Using FossID with AI assistants
FossID works with AI chat assistants through MCP (Model Context Protocol). MCP is the standard way assistants connect to external tools. Once you're signed in, your assistant can scan code, query the results, check license compatibility, generate an SBOM, and show findings directly in your editor.
| Assistant | Support |
|---|---|
| GitHub Copilot Chat (Agent Mode) | Supported, with any model |
| Claude Code (VS Code extension or CLI) | Supported |
| Cursor | Supported |
How your assistant is connected
FossID offers two MCP servers, both running locally on your machine:
- fossid-mcp: the scanner. It scans code, queries results, analyzes compliance and generates reports.
- fossid-editor: editor actions. It opens files, shows diffs, highlights code and adds findings to the Problems panel.
After you sign in, FossID registers both servers by writing configuration files into your workspace folder:
| Assistant | File |
|---|---|
| GitHub Copilot | .vscode/mcp.json |
| Claude Code | .mcp.json |
| Cursor | .cursor/mcp.json |
These files contain only local addresses (http://127.0.0.1:…), never your sign-in. FossID keeps them up to date and leaves any other servers in them untouched. The addresses are specific to your machine, so add the files to .gitignore (FossID offers to copy the lines the first time).
- VS Code: FossID starts both servers automatically. No Start Server click is needed in a trusted workspace.
- Cursor: the servers are added disabled. Open Cursor's MCP settings and enable fossid-mcp and fossid-editor once.
- Claude Code: picks the servers up from
.mcp.json. Approve them if Claude Code asks.
Your assistant and the editor share one set of scan results. A scan the assistant runs appears in the Problems panel, and findings from automatic scanning are visible to the assistant. Copilot and Claude Code in the same window share results too.
To connect another MCP client by hand, run FossID: Copy MCP URL. It copies either server's address, or a ready-made JSON snippet with both.
What you can ask
Some examples:
- "Scan this workspace and give me a risk overview."
- "Which files contain copyleft code, and under which licenses?"
- "Find all files with GPL-3.0 licenses and push them to the Problems panel."
- "Analyze LICENSE and highlight any modifications."
- "Show a diff between the canonical MIT license text and my LICENSE file."
- "Is the Apache-2.0 license compatible with the licenses of our dependencies?"
- "Which of our dependencies have known vulnerabilities, and which versions fix them?"
- "Generate an SPDX SBOM for this project."
The assistant can:
| Area | What it can do |
|---|---|
| Scanning | Scan files, folders or the whole project for open-source components, licenses and vulnerable snippets. Import offline scans. |
| Dependencies | Resolve dependency manifests, look up component details and vulnerabilities. |
| Analysis | Query results (for example a risk overview, copyleft exposure, or files by license or component), analyze license texts in your files, check license compatibility, look up license texts. |
| Deliverables | Generate an SPDX 2.3 SBOM or a FossID Workbench report. Import existing SPDX documents. |
| Editor | Open files at the relevant lines, show side-by-side diffs, highlight code, add findings to and clear them from the Problems panel. |
For single findings, use Explain and Fix with FossID.
Analyze Findings
When FossID: Scan Workspace finishes, FossID offers Analyze Findings. It opens your chat with a prompt asking the assistant to audit the fresh results, without scanning again. If the chat can't be opened, the prompt is copied to your clipboard.
Skills and the workflow file
FossID ships skills that teach your assistant how to work with it:
- fossid-workflow is used by the assistant itself. It describes the correct scan workflow: load the policy, check existing results, then scan. The assistant must read it before it may run scans. FossID keeps a copy at
.fossid/workflow.mdin your workspace. - fossid-explain and fossid-fix are behind the Explain and Fix actions. In Claude Code you can run them yourself as
/fossid-explainand/fossid-fix.
FossID installs and updates these skills automatically:
- in Claude Code and Cursor, under
~/.claude/skills/; - in Copilot, built in.
Note: FossID overwrites these skill files when it starts, so local edits to them are lost.