License Compliance Checker Skill

SkillDev tools

Automated license compliance verification for dependencies to ensure legal compliance during migration

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the License Compliance Checker Skill skill

What this skill tells your AI

The instructions your AI receives, as published by a5c-ai/babysitter in library/specializations/code-migration-modernization/skills/license-compliance-checker/SKILL.md and read by ahel’s review.

Automated verification of license compliance across all project dependencies to ensure legal compliance during migration activities.

Purpose

Enable comprehensive license compliance checking for:

  • Dependency license identification
  • Compatibility verification
  • Copyleft license flagging
  • Attribution requirement tracking
  • Policy enforcement

Capabilities

1. License Identification

  • Extract licenses from dependencies
  • Parse SPDX identifiers
  • Detect custom licenses
  • Handle multi-license packages

2. Compatibility Checking

  • Verify license compatibility
  • Check against project license
  • Identify conflicting licenses
  • Map dependency license chains

3. Copyleft License Flagging

  • Detect GPL/AGPL licenses
  • Identify viral clauses
  • Flag distribution implications
  • Alert on copyleft in proprietary projects

4. Attribution Requirement Tracking

  • Collect NOTICE requirements
  • Track attribution obligations
  • Generate attribution documents
  • Monitor compliance completeness

5. Policy Enforcement

  • Define allowed/blocked licenses
  • Enforce organizational policies
  • Generate compliance reports
  • Track policy violations

6. Compliance Report Generation

  • Create audit-ready reports
  • Generate SBOM with licenses
  • Produce attribution files
  • Export compliance evidence

Tool Integrations

ToolPurposeIntegration Method
FOSSAFull compliance platformAPI
WhiteSourceLicense scanningAPI
Black DuckComprehensive analysisAPI
license-checkernpm license checkingCLI
licenseeLicense detectionCLI
go-licensesGo license checkingCLI
pip-licensesPython license checkingCLI

Output Schema

{
  "analysisId": "string",
  "timestamp": "ISO8601",
  "projectLicense": "string",
  "dependencies": [
    {
      "name": "string",
      "version": "string",
      "license": "string",
      "spdxId": "string",
      "compatible": "boolean",
      "attributionRequired": "boolean",
      "riskLevel": "high|medium|low|none"
    }
  ],
  "compliance": {
    "status": "compliant|non-compliant|review-required",
    "violations": [],
    "warnings": [],
    "attributionNeeded": []
  },
  "sbom": {
    "format": "SPDX|CycloneDX",
    "path": "string"
  }
}

Integration with Migration Processes

  • dependency-analysis-updates: License verification
  • legacy-codebase-assessment: Compliance assessment

Related Skills

  • dependency-scanner: Dependency discovery
  • vulnerability-scanner: Security + compliance

Related Agents

  • dependency-modernization-agent: License-safe updates
  • compliance-migration-agent: Full compliance

Signals

GitHub stars
2k
Forks
112
Last commit
Sep 2026
Advanced
Item type
skill
Key
license-compliance-checker
Source
github.com/a5c-ai/babysitter