‹ The Index

Black Duck Security Scanner

npm

AI-powered security scanning using Black Duck Signal for vulnerability detection.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code

Category: Security — see all ranked ›

Install (Claude Code):

claude mcp add lack--uck--ecurity--canner -- npx -y @black-duck/mcp-server
solid

“Both tools documented with parameters, returns, and the git-only constraint on scans”

Security audit

scanned 2026-07-30

Every finding is shown in full. A licence adds the detail needed to act on it — which advisory, what the install script does, the version that fixes it.

No known advisoriesclearchecked against OSV for 1.1.8
Handles credentials or secrets · Makes network requestsfrom declared dependencies
Can carry remote content into your agentunlock detail
No build provenanceno attestation — the published artifact cannot be traced to its source

1 finding here has detail behind a licence. You can see it exists above, free, permanently — Pro tells you what third-party content it can pull into your agent.

Unlock the fix — $6/mo ›or check your whole config free with npx tashan-cli doctor

npm ↗  ·  source ↗  ·  pkg:@black-duck/mcp-server

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›