# Black Duck Signal MCP server

> Scan code changes or specific files for security vulnerabilities with Black Duck Signal AI analysis, from your coding assistant.

- Listing: https://mcp.tc/i/black-duck
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: API key
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Black Duck
- Homepage: <https://www.blackduck.com/signal-ai-appsec.html>
- Repository: <https://github.com/blackducksoftware/mcp-server>
- Package: npm `@black-duck/mcp-server`

## About

Connects your coding assistant to Black Duck Signal, an AI-assisted application security analysis service. It can scan only the code changes in a git project, either uncommitted changes or changes against a reference branch, or scan specific files and directories. Each scan returns a SARIF report path, a status, issue counts by severity and guidance for analyzing the findings.

Runs locally over stdio with npx and requires Node.js 24 or newer. A Black Duck Signal license is needed, and the key is passed in the BLACKDUCK\_MCP\_GATEWAY\_KEY environment variable. The server must be able to reach repo.blackduck.com and llm.core.blackduck.com over HTTPS.

## What it can do

- Scan uncommitted git changes for security issues
- Scan changes since branching from a reference branch
- Scan specific files or directories, including non-git projects
- Get a SARIF report with issue counts by severity
- Receive guidance for analyzing and fixing findings
- Works on Windows, macOS and Linux

## Example prompts

- "Scan my code changes for security vulnerabilities"
- "Scan the changed files with respect to the main branch"
- "Scan all files under the src/auth folder for security vulnerabilities"
- "Run a security scan on server.js and summarize the issues by severity"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio black-duck --env "BLACKDUCK_MCP_GATEWAY_KEY=<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>" -- npx -y @black-duck/mcp-server
```

2. Start Claude Code and type `/mcp`. **black-duck** should show as connected.

Add `--scope user` to make it available in every project. Replace the placeholders with your own values.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "black-duck": {
      "command": "npx",
      "args": [
        "-y",
        "@black-duck/mcp-server"
      ],
      "env": {
        "BLACKDUCK_MCP_GATEWAY_KEY": "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>"
      }
    }
  }
}
```

2. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs Node.js on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=black-duck&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBibGFjay1kdWNrL21jcC1zZXJ2ZXIiXSwiZW52Ijp7IkJMQUNLRFVDS19NQ1BfR0FURVdBWV9LRVkiOiI8WU9VUl9CTEFDS0RVQ0tfTUNQX0dBVEVXQVlfS0VZPiJ9fQ%3D%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "black-duck": {
      "command": "npx",
      "args": [
        "-y",
        "@black-duck/mcp-server"
      ],
      "env": {
        "BLACKDUCK_MCP_GATEWAY_KEY": "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>"
      }
    }
  }
}
```

Needs Node.js on your computer. Replace the placeholders with your own values.

### VS Code

Add it to `.vscode/mcp.json`. VS Code asks for the secret the first time and stores it securely:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "black-duck": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@black-duck/mcp-server"
      ],
      "env": {
        "BLACKDUCK_MCP_GATEWAY_KEY": "${input:blackduck-mcp-gateway-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "blackduck-mcp-gateway-key",
      "description": "BLACKDUCK_MCP_GATEWAY_KEY",
      "password": true
    }
  ]
}
```

Needs Node.js on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "black-duck": {
      "command": "npx",
      "args": [
        "-y",
        "@black-duck/mcp-server"
      ],
      "env": {
        "BLACKDUCK_MCP_GATEWAY_KEY": "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add black-duck --env "BLACKDUCK_MCP_GATEWAY_KEY=<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>" -- npx -y @black-duck/mcp-server
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.black-duck]
command = "npx"
args = ["-y", "@black-duck/mcp-server"]
env = { BLACKDUCK_MCP_GATEWAY_KEY = "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>" }
```

Needs Node.js on your computer. Replace the placeholders with your own values.

### Gemini CLI

```bash
gemini mcp add -e "BLACKDUCK_MCP_GATEWAY_KEY=<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>" black-duck npx -- -y @black-duck/mcp-server
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "black-duck": {
      "command": "npx",
      "args": [
        "-y",
        "@black-duck/mcp-server"
      ],
      "env": {
        "BLACKDUCK_MCP_GATEWAY_KEY": "<YOUR_BLACKDUCK_MCP_GATEWAY_KEY>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs Node.js on your computer. Replace the placeholders with your own values.

## Details

- Server version: 1.1.8
- Last checked: 2026-10-03
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/black-duck (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
