Back to Browse

License Boundary MCP Server

Developer ToolsModerate7.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Summarize local license evidence and uncertainty without returning package names, license text,...

About

Summarize local license evidence and uncertainty without returning package names, license text,...

Security Report

7.2
Moderate7.2Low Risk

License Boundary MCP is a well-designed read-only tool with strong privacy safeguards and appropriate permissions for its purpose. The server intentionally avoids returning sensitive data (license text, package names, paths) and uses conservative classification. Minor code quality issues exist (broad exception handling, minified code readability) but do not present security risks. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

6 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-mrfentmen-license-boundary-mcp": {
      "args": [
        "-y",
        "license-boundary-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

license-boundary-mcp

License Boundary summarizes local license evidence before a release. It classifies common license markers and highlights unknown evidence without pretending to provide legal advice.

Quick start

npm install
npm test
npm start

Call inspect_license_boundary with a bounded project path.

Privacy and limits

The server reads license files and recognized manifests, but only returns aggregate categories. It never returns license text, package names, paths, or source. Classification is intentionally conservative.

Reviews

No reviews yet

Be the first to review this server!