started · updated
Black Duck integrates Signal vulnerability scanning into Claude
Black Duck has launched its Signal vulnerability scanning engine as an MCP server within the Claude Directory. This integration allows developers using Anthropic’s Claude Desktop to perform security checks directly within their AI-assisted coding environment.
Utilizing the Model Context Protocol (MCP), the Signal Code Analysis engine can scan individual files, git diffs, or entire codebases. The source code is processed via Black Duck’s cloud-based analysis service, and the results are returned as structured MCP resources. This enables Claude to interpret the findings, explain identified risks, and suggest remediation steps in natural language.
Dipto Chakravarty, Chief Product & Technology Officer at Black Duck, stated that the integration aims to ensure security keeps pace with the increased speed of development provided by AI coding tools. The service is intended to embed vulnerability detection at the point of code generation and review, rather than relying on post-merge scans.