Back to Browse

License Compliance MCP Server

SecurityLow Risk8.3Local
Free

Scan npm dependencies for license compliance issues. Catch GPL contamination.

About

Scan npm dependencies for license compliance issues. Catch GPL contamination.

Security Report

8.3
Low Risk8.3Low Risk

Valid MCP server (2 strong, 1 medium validity signals). 1 known CVE in dependencies (1 critical, 0 high severity) Package registry verified. Imported from the Official MCP Registry. Trust signals: trusted author (5/5 approved).

5 files analyzed · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-bighippoman-license-compliance": {
      "args": [
        "-y",
        "license-compliance-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

license-compliance-mcp

MCP server that scans npm project dependencies for license compliance issues. Catch GPL contamination before code ships.

Tools

check-licenses

Scan a project's npm dependencies against a license policy and get a detailed compliance report.

Parameters:

  • path (required) — Absolute path to the project root
  • policy (optional, default: "permissive") — Policy preset or custom SPDX expression
    • "permissive" — Only MIT, ISC, BSD, Apache-2.0, etc.
    • "weak-copyleft" — Adds LGPL, MPL-2.0, EPL-2.0
    • "copyleft" — Adds GPL, AGPL
    • Custom: "(MIT OR Apache-2.0)" — Any valid SPDX expression

explain-license

Get a plain-language explanation of any SPDX license — permissions, conditions, limitations, compatibility, and gotchas.

Parameters:

  • license (required) — SPDX identifier (e.g., "MIT", "GPL-3.0-only", "Apache-2.0")

Install

Claude Code

claude mcp add license-compliance -- npx -y license-compliance-mcp

Claude Desktop / Cursor

Add to your config (claude_desktop_config.json or .cursor/mcp.json):

{
  "mcpServers": {
    "license-compliance": {
      "command": "npx",
      "args": ["-y", "license-compliance-mcp"]
    }
  }
}

How It Works

  1. Scans node_modules using license-checker-rseidelsohn
  2. Normalizes license strings to valid SPDX using spdx-correct
  3. Evaluates each package against the policy using spdx-satisfies
  4. Traces dependency chains to show how problematic packages entered the project
  5. Generates a markdown report grouped by severity (critical > warning > info)

Requirements

  • Node.js >= 18
  • Project must have node_modules installed (npm install)

Reviews

No reviews yet

Be the first to review this server!

License Compliance MCP Server - Scan npm dependencies for license compliance issues. Catch | MCP Marketplace