cavil-license-research

Assess license obligations and map them to a Cavil risk level.

63|9|Updated Oct 17, 2018
One-click install
npx skills add https://github.com/openSUSE/cavil --skill cavil-license-research
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cavil-license-research
Source: https://github.com/openSUSE/cavil/tree/main/examples/skills/cavil-license-research
Command: npx skills add https://github.com/openSUSE/cavil --skill cavil-license-research

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps legal and compliance teams evaluate an unfamiliar license or SPDX identifier and turn it into a conservative Cavil risk recommendation, so a human reviewer can teach Cavil the right classification.

Core Features & Use Cases

  • License identification: Distinguishes between a known license name, an SPDX identifier, or license text from an unresolved snippet.
  • Risk assessment: Maps the license to Cavil’s 1–7 risk scale based on its actual obligations, not on approval badges.
  • Flag recommendation: Advises whether patent, trademark, export, EULA, or CLA flags are warranted.
  • Use case: A lawyer receives a new vendor license and needs a sourced, cautious recommendation before adding it to Cavil’s pattern editor.

Quick Start

Ask the Skill to identify the license text you found and produce a Cavil risk assessment with sources, flags, and a one-line recommendation for the pattern editor.

Frequently Asked Questions about cavil-license-research

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess open source license risk for an unknown SPDX identifier?

To assess open source license risk for an unknown SPDX identifier, the Skill evaluates the license's actual obligations against a 1–7 risk scale and recommends conservative patent, trademark, EULA, and CLA flags using primary-source verification.

What is Cavil risk assessment and when do I need it for legal compliance?

Cavil risk assessment is the process of mapping a license's obligations to a 1–7 risk scale. You need it when evaluating an unfamiliar license or unresolved snippet before teaching Cavil the correct pattern classification.

How do I research an unresolved license snippet before authoring a Cavil pattern?

To research an unresolved license snippet before pattern authoring, provide the text to the Skill. It identifies the license, verifies obligations against primary sources and registries, and outputs a one-line recommendation for the pattern editor.

Does license risk assessment require verification from primary sources and authoritative registries?

Yes, license risk assessment requires primary-source verification from the actual license text and authoritative registries. This ensures the obligations, risk level, and patent or trademark flags are accurate for compliance review.

What's the best way to evaluate patent and trademark obligations in a new vendor license?

The best way to evaluate patent and trademark obligations is to analyze the license text against authoritative registries. The Skill then provides conservative flag recommendations for patent, trademark, export, EULA, and CLA signals.

Can I use this approach for licenses without an official SPDX identifier?

Yes, you can use this approach for licenses without an official SPDX identifier. It distinguishes between known names, SPDX identifiers, and unresolved snippets to produce a sourced risk recommendation.