LicenseGuard

Check if a dependency's license obligates you, based on how you ship. npm, PyPI, Go.

我該用這個嗎

品質與安全性

A
說明品質
90%
結構描述完整度
100%
命名品質
93%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

發現項目(1)

  • LOWTool 'explain_license' description lacks action verb在 explain_license 中

根據工具定義與協定合規性的自動化分析。

上下文成本

~1,775Token(工具定義)
~6.2 KB典型回應大小
中等的注意力影響(128k 上下文的 1.39%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "license-guard": {
      "url": "https://license-guard.rcc-aoki.workers.dev/mcp"
    }
  }
}

遠端端點

https://license-guard.rcc-aoki.workers.dev/mcpstreamable-http

它能做什麼

工具清單

工具(3)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢check_dependency_license(ecosystem, name, version, distribution_model, scope)

Determine whether adding or keeping a single open source dependency creates a legal obligation, given how this project ships. Call this BEFORE adding a new dependency to a project, and when auditing an existing one. A permissive result means no source-disclosure duty; a blocked result means the license obligates you and the dependency should be replaced or the shipping model reconsidered.

輸入結構描述

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "enum": [
        "npm",
        "pypi",
        "go",
        "cargo",
        "rubygems",
        "nuget"
      ],
      "description": "Package registry the dependency comes from."
    },
    "name": {
      "type": "string",
      "description": "Package name as written in the manifest, e.g. \"express\", \"requests\", \"github.com/gin-gonic/gin\", or \"serde\"."
    },
    "version": {
      "type": "string",
      "description": "Exact version if known. Omit to use the latest published version, which may differ from what is installed."
    },
    "distribution_model": {
      "type": "string",
      "enum": [
        "saas",
        "distributed-binary",
        "on-prem-delivery",
        "internal-only",
        "library-published"
      ],
      "description": "How the software incorporating this dependency reaches its users. This determines the answer: \"saas\" = users reach it over a network; \"distributed-binary\" = shipped as an app or binary; \"on-prem-delivery\" = installed in a customer environment; \"internal-only\" = never leaves your organization; \"library-published\" = released for others to depend on."
    },
    "scope": {
      "type": "string",
      "enum": [
        "runtime",
        "dev",
        "build",
        "test",
        "optional"
      ],
      "description": "Where the dependency sits. Use \"dev\", \"build\", or \"test\" for anything that does not end up in the shipped artifact — those carry no distribution obligation. Defaults to \"runtime\"."
    }
  },
  "required": [
    "ecosystem",
    "name",
    "distribution_model"
  ]
}

輸出結構描述

{
  "type": "object",
  "properties": {
    "license": {
      "type": [
        "string",
        "null"
      ]
    },
    "verdict": {
      "type": "string",
      "enum": [
        "allowed",
        "review",
        "blocked"
      ]
    },
    "obligations": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "rationale": {
      "type": "string"
    },
    "assumption": {
      "type": "object",
      "properties": {
        "declared": {
          "type": "string"
        },
        "assumed": {
          "type": "string"
        }
      },
      "required": [
        "declared",
        "assumed"
      ]
    },
    "reference": {
      "type": "string"
    }
  },
  "required": [
    "license",
    "verdict",
    "obligations",
    "rationale"
  ]
}
🟢check_manifest_licenses(content, distribution_model)

Scan an entire dependency manifest and report every dependency whose license creates an obligation for this shipping model. Use when reviewing a project as a whole, preparing for due diligence, or after a large dependency change. Pass a package-lock.json when one exists: problematic licenses usually arrive as transitive dependencies rather than ones you added directly, and only a lockfile reveals those.

輸入結構描述

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "description": "Full text of a lockfile, SBOM, or manifest. Accepted: package-lock.json, pnpm-lock.yaml, yarn.lock, go.sum, Cargo.lock, poetry.lock, uv.lock, Gemfile.lock, packages.lock.json, CycloneDX (JSON), SPDX (JSON), package.json, requirements.txt, go.mod, Cargo.toml, .csproj, Directory.Packages.props, packages.config. The format is detected automatically. Prefer a lockfile: it covers transitive dependencies and carries exact versions. package-lock.json is best of all, since it embeds licenses and needs no registry lookups. An SBOM covers several ecosystems in one document, but its licenses are read from the document rather than looked up, so they are only as current as the document."
    },
    "distribution_model": {
      "type": "string",
      "enum": [
        "saas",
        "distributed-binary",
        "on-prem-delivery",
        "internal-only",
        "library-published"
      ],
      "description": "How the software incorporating this dependency reaches its users. This determines the answer: \"saas\" = users reach it over a network; \"distributed-binary\" = shipped as an app or binary; \"on-prem-delivery\" = installed in a customer environment; \"internal-only\" = never leaves your organization; \"library-published\" = released for others to depend on."
    }
  },
  "required": [
    "content",
    "distribution_model"
  ]
}

輸出結構描述

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string"
    },
    "distributionModel": {
      "type": "string"
    },
    "summary": {
      "type": "object",
      "description": "Counts by verdict. total is every dependency found, not only the ones that were resolved.",
      "properties": {
        "total": {
          "type": "number"
        },
        "allowed": {
          "type": "number"
        },
        "review": {
          "type": "number"
        },
        "blocked": {
          "type": "number"
        }
      },
      "required": [
        "total",
        "allowed",
        "review",
        "blocked"
      ]
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "ecosystem": {
            "type": "string"
          },
          "name": {
            "type": "string"
          },
          "version": {
            "type": [
              "string",
              "null"
            ]
          },
          "scope": {
            "type": "string",
            "enum": [
              "runtime",
              "dev",
              "build",
              "test",
              "optional"
            ]
          },
          "spdxExpression": {
            "type": [
              "string",
              "null"
            ]
          },
          "resolvedFrom": {
            "type": "string",
            "description": "Where the license came from. \"lockfile\" is exact; \"sbom\" means it was written in the SBOM you pasted rather than looked up, so it is only as current as that document; \"registry\" and \"deps-dev\" are the pinned version as published; \"registry-latest\" means the pinned version could not be read and the latest release was used instead; \"not-checked\" means the lookup budget ran out and this dependency was never resolved; \"not-published\" means it is a git dependency, a member of the scanned workspace, or from a private registry, so no public registry has license data for it — re-scanning will not resolve those."
          },
          "verdict": {
            "type": "string",
            "enum": [
              "allowed",
              "review",
              "blocked"
            ]
          },
          "obligations": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "rationale": {
            "type": "string"
          }
        },
        "required": [
          "ecosystem",
          "name",
          "scope",
          "verdict",
          "obligations",
          "rationale"
        ]
      }
    },
    "limitations": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "What this scan could not establish. Never empty when anything was left unresolved. Read it before treating a result as clean."
    }
  },
  "required": [
    "summary",
    "findings",
    "limitations"
  ]
}
🟢explain_license(license, linkage)

Given an SPDX license identifier or expression, explain what it requires across every shipping model at once. Use when the question is about the license itself rather than a specific package — for example when comparing AGPL-3.0 against GPL-3.0 for a hosted service, or deciding what a project may safely depend on.

輸入結構描述

{
  "type": "object",
  "properties": {
    "license": {
      "type": "string",
      "description": "SPDX identifier or expression, e.g. \"AGPL-3.0-only\", \"Apache-2.0\", or \"(MIT OR GPL-2.0-only)\"."
    },
    "linkage": {
      "type": "string",
      "enum": [
        "dynamic",
        "static",
        "separate-process"
      ],
      "description": "How the dependency is linked. Matters for LGPL-family licenses. Compiled languages such as Go and Rust normally link statically. Defaults to \"dynamic\"."
    }
  },
  "required": [
    "license"
  ]
}

輸出結構描述

{
  "type": "object",
  "properties": {
    "license": {
      "type": "string"
    },
    "linkage": {
      "type": "string"
    },
    "byDistributionModel": {
      "type": "array",
      "description": "One row per way of shipping. This is where the same license diverges.",
      "items": {
        "type": "object",
        "properties": {
          "model": {
            "type": "string",
            "enum": [
              "saas",
              "distributed-binary",
              "on-prem-delivery",
              "internal-only",
              "library-published"
            ]
          },
          "verdict": {
            "type": "string",
            "enum": [
              "allowed",
              "review",
              "blocked"
            ]
          },
          "obligations": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "rationale": {
            "type": "string"
          }
        },
        "required": [
          "model",
          "verdict",
          "obligations",
          "rationale"
        ]
      }
    },
    "devScope": {
      "type": "object",
      "description": "The result when the dependency never reaches users (dev, build or test scope). Independent of the shipping model.",
      "properties": {
        "verdict": {
          "type": "string",
          "enum": [
            "allowed",
            "review",
            "blocked"
          ]
        },
        "rationale": {
          "type": "string"
        }
      },
      "required": [
        "verdict",
        "rationale"
      ]
    }
  },
  "required": [
    "license",
    "byDistributionModel",
    "devScope"
  ]
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本3 個工具
已驗證未記錄版本3 個工具
已驗證未記錄版本3 個工具