# Does Black Duck have an MCP server?

**Yes — Official.** Black Duck maintains an official MCP server.

> Requires a Black Duck Signal license and gateway key.

## Facts

- Verdict: Official (Yes)
- Access: Local server — Runs on your machine over stdio, launched by your MCP client.
- Package: [`@black-duck/mcp-server`](https://www.npmjs.com/package/@black-duck/mcp-server) on npm
- Repository: [blackducksoftware/mcp-server](https://github.com/blackducksoftware/mcp-server) — ★ 0, last push 2026-09-02, MIT
- Maintainer: Black Duck Software, Inc.
- Category: [Developer Tools](https://mcpyet.com/category/developer-tools/)
- Verified against vendor docs: 2026-09-29
- GitHub data refreshed: 2026-09-29 (re-checked every 6 hours)

## What it does

> AI-powered security analysis and vulnerability detection through MCP
> — how [blackducksoftware/mcp-server](https://github.com/blackducksoftware/mcp-server) describes itself

Project site: <https://www.blackduck.com/>

## The receipts

- **Official package:** [`@black-duck/mcp-server`](https://www.npmjs.com/package/@black-duck/mcp-server) on npm. The package page carries the exact launch arguments and required credentials.
- **Official repository:** [blackducksoftware/mcp-server](https://github.com/blackducksoftware/mcp-server) — ★ 0, pushed 2026-09-02, MIT (active)

## How to connect it

Runs on your machine over stdio, launched by your MCP client.

### Claude Code

```sh
claude mcp add blackduck -- npx -y @black-duck/mcp-server
```

Most servers need an API key passed as an environment variable — check the README for the exact variable names. Add `--scope user` to make it available in every project.

### Claude Desktop

Open **Settings → Developer → Edit Config** and add the server to `claude_desktop_config.json`, then restart Claude Desktop:

```json
{
  "mcpServers": {
    "blackduck": {
      "command": "npx",
      "args": [
        "-y",
        "@black-duck/mcp-server"
      ],
      "env": {
        "API_KEY": "…"
      }
    }
  }
}
```

### Cursor

Add to `.cursor/mcp.json` in your project, or `~/.cursor/mcp.json` for every project:

```json
{
  "mcpServers": {
    "blackduck": {
      "command": "npx",
      "args": [
        "-y",
        "@black-duck/mcp-server"
      ],
      "env": {
        "API_KEY": "…"
      }
    }
  }
}
```

### VS Code

Add to `.vscode/mcp.json`, then pick the server from Copilot's agent-mode tools menu:

```json
{
  "servers": {
    "blackduck": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@black-duck/mcp-server"
      ]
    }
  }
}
```

### ChatGPT

ChatGPT connects to **remote servers only**, and this one runs on your machine. Either expose it through an MCP gateway that gives it a public URL, or use a client with native local support (Claude or Cursor).

## How we know

Published to the MCP Registry under Black Duck's verified namespace com.blackduck as the npm package @black-duck/mcp-server, built from the blackducksoftware/mcp-server repo. Black Duck announced the Signal MCP server at news.blackduck.com (2026-09-02). It runs locally and sends scanned code to Black Duck's remote analysis service.

- GitHub data refreshed 2026-09-29, then every 6 hours.
- Vendor docs verified on 2026-09-29.
- Corrections: hello@mcpyet.com.

## Also in Developer Tools

- [Chrome DevTools](https://mcpyet.com/mcp/chrome-devtools.md) — Official (Yes)
- [Google AI Studio](https://mcpyet.com/mcp/google-ai-studio.md) — Community only (Sort of)
- [Serena](https://mcpyet.com/mcp/serena.md) — Official (Yes)
- [LangChain](https://mcpyet.com/mcp/langchain.md) — Official (Yes)
- [GitLab](https://mcpyet.com/mcp/gitlab.md) — Official (Yes)
- [n8n](https://mcpyet.com/mcp/n8n.md) — Official (Yes)

---

Source: https://mcpyet.com/mcp/black-duck/ — data refreshed 2026-09-29
