Skip to main content

license-sentinel

Audit Python and npm dependency licenses for compliance before you ship — an MCP server for AI coding agents.

An AI agent can add pdf-renderer to your project in one second. It will not tell you that pdf-renderer is AGPL-3.0 and that shipping it inside a closed-source product is a license violation. License data and compatibility rules are things a model cannot reliably recall — packages relicense between versions (MongoDB → SSPL, Redis → BUSL, Elasticsearch → Elastic-2.0), and "the source is on GitHub" does not mean "free to ship".

license-sentinel reads what is actually on your disk and judges it against how you distribute your product.

  • Works for Python and npm in one pass — existing MCP license tools are npm-only.
  • Runs locally over stdio. No network calls, no telemetry, nothing leaves your machine.
  • Verdicts, not raw data: CLEAN / REVIEW / BLOCK, each with the reason in plain language.

Tools

Tool What it does
audit_project(path, context) Scan a project's dependencies and return counts plus every BLOCKING and REVIEW item with reasons.
check_package(names, context) Check specific packages or messy license strings before installing. Accepts AGPL-3.0, BUSL-1.1, GPLv3, Apache License 2.0, MIT OR Apache-2.0.
generate_notices(path, output) Write a THIRD-PARTY-NOTICES.md attribution document for client hand-off.

There is also a pre_release_license_review prompt that chains the audit into a go/no-go review.

Install

# run without installing (recommended)
uvx --from license-sentinel license-sentinel

# or install
uv pip install license-sentinel
# or
pip install license-sentinel

Configure your client

Claude Desktop / Cursor / Windsurf / VS Code Copilot / Zed all read the same shape:

{
  "mcpServers": {
    "license-sentinel": {
      "command": "uvx",
      "args": ["--from", "license-sentinel", "license-sentinel"]
    }
  }
}

If you installed with pip instead, use "command": "license-sentinel" with no args. Restart the client and the three tools appear.

Distribution context

The same dependency is fine in one context and fatal in another, so every tool takes a context argument:

Context Meaning What it blocks
proprietary (default) Closed-source product you distribute GPL/AGPL/SSPL, BUSL/Elastic, non-commercial
saas-backend Never distributed, only runs on your servers AGPL/SSPL (network trigger), BUSL/Elastic
permissive Your own project is MIT/Apache/BSD Anything copyleft that would contaminate your terms
copyleft-ok Your own project is GPL family Only source-available and non-commercial

What it reads

  • Python: .venv/ / venv/ / env/ installed packages (dist-info/METADATA), requirements.txt, pyproject.toml (PEP 621, poetry, dependency-groups)
  • npm: node_modules/*/package.json (including scoped packages), package.json dependencies

If a dependency is declared but not installed, it is reported with an UNKNOWN license rather than silently dropped — an unlicensed dependency is all-rights-reserved by default.

Privacy

No HTTP client is imported anywhere in this package. The scan is read-only (except generate_notices, which writes the file you name). Nothing is uploaded.

Limitations

  • Not legal advice. It is a fast first pass that catches the expensive mistakes; have counsel review anything flagged.
  • Transitive dependencies are read from what is installed. If you have no .venv and no node_modules, declared-only dependencies come back UNKNOWN.
  • The current environment running the server is never scanned, so the server's own packages never pollute your report. Set LICENSE_SENTINEL_SCAN_CURRENT_ENV=1 to change that.

Development

uv sync
python tests/smoke_test.py     # 9 tests, no pytest needed
python tests/e2e_check.py      # calls the tools end to end

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

license_sentinel-0.1.0.tar.gz (17.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

license_sentinel-0.1.0-py3-none-any.whl (21.1 kB view details)

Uploaded Python 3

File details

Details for the file license_sentinel-0.1.0.tar.gz.

File metadata

  • Download URL: license_sentinel-0.1.0.tar.gz
  • Upload date:
  • Size: 17.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for license_sentinel-0.1.0.tar.gz
Algorithm Hash digest
SHA256 e5eccdbe480597a634a6b0a0e48b45f0ac94f2a4bd55e7a5c71a1b0ee0bc80e8
MD5 c73a384db8dc48732781437381c215ca
BLAKE2b-256 4c849f9199d4ed22a4d4ffaeb49e4ae70e2a39aadbdb5d003fd891055bacfcc0

See more details on using hashes here.

File details

Details for the file license_sentinel-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for license_sentinel-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 0a3f82897cdc8bf3afbe089346cdb87d25f4071ebfa8ce5fe0ee4f7f9b82d063
MD5 36071a7b286b0e95608e554853897687
BLAKE2b-256 529c6e86a7a0dd76a909304012181cafbb23df1fa639809949b431a74b3d5427

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page