Skip to content
Back to skills

Code License Position

ASecurity

Check a vendor's licence FAQ and discussion threads before calling a LICENSE restriction a blocker. Use when a model or dependency licence seems to forbid use.

  • 59 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
developmentgobashgitapi

Works with

  • api

Security analysis

A96/100
  • mediumUses curl or wget to download content

Pro shows the line behind each finding and how to fix it

Scanned September 29, 2026

npx -y skills add laurigates/claude-plugins --skill code-license-position --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code License Position?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code License Position
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/laurigates-code-license-position/badge)](https://www.skillsdirectory.com/skills/laurigates-code-license-position)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-license-position
description: Check a vendor's licence FAQ and discussion threads before calling a LICENSE restriction a blocker. Use when a model or dependency licence seems to forbid use.
allowed-tools: Bash, Read, WebFetch, Grep, TodoWrite
created: 2026-09-29
modified: 2026-09-29
reviewed: 2026-09-29
---

# Verify the Licensing *Position*, Not Just the LICENSE File

## When to Use This Skill

| Use this skill when... | Use something else when... |
|---|---|
| A `LICENSE` for an open-weights model or source-available dependency seems to forbid your use (territory, entity, field-of-use carve-out) | Auditing a whole dependency tree for licence compatibility — use `code-quality-plugin:code-dep-audit` |
| A licence conclusion is about to land in a public issue, PR, or doc | Deciding whether to contribute upstream at all — use `git-plugin:git-issue-scoping` |

A `LICENSE` reads complete and authoritative, so a restriction found in it gets
reported as settled fact. But for source-available models and dependencies the
vendor's *actual* position routinely lives in two other places **in the same
repo**: a licence FAQ, and the discussion tab. Read the licence, then go find
those, before telling anyone a licence blocks the work.

> Canonical break (2026-08, `MiniMaxAI/MiniMax-H3`): `LICENSE` §I.5 excludes the
> EU, UK, South Korea and USA from the "Applicable Territory", and §V.4 bars use
> — even distribution of *Outputs* — outside it. That was reported as a hard
> blocker in a public issue. The same repo's `docs/QA-about-License.md` frames
> the carve-out as regulatory caution, *"not yet, not ever"*, and links an
> application form; a maintainer in HF discussion #12 wrote **"apply will auto
> get access"** and told individuals to put `Personal/None` in the mandatory
> Company Name field. The blocker was a form. Corrected twice, publicly.

## Execution

1. **List the repo's own licence docs** alongside `LICENSE`:

   ```
   curl -s https://huggingface.co/api/models/<owner>/<repo> | jq -r '.siblings[].rfilename' | grep -iE 'licen|faq|qa|terms'
   ```

   GitHub analogue: `gh api repos/<owner>/<repo>/contents` for a licence FAQ.

2. **Read the discussion threads** that mention the licence:

   ```
   curl -s https://huggingface.co/api/models/<owner>/<repo>/discussions/<n> | jq -r '.events[] | select(.type=="comment") | "=== \(.author.name)\n\(.data.latest.raw)\n"'
   ```

   GitHub analogue: the issue and Discussions tabs.

3. **Establish who speaks for the vendor.** HuggingFace's `isOwner` is **not**
   the authority test — it reads `false` for every human commenter, staff
   included. Check **commit authorship**; write access, especially authorship
   of the licence or FAQ commit itself, is the signal:

   ```
   curl -s https://huggingface.co/api/models/<owner>/<repo>/commits/main | jq -r '.[] | "\(.date)\t\(.authors[]?.user // "?")\t\(.title)"'
   ```

   GitHub analogue: `author_association` (`MEMBER` / `OWNER`) — not a field on
   `gh pr view --json`; read it from `gh api`.

4. **Act on the written grant, not the forum reply.** In the canonical case the
   informal replies were **looser than the documents they explained**: the QA
   doc said MiniMax *"may authorize"* after review, the maintainer said *"auto
   get access"*, and one reply ("you don't need apply" to distribute Outputs
   into excluded regions) contradicts §V.4 on its face. A reply is evidence a
   path exists, not the path. Report the divergence rather than silently
   adopting the permissive reading.

5. **Report the position**, not just the clause: licence text, FAQ framing,
   application path (if any), who said what with their authority, and where
   they diverge.

## When it bites

- Evaluating an open-weights model or source-available dependency as a project
  target — exactly where a "we can't use this" verdict gates real work.
- **Geography or entity carve-outs specifically.** These are usually regulatory
  caution with an application path attached (AI Act, pending litigation), not
  prohibition. Treat "Excluded Territories" as "ask", not "no".
- Any licence conclusion about to be written into a public artifact. The
  correction is public too.

Do not design around the restriction (jurisdiction shopping, hosting in a
non-excluded region) before checking whether the vendor simply grants
exceptions. The workaround is usually more effort *and* more risk than the form.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…