LicenseGuard
Qué hace este MCP
Analyzes open-source dependency licenses and identifies obligations for individual packages or complete manifests.
Herramientas
Esquema de entrada
{'type': 'object', 'required': ['ecosystem', 'name', 'distribution_model'], 'properties': {'name': {'type': 'string', 'description': 'Package name as written in the manifest, e.g. "express", "requests", "github.com/gin-gonic/gin", or "serde".'}, 'scope': {'enum': ['runtime', 'dev', 'build', 'test', 'optional'], 'type': 'string', 'description': 'Where the dependency sits. Use "dev", "build", or "test" for anything that does not end up in the shipped artifact — those carry no distribution obligation. Defaults to "runtime".'}, 'version': {'type': 'string', 'description': 'Exact version if known. Omit to use the latest published version, which may differ from what is installed.'}, 'ecosystem': {'enum': ['npm', 'pypi', 'go', 'cargo', 'rubygems', 'nuget'], 'type': 'string', 'description': 'Package registry the dependency comes from.'}, 'distribution_model': {'enum': ['saas', 'distributed-binary', 'on-prem-delivery', 'internal-only', 'library-published'], 'type': 'string', 'description': 'How the software incorporating this dependency reaches its users. This determines the answer: "saas" = users reach it over a network; "distributed-binary" = shipped as an app or binary; "on-prem-delivery" = installed in a customer environment; "internal-only" = never leaves your organization; "library-published" = released for others to depend on.'}}}
Esquema de salida
{'type': 'object', 'required': ['license', 'verdict', 'obligations', 'rationale'], 'properties': {'license': {'type': ['string', 'null']}, 'verdict': {'enum': ['allowed', 'review', 'blocked'], 'type': 'string'}, 'rationale': {'type': 'string'}, 'reference': {'type': 'string'}, 'assumption': {'type': 'object', 'required': ['declared', 'assumed'], 'properties': {'assumed': {'type': 'string'}, 'declared': {'type': 'string'}}}, 'obligations': {'type': 'array', 'items': {'type': 'string'}}}}
Esquema de entrada
{'type': 'object', 'required': ['content', 'distribution_model'], 'properties': {'content': {'type': 'string', 'description': 'Full text of a lockfile, SBOM, or manifest. Accepted: package-lock.json, pnpm-lock.yaml, yarn.lock, go.sum, Cargo.lock, poetry.lock, uv.lock, Gemfile.lock, packages.lock.json, CycloneDX (JSON), SPDX (JSON), package.json, requirements.txt, go.mod, Cargo.toml, .csproj, Directory.Packages.props, packages.config. The format is detected automatically. Prefer a lockfile: it covers transitive dependencies and carries exact versions. package-lock.json is best of all, since it embeds licenses and needs no registry lookups. An SBOM covers several ecosystems in one document, but its licenses are read from the document rather than looked up, so they are only as current as the document.'}, 'distribution_model': {'enum': ['saas', 'distributed-binary', 'on-prem-delivery', 'internal-only', 'library-published'], 'type': 'string', 'description': 'How the software incorporating this dependency reaches its users. This determines the answer: "saas" = users reach it over a network; "distributed-binary" = shipped as an app or binary; "on-prem-delivery" = installed in a customer environment; "internal-only" = never leaves your organization; "library-published" = released for others to depend on.'}}}
Esquema de salida
{'type': 'object', 'required': ['summary', 'findings', 'limitations'], 'properties': {'summary': {'type': 'object', 'required': ['total', 'allowed', 'review', 'blocked'], 'properties': {'total': {'type': 'number'}, 'review': {'type': 'number'}, 'allowed': {'type': 'number'}, 'blocked': {'type': 'number'}}, 'description': 'Counts by verdict. total is every dependency found, not only the ones that were resolved.'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['ecosystem', 'name', 'scope', 'verdict', 'obligations', 'rationale'], 'properties': {'name': {'type': 'string'}, 'scope': {'enum': ['runtime', 'dev', 'build', 'test', 'optional'], 'type': 'string'}, 'verdict': {'enum': ['allowed', 'review', 'blocked'], 'type': 'string'}, 'version': {'type': ['string', 'null']}, 'ecosystem': {'type': 'string'}, 'rationale': {'type': 'string'}, 'obligations': {'type': 'array', 'items': {'type': 'string'}}, 'resolvedFrom': {'type': 'string', 'description': 'Where the license came from. "lockfile" is exact; "sbom" means it was written in the SBOM you pasted rather than looked up, so it is only as current as that document; "registry" and "deps-dev" are the pinned version as published; "registry-latest" means the pinned version could not be read and the latest release was used instead; "not-checked" means the lookup budget ran out and this dependency was never resolved; "not-published" means it is a git dependency, a member of the scanned workspace, or from a private registry, so no public registry has license data for it — re-scanning will not resolve those.'}, 'spdxExpression': {'type': ['string', 'null']}}}}, 'ecosystem': {'type': 'string'}, 'limitations': {'type': 'array', 'items': {'type': 'string'}, 'description': 'What this scan could not establish. Never empty when anything was left unresolved. Read it before treating a result as clean.'}, 'distributionModel': {'type': 'string'}}}
Esquema de entrada
{'type': 'object', 'required': ['license'], 'properties': {'license': {'type': 'string', 'description': 'SPDX identifier or expression, e.g. "AGPL-3.0-only", "Apache-2.0", or "(MIT OR GPL-2.0-only)".'}, 'linkage': {'enum': ['dynamic', 'static', 'separate-process'], 'type': 'string', 'description': 'How the dependency is linked. Matters for LGPL-family licenses. Compiled languages such as Go and Rust normally link statically. Defaults to "dynamic".'}}}
Esquema de salida
{'type': 'object', 'required': ['license', 'byDistributionModel', 'devScope'], 'properties': {'license': {'type': 'string'}, 'linkage': {'type': 'string'}, 'devScope': {'type': 'object', 'required': ['verdict', 'rationale'], 'properties': {'verdict': {'enum': ['allowed', 'review', 'blocked'], 'type': 'string'}, 'rationale': {'type': 'string'}}, 'description': 'The result when the dependency never reaches users (dev, build or test scope). Independent of the shipping model.'}, 'byDistributionModel': {'type': 'array', 'items': {'type': 'object', 'required': ['model', 'verdict', 'obligations', 'rationale'], 'properties': {'model': {'enum': ['saas', 'distributed-binary', 'on-prem-delivery', 'internal-only', 'library-published'], 'type': 'string'}, 'verdict': {'enum': ['allowed', 'review', 'blocked'], 'type': 'string'}, 'rationale': {'type': 'string'}, 'obligations': {'type': 'array', 'items': {'type': 'string'}}}}, 'description': 'One row per way of shipping. This is where the same license diverges.'}}}
Cambios recientes en herramientas
Servidores MCP similares
Kamy
Renders, converts, edits and extracts PDFs, manages document templates and schedules, supports e-signature workflows and provides…
Spdx License
Browses SPDX open-source license metadata, approved-license lists, and complete license texts.
Licenses
Looks up SPDX open-source license metadata and retrieves complete license texts.
Clearlydefined
Finds software package coordinates and provides license, attribution, provenance, harvesting, and completeness information for ex…
SPDX license expression tokens, value discarded
Tokenizes and checks SPDX license expressions.
SPDX license id shape
Checks the shape of SPDX license identifiers.
AgentAegis
Performs cybersecurity assessments including vulnerability scans, code and dependency audits, secret detection, threat intelligen…
aribot-mcp
Performs threat modeling, code security, API and cloud security scans, compliance analysis, and governed remediation.