oss-review

Identify open source license compliance obligations and legal risks for software products.

17|4|Updated May 25, 2026
One-click install
npx skills add https://github.com/AlsKozlov/ru-legal --skill oss-review-alskozlov
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: oss-review
Source: https://github.com/AlsKozlov/ru-legal/tree/main/packs/ip-law/skills/oss-review
Command: npx skills add https://github.com/AlsKozlov/ru-legal --skill oss-review-alskozlov

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill eliminates the risk of non-compliance with open source license obligations, which can lead to legal liability, forced open-sourcing of proprietary code, and failure to meet Russian IT accreditation requirements for tax benefits.

Core Features & Use Cases

  • OSS License Categorization: Classifies dependencies by copyleft strength (permissive, weak/strong copyleft, non-standard) with clear attribution and modification rules for each license type.
  • Compatibility & Risk Analysis: Flags incompatible license combinations and assesses risks for different product use cases (internal tools, SaaS, distributed binaries, open-source projects).
  • Russian Regulatory Alignment: Provides specific guidance for Mincifry IT accreditation, import substitution requirements for government contracts, and post-2022 sanctions impacts on OSS supply chains. Use case example: A product team launching a proprietary desktop application can use this Skill to identify GPL components that require open-sourcing the entire product, and document OSS usage to qualify for Russian IT accreditation tax benefits.

Quick Start

Use the oss-review skill to audit the open source licenses in your project's dependencies and generate a compliance risk report aligned with Russian legal requirements.

Frequently Asked Questions about oss-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check open source license compliance for software dependencies?

OSS license categorization classifies dependencies by copyleft strength—permissive, weak, or strong copyleft—and flags incompatible license combinations. It assesses legal risks for specific use cases like internal tools, SaaS, and distributed binaries, providing actionable remediation steps.

How do I assess copyleft risks when building a proprietary SaaS platform?

Assess copyleft risks for SaaS platforms by checking dependency licenses for strong copyleft obligations that could force open-sourcing proprietary code. The review categorizes permissive versus copyleft licenses and flags incompatible combinations specific to your distribution model.

Does open source license review support Russian IT accreditation requirements?

Yes, open source license review supports Russian IT accreditation by aligning dependency audits with Mincifry requirements and import substitution rules. It helps document OSS usage to qualify for tax benefits and addresses post-2022 sanctions impacts on OSS supply chains.

What is the best way to identify incompatible open source license combinations in a project?

The best way to identify incompatible open source license combinations is to perform a compatibility and risk analysis across your dependency inventory. This flags conflicting licenses and assesses use case-specific risks for internal tools, SaaS platforms, or distributed binaries.

When do I need an OSS license review for government contracts?

An OSS license review is needed for government contracts when you must meet import substitution requirements and Russian regulatory constraints. It ensures software dependencies comply with legal standards and documents usage for Mincifry accreditation processes.