{
 "categories": [
  "developer-tools",
  "quality-management"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-06",
   "fact": "homepage",
   "note": "Black Duck presents Signal as an agentic AI AppSec product that connects to Claude Code, Google Gemini, and GitHub Copilot via MCP so developers can run security scans in coding assistants. The page treats Signal as complementary to Coverity and Polaris fAST Static, not as a replacement for those tools.",
   "source": "https://www.blackduck.com/signal-ai-appsec.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "license",
   "note": "The official npm package lists a Signal License as a requirement and links it to the Signal Early Access Program. No public free self-serve plan was on the opened product or npm pages.",
   "source": "https://www.npmjs.com/package/@black-duck/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "license",
   "note": "Opened the Early Access Program page linked from the MCP package. It is a sales form for Signal participation details, not a published price list or free tier.",
   "source": "https://www.blackduck.com/signal-ai-appsec/early-access.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "platforms",
   "note": "The package README states cross-platform support on Windows, macOS, and Linux. The product homepage is a web property.",
   "source": "https://www.npmjs.com/package/@black-duck/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "modalities.mcp.first_party",
   "note": "The Black Duck GitHub organization publishes blackducksoftware/mcp-server as AI-powered security analysis through MCP. The README is the Signal MCP install and tool contract.",
   "source": "https://github.com/blackducksoftware/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "modalities.mcp.first_party",
   "note": "npm package @black-duck/mcp-server is authored by Black Duck Inc., version 1.1.8, and tells clients to run npx -y @black-duck/mcp-server with BLACKDUCK_MCP_GATEWAY_KEY. It names Claude, Gemini, Cursor, and Copilot.",
   "source": "https://www.npmjs.com/package/@black-duck/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "modalities.mcp.verdict",
   "note": "The vendor package documents two MCP tools, stdio client JSON, and required env vars. That is an official first-party server, not a community wrapper.",
   "source": "https://www.npmjs.com/package/@black-duck/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "modalities.data_access.export[0]",
   "note": "Both run_changes_security_scan and run_security_scan return sarifFilePath as the scan report path.",
   "source": "https://www.npmjs.com/package/@black-duck/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "verdict.scores.mcp",
   "note": "Official stdio MCP with two scan tools and SARIF output. Coverage is local code scanning only, requires a Signal license and gateway key, and is not a hosted tenant MCP. That is a limited official path.",
   "source": "https://www.npmjs.com/package/@black-duck/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "freshness.watch[0].url",
   "note": "Opened the current @black-duck/mcp-server npm page. Version 1.1.8, last npm update 2026-07-17, documents tools, env vars, Node 24, and the Signal license requirement.",
   "source": "https://www.npmjs.com/package/@black-duck/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "freshness.watch[1].url",
   "note": "Opened the first-party GitHub repository. Description is AI-powered security analysis through MCP. Raw README matches the npm tool table.",
   "source": "https://github.com/blackducksoftware/mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "freshness.watch[2].url",
   "note": "Opened the Signal product page. It markets MCP integration with coding assistants and does not publish a Signal REST API reference.",
   "source": "https://www.blackduck.com/signal-ai-appsec.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-06",
   "fact": "freshness.watch[3].url",
   "note": "Opened the GitHub README. It is the same Signal MCP contract as npm, including tool parameters and the repo.blackduck.com / llm.core.blackduck.com allowlist.",
   "source": "https://raw.githubusercontent.com/blackducksoftware/mcp-server/main/README.md",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-06",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://www.npmjs.com/package/@black-duck/mcp-server"
   },
   {
    "type": "repo",
    "url": "https://github.com/blackducksoftware/mcp-server"
   },
   {
    "type": "docs",
    "url": "https://www.blackduck.com/signal-ai-appsec.html"
   },
   {
    "type": "docs",
    "url": "https://raw.githubusercontent.com/blackducksoftware/mcp-server/main/README.md"
   }
  ]
 },
 "homepage": "https://www.blackduck.com/signal-ai-appsec.html",
 "id": "black-duck-signal",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [],
   "coverage": "unknown",
   "docs": null,
   "exists": "unknown",
   "kinds": []
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "sarif"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Opened vendor pages automate Signal through a local first-party MCP that writes SARIF. They do not establish a Signal web console or classic Black Duck SCA/Hub coverage for this product identity.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Black Duck Signal",
 "platforms": [
  "web",
  "windows",
  "macos",
  "linux"
 ],
 "related": {
  "alternatives": [
   "snyk",
   "semgrep"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Black Duck",
 "verdict": {
  "best_path": "mcp",
  "scores": {
   "api": null,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 6,
   "rpa": null
  },
  "summary": "Black Duck Signal is automatable today through the official Black Duck MCP server. This record is Black Duck Signal agentic AppSec as packaged in @black-duck/mcp-server and blackducksoftware/mcp-server. It is not classic Black Duck SCA/Hub, Checkmarx One, Snyk, or Semgrep. Opened vendor MCP and product pages do not show that this MCP is the Black Duck SCA/Hub API, and they do not publish a public Signal REST API, so API presence stays unknown. The MCP runs locally over stdio as `npx -y @black-duck/mcp-server` and requires BLACKDUCK_MCP_GATEWAY_KEY plus a Signal license. npm still points that license requirement at the Signal Early Access Program page. Node.js 24 or newer is required. Documented tools are run_changes_security_scan (git incremental; all-uncommitted or reference-branch) and run_security_scan (file or directory paths). Both return a SARIF path, issue counts, and analysis guidance. Outbound HTTPS to repo.blackduck.com and llm.core.blackduck.com on port 443 is required. The opened pages do not establish an official Signal CLI, webhooks, or language SDK. iPaaS connector catalogs were not opened. Computer-use viability is unassessed. MCP scores 6 because it is a maintained official server whose public surface is two local scan tools behind a license gate, not a hosted production MCP with tenant issue management.\n"
 }
}