Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration
Brief
Application security vendor Black Duck has launched its Signal vulnerability scanning engine as an MCP server in the Claude Directory, giving developers using Anthropic’s Claude Desktop a way to check code for security flaws without switching tools.
The integration is built on the Model Context Protocol (MCP), the open standard that lets AI assistants like Claude call out to external services and pull structured data back into a conversation.
Through it, Black Duck’s Signal Code Analysis engine can scan git diffs, individual files, or whole codebases for vulnerabilities directly from within the Claude environment developers are already using to write and refactor code.
Under the hood, source code submitted for a scan is sent to Black Duck’s cloud-based analysis service for processing.
