Back to skills
SKILL.md
License Compliance Checker
ASecurityAutomated license compliance verification for dependencies to ensure legal compliance during migration
- 1,760 stars
- 0 votes
- 0 copies
- 1 view
- Added September 2, 2026
Works with
Security analysis
100/100Pro scans all 2 files and shows the line behind each finding
npx -y skills add a5c-ai/babysitter --skill license-compliance-checker --agent claude-codeAre you the author of License Compliance Checker?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/a5c-ai-license-compliance-checker-babysitter)---
name: license-compliance-checker
description: Automated license compliance verification for dependencies to ensure legal compliance during migration
allowed-tools: ["Bash", "Read", "Write", "Grep", "Glob", "Edit"]
graph:
domains: [domain:software-engineering]
specializations: [specialization:code-migration-modernization]
skillAreas: [skill-area:compliance-automation, skill-area:supply-chain-security]
roles: [role:compliance-engineer, role:license-auditor]
workflows: [workflow:technical-debt-reduction]
topics: [topic:refactoring]
---
# License Compliance Checker Skill
Automated verification of license compliance across all project dependencies to ensure legal compliance during migration activities.
## Purpose
Enable comprehensive license compliance checking for:
- Dependency license identification
- Compatibility verification
- Copyleft license flagging
- Attribution requirement tracking
- Policy enforcement
## Capabilities
### 1. License Identification
- Extract licenses from dependencies
- Parse SPDX identifiers
- Detect custom licenses
- Handle multi-license packages
### 2. Compatibility Checking
- Verify license compatibility
- Check against project license
- Identify conflicting licenses
- Map dependency license chains
### 3. Copyleft License Flagging
- Detect GPL/AGPL licenses
- Identify viral clauses
- Flag distribution implications
- Alert on copyleft in proprietary projects
### 4. Attribution Requirement Tracking
- Collect NOTICE requirements
- Track attribution obligations
- Generate attribution documents
- Monitor compliance completeness
### 5. Policy Enforcement
- Define allowed/blocked licenses
- Enforce organizational policies
- Generate compliance reports
- Track policy violations
### 6. Compliance Report Generation
- Create audit-ready reports
- Generate SBOM with licenses
- Produce attribution files
- Export compliance evidence
## Tool Integrations
| Tool | Purpose | Integration Method |
|------|---------|-------------------|
| FOSSA | Full compliance platform | API |
| WhiteSource | License scanning | API |
| Black Duck | Comprehensive analysis | API |
| license-checker | npm license checking | CLI |
| licensee | License detection | CLI |
| go-licenses | Go license checking | CLI |
| pip-licenses | Python license checking | CLI |
## Output Schema
```json
{
"analysisId": "string",
"timestamp": "ISO8601",
"projectLicense": "string",
"dependencies": [
{
"name": "string",
"version": "string",
"license": "string",
"spdxId": "string",
"compatible": "boolean",
"attributionRequired": "boolean",
"riskLevel": "high|medium|low|none"
}
],
"compliance": {
"status": "compliant|non-compliant|review-required",
"violations": [],
"warnings": [],
"attributionNeeded": []
},
"sbom": {
"format": "SPDX|CycloneDX",
"path": "string"
}
}
```
## Integration with Migration Processes
- **dependency-analysis-updates**: License verification
- **legacy-codebase-assessment**: Compliance assessment
## Related Skills
- `dependency-scanner`: Dependency discovery
- `vulnerability-scanner`: Security + compliance
## Related Agents
- `dependency-modernization-agent`: License-safe updates
- `compliance-migration-agent`: Full compliance
Files in this skill
- README.md
- SKILL.md
Attribution
Comments
Loading comments…