Black Duck Security Scanner runs on your own machine — the client starts it, so there is no endpoint to ping. 241 installs a week from npm. Last commit 2 Sep 2026.
AI-powered security scanning using Black Duck Signal for vulnerability detection.
Today is the operative word: we check Black Duck Security Scanner every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add mcp-server -- npx -y @black-duck/mcp-server
{
"mcpServers": {
"mcp-server": {
"args": [
"-y",
"@black-duck/mcp-server"
],
"command": "npx"
}
}
}
[mcp_servers.mcp-server]
command = "npx"
args = ["-y", "@black-duck/mcp-server"]
{
"mcpServers": {
"mcp-server": {
"args": [
"-y",
"@black-duck/mcp-server"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"mcp-server": {
"args": [
"-y",
"@black-duck/mcp-server"
],
"command": "npx"
}
}
}
AI-Powered Security Scanner for LLMs. Detects vulnerabilities and syncs with SynapseAudit.
Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
Security scanning and threat detection for AI agents
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
Scan installed MCP servers for security vulnerabilities with 16 detection engines.
AI-powered application security testing — scan APIs, discover endpoints, and find vulnerabilities.
Security scanner for MCP servers - detects tool poisoning and injection
Answers built from our own checks of this server.