cavil-review

Analyze Cavil legal review reports to assess package licensing risk.

63|9|Updated Oct 17, 2018
One-click install
npx skills add https://github.com/openSUSE/cavil --skill cavil-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cavil-review
Source: https://github.com/openSUSE/cavil/tree/main/examples/skills/cavil-review
Command: npx skills add https://github.com/openSUSE/cavil --skill cavil-review

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps legal reviewers evaluate package updates in Cavil so they can quickly identify licensing risks, declared-license mismatches, and compatibility concerns before any decision is finalized.

Core Features & Use Cases

  • Report Analysis: Reads Cavil legal reports and summarizes the declared license, license breakdown, risk levels, and unresolved matches.
  • Risk Assessment: Flags copyleft, proprietary, non-commercial, patent, export, and EULA-related issues that may require human review.
  • Workflow Support: Helps reviewers inspect notes, gather file context, and present a clear accept/reject recommendation with evidence.
  • Use Case: A SUSE legal reviewer can assess a newly uploaded package, verify whether the declared license matches the scanned content, and prepare a defensible review summary.

Quick Start

Ask the assistant to review the open Cavil package, compare the declared license against the report, inspect any unresolved matches, and summarize whether human review is needed.

Frequently Asked Questions about cavil-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess package licensing risk from a Cavil legal review report?

Yes, you can verify whether the declared license matches the scanned content by comparing the declared license against the license breakdown and unresolved matches within the Cavil report to identify any mismatches.

What specific license compliance issues should be flagged for human review?

License compliance issues that require human review include copyleft conditions, proprietary restrictions, non-commercial clauses, patent issues, export controls, and EULA-related concerns identified during the package update analysis.

How do I prepare a defensible package review summary for SUSE package updates?

Prepare a defensible package review summary by inspecting reviewer notes, gathering file context, validating license declarations against report findings, and presenting a clear accept, reject, or escalation recommendation with supporting evidence.

Does automated license review work for unresolved file matches in an SBOM?

Automated license review works for unresolved matches by applying evidence-based comparison of file context and reviewer notes to validate license declarations and identify compatibility concerns within the software bill of materials.