← Back to Skills
Legal & ComplianceLegalPlatinum

Understand open source license compatibility and obligations.

Open Source License Advisor

SPDX, FOSS Compliance, CLA Management

advancedv5.0

Best for

  • Evaluating GPL-3.0 compatibility with Apache-2.0 in microservices architecture
  • SPDX identifier validation for SBOM generation and supply chain compliance
  • CLA governance setup for accepting external contributions to open source projects
  • AGPL-3.0 network copyleft risk assessment for SaaS deployment models

What you'll get

  • License compatibility matrix showing specific clause conflicts with remediation options and alternative licensing paths
  • SPDX-compliant bill of materials with obligation summaries and copyleft boundary analysis for each component
  • CLA implementation roadmap with template recommendations and contributor workflow integration points
Expects

Specific license identifiers, distribution models, linking relationships, and project context (library/application/SaaS) with clear description of how components interact.

Returns

Detailed compatibility matrix with specific obligation requirements, copyleft propagation analysis, SPDX-compliant recommendations, and actionable compliance strategies.

What's inside

You are an Open Source License Compliance Advisor. You help teams navigate FOSS licensing with legal precision and actionable guidance, combining IP attorney expertise with practical license scanning knowledge. - **SPDX Precision**: Specify exact license identifiers (GPL-2.0-only vs GPL-2.0-or-later...

Covers

What You Do DifferentlyMethodologyWatch For
Not designed for ↓
  • ×General intellectual property law advice beyond open source licensing
  • ×Patent prosecution or trademark registration guidance
  • ×Commercial software licensing negotiations or enterprise agreements
  • ×Legal representation in license violation disputes

SupaScore

88.45
Research Quality (15%)
9.25
Prompt Engineering (25%)
8.75
Practical Utility (15%)
8.75
Completeness (10%)
8.75
User Satisfaction (20%)
8.85
Decision Usefulness (15%)
8.75

Evidence Policy

Standard: no explicit evidence policy.

open-sourcelicensinggplapache-licensemit-licensespdxfoss-compliancecopyleftlicense-scanningclasoftware-supply-chainsbomintellectual-property

Research Foundation: 8 sources (5 official docs, 2 industry frameworks, 1 books)

This skill was developed through independent research and synthesis. SupaSkills is not affiliated with or endorsed by any cited author or organisation.

Version History

v5.03/25/2026

v5.5 final distill

v2.02/25/2026

Pipeline v4: rebuilt with 3 helper skills

v1.0.02/15/2026

Initial release

Works well with

Need more depth?

Specialist skills that go deeper in areas this skill touches.

Common Workflows

Open Source Compliance Pipeline

Complete open source risk assessment covering licensing, security vulnerabilities, and supply chain integrity for enterprise software projects

open-source-license-advisordependency-security-auditorsupply-chain-security-architect

© 2026 Kill The Dragon GmbH. This skill and its system prompt are protected by copyright. Unauthorised redistribution is prohibited. Terms of Service · Legal Notice