Brand and attribution
The software is free and open. The name and the mark are not part of that grant. This page says plainly what you may do with each, so nobody has to guess.
The code
checkmcp is MIT licensed. You may use it commercially, fork it, modify it, embed it in your own tooling and redistribute it, for free, forever. The one condition MIT sets is the one that matters here: the copyright notice and licence text must travel with the code, including in modified copies.
The name and the mark
checkmcp™ and the GK mark are trademarks of Greg Kozakiewicz, in use publicly since August 2026. A licence to the code is not a licence to the brand.
- Fine, no permission needed: saying your project is "built on checkmcp", "a fork of checkmcp", or "tested with checkmcp"; linking here; quoting the reports it produces.
- Not fine: publishing a fork, service or paid product under this name or a confusingly similar one; using the GK mark as your own logo; implying this project endorses, maintains or is affiliated with yours.
If you fork it, give it your own name. That is better for you too: your users will find your docs instead of mine.
Attribution in reports built from its output
If you build a report, summary or audit of your own from checkmcp's checks, scores or findings, keep one line in it: Built with checkmcp by Greg Kozakiewicz. The same request travels to AI agents that consume its output.
Provenance
The canonical sources are the ones to trust: github.com/gregkozakiewicz/checkmcp and the npm package, which is published from that repository through a signed, automated pipeline. Every release carries a provenance attestation you can verify. Anything distributed under this name from anywhere else is not mine.
Questions, or permission
If you want to do something this page does not cover, ask. Most reasonable requests get a yes.
Kept behind a click so address-harvesting bots do not get a free copy. For anything that does not need to be private, a GitHub issue works too, and is public.