a server-side service, a distributed binary and an embedded SDK have different obligations from the same licence.
  3. Separates real obligations (attribution bundles, source offers, notice files) from folklore, and prices the options where conflicts exist.
  4. Encodes the policy as a pipeline check so the audit does not rot: new licences outside the allowed set fail loudly at addition time.

Example

You: The acquirer's due diligence asks for our licence position. We have never looked.

Result: The audit of 1,241 packages (62 direct): mostly permissive, obligations documented (the attribution bundle your distributed app was supposed to ship — now generated at build); two real findings — a copyleft-licensed library statically linked into the shipped binary (options priced: the maintained permissive alternative was a half-day swap) and one package with NO licence at all (author contacted; replaced meanwhile, since no licence means no permission). The policy now gates additions in CI; due diligence got a documented yes.

Limits — please read

  • It identifies issues and options by licence class; for genuine legal edge cases it says 'this one needs a lawyer' — specifically, not generally.
  • Licence detection from package metadata has gaps (the no-licence, the custom text); those are flagged for human resolution, never guessed.
  • Dual-licensed and 'source-available' packages need business decisions; it frames them with the facts.