dependency-license-auditScan project dependencies for license compatibility issues, GPL contamination, and compliance violations. Supports npm, pip, Go, Rust, and Ruby ecosystems. U...
Install via ClawdBot CLI:
clawdbot install charlie-morrison/dependency-license-auditGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Aug 9, 2026
Before shipping a new software release, run a comprehensive license audit to ensure all dependencies comply with the project's licensing policy. The audit identifies GPL contamination risks, flags unknown licenses, and generates a markdown report for the release notes.
Integrate the license audit into the CI/CD pipeline with the --ci flag to automatically block builds that introduce policy violations or critical warnings. Exit codes 0, 1, or 2 enable automated checks gatekeeping the release process.
When evaluating a new third-party library for incorporation into an existing codebase, the developer runs a targeted audit on the library's dependencies. This ensures the library's licensing is compatible with the project's policy before adoption.
A large enterprise with strict open-source compliance policies uses the audit tool to scan multiple repositories. The custom policy feature allows them to define precise license allowlists and classify dependencies accordingly.
Maintainers of an open-source project use the 'any-open' policy to verify all dependencies are OSI-approved. The markdown output helps them document licensing in the project's README and contribute guidelines.
Offer a free, open-source version of the license audit CLI for individual developers. A premium version includes advanced features like custom policy management, automated reports, and priority support.
Provide the audit as a hosted service where companies submit their repositories and receive compliance reports, alerts, and integration with their CI pipelines. This reduces the burden on internal teams.
Integrate the audit tool into a broader software asset management platform that tracks licenses across an organization. The platform offers dashboards, policy enforcement, and risk scoring for enterprise clients.
💬 Integration Tip
Start by running the audit without the --ci flag to understand the current license status. Then define a custom policy file to match your organization's licensing requirements before integrating into CI.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...