Does Black Duck have an MCP server?
Black Duck maintains an official MCP server.
Requires a Black Duck Signal license and gateway key.
- Access
- Local server
- Package
- @black-duck/mcp-server
- Repository
- blackducksoftware/mcp-server
- Maintainer
- Black Duck Software, Inc.
- License
- MIT
- Stars
- 0
- Last commit
- 27d ago
- Category
- Developer Tools
AI-powered security analysis and vulnerability detection through MCP
Project site: www.blackduck.com
Published on npm. The package page carries the exact launch arguments and required credentials.
AI-powered security analysis and vulnerability detection through MCP
Runs on your machine over stdio, launched by your MCP client.
Add it from the terminal, then restart your session:
claude mcp add blackduck -- npx -y @black-duck/mcp-serverSwap in the exact package and flags from the repo README — most servers need an API key passed as an environment variable.
Add --scope user to make it available in every project.
Open Settings → Developer → Edit Config and add the server to claude_desktop_config.json:
{
"mcpServers": {
"blackduck": {
"command": "npx",
"args": [
"-y",
"@black-duck/mcp-server"
],
"env": {
"API_KEY": "…"
}
}
}
}Restart Claude Desktop after saving.
Add to .cursor/mcp.json in your project, or ~/.cursor/mcp.json for
every project:
{
"mcpServers": {
"blackduck": {
"command": "npx",
"args": [
"-y",
"@black-duck/mcp-server"
],
"env": {
"API_KEY": "…"
}
}
}
}A green dot in Settings → MCP means it connected.
Add to .vscode/mcp.json:
{
"servers": {
"blackduck": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@black-duck/mcp-server"
]
}
}
}Then pick the server from the tools menu in Copilot's agent mode.
Does Black Duck have an official MCP server?
Yes. Black Duck maintains an official MCP server, distributed as @black-duck/mcp-server on npm. The source lives at blackducksoftware/mcp-server on GitHub.
How do I connect Black Duck to Claude?
Run the server locally and register it in Claude's MCP config. In Claude Code that's a single "claude mcp add" command; in Claude Desktop you add it to claude_desktop_config.json.
How is this verdict verified?
Published to the MCP Registry under Black Duck's verified namespace com.blackduck as the npm package @black-duck/mcp-server, built from the blackducksoftware/mcp-server repo. Black Duck announced the Signal MCP server at news.blackduck.com (2026-09-02). It runs locally and sends scanned code to Black Duck's remote analysis service. GitHub metadata is refreshed every six hours.
Published to the MCP Registry under Black Duck's verified namespace com.blackduck as the npm package @black-duck/mcp-server, built from the blackducksoftware/mcp-server repo. Black Duck announced the Signal MCP server at news.blackduck.com (2026-09-02). It runs locally and sends scanned code to Black Duck's remote analysis service.
- github data refreshed 2026-09-29, then every 6 hours
- vendor docs verified on 2026-09-29
Spotted something out of date? Tell us — corrections ship same-day.