# Open source license check (/legal--oss-license-check)

/legal--oss-license-check is a Claude Code skill in the Business section. Scans your dependency tree for incompatible licenses, copyleft risk and unmet attribution obligations.

- Web version: https://skills.sgomez.dev/en/s/legal--oss-license-check
- Section: [Business](https://skills.sgomez.dev/en/business.md)
- Author: Santiago Gómez de la Torre
- License: MIT
- Source: https://github.com/sgomez-dev/claude-skills/blob/main/skills/legal/oss-license-check.md
- Updated 10 Jul 2026

## Use it when

- You are shipping a product and want to know if a dependency forces you to open your code
- A customer asks for assurances about open source licenses
- You need a NOTICE file with the required attributions

## Not for

- Replacing the advice of a lawyer
- Final verdicts: unclear cases are marked [COUNSEL]

## What you get

A Markdown report in legal/ with a license summary table, findings by severity and fix options, plus a NOTICE file if attributions are missing.

## How to ask for it

- `/legal--oss-license-check check the licenses of my npm dependencies`
- `/legal--oss-license-check tell me if I have any copyleft risk in this project`
- `/legal--oss-license-check check license compatibility before I ship`

## Install

macOS · Linux:

```
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash
```

Windows:

```
irm https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.ps1 | iex
```

Claude Code plugin:

```
/plugin marketplace add sgomez-dev/claude-skills
/plugin install legal-skills@claude-skills-collection
```

## Permissions

- Reads: `**/*`
- Writes: `legal/**`, `LICENSE_REPORT*.md`, `NOTICE*`
- Runs: `npm ls*`, `npx license-checker*`, `yarn licenses*`, `pnpm licenses*`, `pip-licenses*`, `pip show*`, `cargo license*`, `cargo metadata*`, `go-licenses*`, `composer licenses*`, `mvn license:*`, `gradle*licenseReport*`, `dotnet list*`
- Network: No
- Destructive: No

## Author's description

Scan dependencies for license compatibility, obligations, and copyleft risk

## Questions about this skill

### Does it include transitive dependencies?

Yes. Copyleft usually arrives that way, and each finding says whether the dependency is direct or transitive.

### Does it matter how I distribute the product?

A lot. SaaS, a shipped binary and an open source project carry different risk, so it asks first. AGPL is treated as critical even for SaaS.

### Can I trust the result?

It reports what package metadata says, which is sometimes wrong. For critical findings, check the LICENSE file shipped in the package.


- [How we review this](https://skills.sgomez.dev/en/methodology.md)
