← Back to Skills

Open Source License Compliance Auditor

Expert guidance for auditing and ensuring open source license compliance across software projects. Covers license identification, compatibility analysis, SBOM generation, copyleft obligations, SPDX/CycloneDX standards, OSPO policy frameworks, and M&A due diligence.

Gold
v1.0.00 activationsLegal & ComplianceLegalexpert

SupaScore

83
Research Quality (15%)
8.5
Prompt Engineering (25%)
8.3
Practical Utility (15%)
8.2
Completeness (10%)
8.2
User Satisfaction (20%)
8.2
Decision Usefulness (15%)
8.4

Best for

  • SBOM generation and license compatibility analysis for software releases
  • M&A due diligence review of target company's open source usage
  • GPL/AGPL copyleft obligation assessment for SaaS deployments
  • OSPO policy framework implementation and OpenChain compliance
  • Apache 2.0 patent grant analysis for enterprise software integration

What you'll get

  • SPDX 2.3 formatted SBOM with license risk classifications (permissive/weak copyleft/strong copyleft) and specific obligation requirements
  • Compliance matrix showing distribution triggers, source code disclosure requirements, and patent grant implications by component
  • Risk assessment report with high/medium/low classifications and prioritized remediation steps for license violations
Not designed for ↓
  • ×Creating or drafting new open source licenses
  • ×Patent infringement litigation strategy or legal representation
  • ×General intellectual property portfolio management
  • ×Commercial software licensing negotiations
Expects

Specific software distribution context, existing SBOM or dependency list, and intended use case (distribution, SaaS, internal use, or M&A).

Returns

Structured compliance assessment with SPDX-formatted license inventory, obligation matrix, risk classification, and actionable remediation steps.

Risk Domain: legal. This skill covers legal topics. Consult a lawyer for binding decisions.

Human sign-off recommended before acting on this output.

Evidence Policy

Enabled: this skill cites sources and distinguishes evidence from opinion.

open-sourcelicense-compliancesbomspdxcyclonedxcopyleftgplapachemitosposoftware-composition-analysisopenchain

Research Foundation: 7 sources (4 official docs, 1 books, 2 industry frameworks)

This skill was developed through independent research and synthesis. SupaSkills is not affiliated with or endorsed by any cited author or organisation.

Version History

v1.0.02/16/2026

Initial release

Works well with

Need more depth?

Specialist skills that go deeper in areas this skill touches.

Common Workflows

Software Release Compliance Pipeline

Complete software release legal review from dependency audit through customer-facing terms

open-source-license-compliance-auditorAPI Terms of Use Architectlegal-disclaimer-validation-expert

Activate this skill in Claude Code

Sign up for free to access the full system prompt via REST API or MCP.

Start Free to Activate This Skill

© 2026 Kill The Dragon GmbH. This skill and its system prompt are protected by copyright. Unauthorised redistribution is prohibited. Terms of Service · Legal Notice