oss-licensing-advisor

Audit OSS licenses with SPDX mapping and compatibility risk scoring.

1|Updated Mar 6, 2026
One-click install
npx skills add https://github.com/grant-vine/wunderkind --skill oss-licensing-advisor
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: oss-licensing-advisor
Source: https://github.com/grant-vine/wunderkind/tree/main/skills/oss-licensing-advisor
Command: npx skills add https://github.com/grant-vine/wunderkind --skill oss-licensing-advisor

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill provides systematic OSS license auditing, compatibility analysis, and contributor agreement guidance to help teams stay compliant across licenses, notices, and COC requirements.

Core Features & Use Cases

  • License discovery and SPDX mapping for project inventories
  • Compatibility assessment between licenses and risk scoring
  • Guidance on contributor agreements (CLA/DCO) with OpenChain and REUSE alignment
  • Use Case: For a multinational project with many dependencies, generate a license posture and remediation plan.

Quick Start

Audit your repository for OSS licenses and generate a compliant license strategy.

Frequently Asked Questions about oss-licensing-advisor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit OSS licenses for a multi-dependency software project?

Auditing OSS licenses for multi-dependency projects requires mapping dependencies to SPDX identifiers and checking compatibility to identify potential license conflicts. This skill systematically inventories project licenses, scores compliance risks, and generates a structured remediation plan.

What is SPDX identification and how does it help with license compliance?

SPDX identification maps open-source dependencies to standardized license identifiers, enabling accurate license compliance analysis. It provides a consistent format for inventorying licenses across complex projects and detecting potential conflicts between different open-source licenses.

How do I check license compatibility between dependencies in my repository?

Checking license compatibility requires analyzing the licenses of all project dependencies against each other to detect conflicts. This skill applies compatibility checks and risk scoring to identify licenses that cannot safely coexist within your software project.

Can I use this to manage CLA and DCO workflows across multiple vendors and teams?

Yes, managing CLA and DCO workflows across teams and vendors is supported. The skill provides guidance on contributor agreements aligned with OpenChain and REUSE standards, ensuring structured and policy-aware compliance across distributed contributors.

What is the best way to generate a license posture and remediation plan for a multinational project?

Generating a license posture and remediation plan for a multinational project requires systematic license discovery, SPDX mapping, and compatibility assessment. This skill applies a structured, policy-aware process to identify risks and outline actionable compliance steps across dependencies.

Does this license compliance process align with OpenChain and REUSE standards?

Yes, the license compliance process aligns with OpenChain and REUSE standards. It integrates these frameworks into its contributor agreement guidance and SPDX mapping workflows to ensure your project's license inventory meets recognized industry compliance requirements.