Does Black Duck have an MCP server?

Yes Official

Black Duck maintains an official MCP server.

Requires a Black Duck Signal license and gateway key.

Verified 2026-09-29 against vendor docs
Access
Local server
Maintainer
Black Duck Software, Inc.
License
MIT
Stars
0
Last commit
27d ago
What it does
AI-powered security analysis and vulnerability detection through MCP
— how blackducksoftware/mcp-server describes itself

Project site: www.blackduck.com

The receipts
Official package @black-duck/mcp-server

Published on npm. The package page carries the exact launch arguments and required credentials.

Official repository blackducksoftware/mcp-server

AI-powered security analysis and vulnerability detection through MCP

★ 0 pushed 2026-09-02 MIT Active
Connect it

Runs on your machine over stdio, launched by your MCP client.

Add it from the terminal, then restart your session:

terminal
claude mcp add blackduck -- npx -y @black-duck/mcp-server

Swap in the exact package and flags from the repo README — most servers need an API key passed as an environment variable.

Add --scope user to make it available in every project.

Setup sponsor · open Put your product right here, under the setup steps of all 645 verdict pages. One sponsor at a time. $149 first month, then $399/mo →
Questions
Does Black Duck have an official MCP server?

Yes. Black Duck maintains an official MCP server, distributed as @black-duck/mcp-server on npm. The source lives at blackducksoftware/mcp-server on GitHub.

How do I connect Black Duck to Claude?

Run the server locally and register it in Claude's MCP config. In Claude Code that's a single "claude mcp add" command; in Claude Desktop you add it to claude_desktop_config.json.

How is this verdict verified?

Published to the MCP Registry under Black Duck's verified namespace com.blackduck as the npm package @black-duck/mcp-server, built from the blackducksoftware/mcp-server repo. Black Duck announced the Signal MCP server at news.blackduck.com (2026-09-02). It runs locally and sends scanned code to Black Duck's remote analysis service. GitHub metadata is refreshed every six hours.

How we know

Published to the MCP Registry under Black Duck's verified namespace com.blackduck as the npm package @black-duck/mcp-server, built from the blackducksoftware/mcp-server repo. Black Duck announced the Signal MCP server at news.blackduck.com (2026-09-02). It runs locally and sends scanned code to Black Duck's remote analysis service.

  • github data refreshed 2026-09-29, then every 6 hours
  • vendor docs verified on 2026-09-29

Spotted something out of date? Tell us — corrections ship same-day.

Also in Developer Tools

See all Developer Tools servers →