Black Duck Signal
Servidor MCP de Black Duck
Scan code changes or specific files for security vulnerabilities with Black Duck Signal AI analysis, from your coding assistant.
Instalar Black Duck Signal
Se ejecuta en tu equipo. Tu cliente lo inicia con este comando:
Requiere Node.js en tu equipo. Los pasos de configuración de abajo muestran dónde va el comando en cada cliente.
BLACKDUCK_MCP_GATEWAY_KEYsecreto Black Duck Signal API key (required).
Compartir este servidor
Abre esta página, con el comando de instalación y los pasos de configuración.
mcp.tc/i/black-duckDescripción
Connects your coding assistant to Black Duck Signal, an AI-assisted application security analysis service. It can scan only the code changes in a git project, either uncommitted changes or changes against a reference branch, or scan specific files and directories. Each scan returns a SARIF report path, a status, issue counts by severity and guidance for analyzing the findings.
Runs locally over stdio with npx and requires Node.js 24 or newer. A Black Duck Signal license is needed, and the key is passed in the BLACKDUCK_MCP_GATEWAY_KEY environment variable. The server must be able to reach repo.blackduck.com and llm.core.blackduck.com over HTTPS.
Qué puedes hacer
- Scan uncommitted git changes for security issues
- Scan changes since branching from a reference branch
- Scan specific files or directories, including non-git projects
- Get a SARIF report with issue counts by severity
- Receive guidance for analyzing and fixing findings
- Works on Windows, macOS and Linux
Herramientas
Black Duck Signal solo muestra sus herramientas a clientes con clave, así que no podemos listarlas aquí.
Prompts de ejemplo
Scan my code changes for security vulnerabilities
Scan the changed files with respect to the main branch
Scan all files under the src/auth folder for security vulnerabilities
Run a security scan on server.js and summarize the issues by severity
Configuración
Todos los clientes inician Black Duck Signal en tu equipo con el mismo comando. Elige el tuyo; la página recuerda tu elección.
Claude Code
- Run this in a terminal, in your project folder:
claude mcp add --transport stdio black-duck --env "BLACKDUCK_MCP_GATEWAY_KEY=<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>" -- npx -y @black-duck/mcp-server- Start Claude Code and type
/mcp. black-duck should show as connected.
Add --scope user to make it available in every project. Replace the placeholders with your own values.
Claude Desktop
- Open Settings → Developer → Edit Config. It opens
claude_desktop_config.json. Add:
{
"mcpServers": {
"black-duck": {
"command": "npx",
"args": [
"-y",
"@black-duck/mcp-server"
],
"env": {
"BLACKDUCK_MCP_GATEWAY_KEY": "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>"
}
}
}
}- Save the file and restart Claude Desktop. Replace the placeholders with your own values.
Needs Node.js on your computer. The file lives in ~/Library/Application Support/Claude/ on macOS and %APPDATA%\Claude\ on Windows.
Cursor
Añadir a Cursor (se abre en una pestaña nueva)
Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):
{
"mcpServers": {
"black-duck": {
"command": "npx",
"args": [
"-y",
"@black-duck/mcp-server"
],
"env": {
"BLACKDUCK_MCP_GATEWAY_KEY": "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>"
}
}
}
}Needs Node.js on your computer. Replace the placeholders with your own values.
VS Code
Add it to .vscode/mcp.json. VS Code asks for the secret the first time and stores it securely:
{
"servers": {
"black-duck": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@black-duck/mcp-server"
],
"env": {
"BLACKDUCK_MCP_GATEWAY_KEY": "${input:blackduck-mcp-gateway-key}"
}
}
},
"inputs": [
{
"type": "promptString",
"id": "blackduck-mcp-gateway-key",
"description": "BLACKDUCK_MCP_GATEWAY_KEY",
"password": true
}
]
}Needs Node.js on your computer.
Devin Desktop
- Add it to
~/.config/devin/mcp_config.json(macOS and Linux) or%APPDATA%\devin\mcp_config.json(Windows):
{
"mcpServers": {
"black-duck": {
"command": "npx",
"args": [
"-y",
"@black-duck/mcp-server"
],
"env": {
"BLACKDUCK_MCP_GATEWAY_KEY": "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>"
}
}
}
}- Refresh the MCP server list in Cascade. Replace the placeholders with your own values.
Devin Desktop is the new name for Windsurf.
Codex
codex mcp add black-duck --env "BLACKDUCK_MCP_GATEWAY_KEY=<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>" -- npx -y @black-duck/mcp-serverOr edit ~/.codex/config.toml directly:
[mcp_servers.black-duck]
command = "npx"
args = ["-y", "@black-duck/mcp-server"]
env = { BLACKDUCK_MCP_GATEWAY_KEY = "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>" }Needs Node.js on your computer. Replace the placeholders with your own values.
Gemini CLI
gemini mcp add -e "BLACKDUCK_MCP_GATEWAY_KEY=<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>" black-duck npx -- -y @black-duck/mcp-serverThis adds it to the current project. Add -s user to use it everywhere.
Any client
Most clients that start local servers accept this shape:
{
"mcpServers": {
"black-duck": {
"command": "npx",
"args": [
"-y",
"@black-duck/mcp-server"
],
"env": {
"BLACKDUCK_MCP_GATEWAY_KEY": "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>"
}
}
}
}Zed puts servers under context_servers in its settings, with the same command, args and env fields.
Needs Node.js on your computer. Replace the placeholders with your own values.
Preguntas frecuentes
Can I paste mcp.tc/i/black-duck into my MCP client?
No. Black Duck Signal runs on your own computer, started by your client, so it has no web address to connect to. The quick link is the page to share; the install command is npx -y @black-duck/mcp-server.
Does Black Duck Signal need an API key?
Yes. It reads BLACKDUCK_MCP_GATEWAY_KEY from its environment, and BLACKDUCK_MCP_GATEWAY_KEY is a secret. Put the value in your client’s config on your own machine, never in a shared file.
Is Black Duck Signal a remote or a local server?
Local. Your client starts it as a process on your computer with npx -y @black-duck/mcp-server, which needs Node.js.
What can Black Duck Signal do?
You can scan uncommitted git changes for security issues, scan changes since branching from a reference branch y scan specific files or directories, including non-git projects.
Which clients can use it?
Any client that starts local servers: Claude Code, Claude Desktop, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. claude.ai and ChatGPT only connect to remote servers.
Who wrote this page?
mcp.tc’s robot read Black Duck Signal’s public metadata (its package and repository pages), and an AI model drafted the text from it. A person reviews anything the checks can’t confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.
Insertar
Muestra Black Duck Signal en un README o en tu web. Cada inserción enlaza a esta página, usa el comando de instalación del servidor y no instala cookies. Cómo funcionan las inserciones
Insignia para README
[](https://mcp.tc/i/black-duck)<a href="https://mcp.tc/i/black-duck"><img src="https://mcp.tc/i/black-duck/badge.svg" alt="Black Duck Signal on mcp.tc" height="20"></a>Sigue el modo claro u oscuro de quien lee. Añade ?theme=light o ?theme=dark para fijarlo, o ?style=compact para mostrar el símbolo sin la palabra.
Tarjeta para web
<script src="https://mcp.tc/w/black-duck.js" async></script>La tarjeta aparece donde esté la etiqueta. Añade data-theme="dark" o data-size="compact" a la etiqueta para cambiarla. El archivo contiene todo lo que necesita, así que no hace otras solicitudes ni instala cookies.
iframe
<iframe src="https://mcp.tc/embed/black-duck" title="Black Duck Signal on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>Úsalo en páginas que no permiten scripts. Añade ?theme=light o ?theme=dark a la dirección para fijar los colores.
JSON
La ficha como datos para tus propias páginas y herramientas: nombre, descripción corta, comando de instalación, herramientas y los enlaces «Add to». Cualquier web puede leerla (CORS abierto).
https://mcp.tc/i/black-duck.jsonmcp.tc no tiene relación con Black Duck. Esta página se creó a partir de los metadatos públicos de Black Duck Signal, comprobados por última vez el 3 oct 2026, y un modelo de IA escribió la descripción, así que puede contener errores. Los nombres y marcas pertenecen a sus titulares. ¿Algo no cuadra? Reportar esta ficha.