Dependency License Compliance Checker

Dependency License Compliance Checker MCP Connector for Claude

A+

Audit software dependencies against approved SPDX license identifiers to ensure supply-chain compliance.

3 tools Official Updated Oct 1, 2026 Official Vinkius Partner

This MCP server provides essential tools for securing the software supply chain by auditing dependency licenses. Use audit_dependencies to verify if a list of packages complies with your organization's whitelist, or use get_dependency_license to retrieve the specific SPDX identifier for a single package. The validate_license_format tool ensures that license strings are recognized SPDX identifiers. It acts as a bridge between your AI agent and your compliance policy, ensuring every dependency is vetted against your approved list.

licensespdxauditsupply-chaincompliancesecurity

3 tools expose this connector's capabilities to your AI agent.

get_dependency_license

audit_dependencies

validate_license_format

See how to talk to your AI agent using Dependency License Compliance Checker.

Are the dependencies npm:lodash@4.17.21 and npm:react@18.2.0 compliant with the MIT and Apache-2.0 licenses?

Yes, both dependencies are compliant with the provided license list.

What is the license for npm:lodash@4.17.21?

The license for npm:lodash@4.17.21 is MIT.

Is 'GPL-3.0' a valid SPDX identifier?

Yes, 'GPL-3.0' is a valid and recognized SPDX identifier.

You can use the `audit_dependencies` tool by providing a list of dependency strings and your list of allowed SPDX identifiers.

Related Connectors