Black Duck Security Scanner is a Model Context Protocol (MCP) server: AI-powered security scanning using Black Duck Signal for vulnerability detection. In practice that means any MCP-compatible AI assistant can call Black Duck Security Scanner's tools directly — the model decides when to use them in a conversation or agent run.
It runs locally: the npm package @black-duck/mcp-server speaks MCP over stdio on your machine. No credentials are required — it works out of the box. The current release is v1.1.8, published under the MIT license, with source at blackducksoftware/mcp-server on GitHub.
Black Duck Security Scanner is listed under Security on mcp.site and works with any MCP client — Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Zed and the rest of the ecosystem — using the install snippets below. If you maintain Black Duck Security Scanner for blackduck.com, claim this listing to verify ownership, earn the Verified badge, and keep the details current.
▸npm package — @black-duck/mcp-server · MCP over stdio
▸Open source — MIT license · blackducksoftware/mcp-server