Can AI agents automate Black Duck Signal?
Black Duck · saas · developer-toolsquality-management
Black Duck Signal is automatable today through the official Black Duck MCP server. This record is Black Duck Signal agentic AppSec as packaged in @black-duck/mcp-server and blackducksoftware/mcp-server. It is not classic Black Duck SCA/Hub, Checkmarx One, Snyk, or Semgrep. Opened vendor MCP and product pages do not show that this MCP is the Black Duck SCA/Hub API, and they do not publish a public Signal REST API, so API presence stays unknown. The MCP runs locally over stdio as `npx -y @black-duck/mcp-server` and requires BLACKDUCK_MCP_GATEWAY_KEY plus a Signal license. npm still points that license requirement at the Signal Early Access Program page. Node.js 24 or newer is required. Documented tools are run_changes_security_scan (git incremental; all-uncommitted or reference-branch) and run_security_scan (file or directory paths). Both return a SARIF path, issue counts, and analysis guidance. Outbound HTTPS to repo.blackduck.com and llm.core.blackduck.com on port 443 is required. The opened pages do not establish an official Signal CLI, webhooks, or language SDK. iPaaS connector catalogs were not opened. Computer-use viability is unassessed. MCP scores 6 because it is a maintained official server whose public surface is two local scan tools behind a license gate, not a hosted production MCP with tenant issue management.
Best path today: mcp · Overall automatability: 6/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | unknown | coverage: unknown |
| SDK | unknown | official: unknown |
| MCP | yes | verdict: official |
| Integrations | unknown | |
| CLI | unknown | |
| Extensibility | unknown | webhooks: unknown |
| Data access | export: sarif · import: unknown | |
| RPA / UI automation | unknown | No repeatable UI probe was run. Opened vendor pages automate Signal through a local first-party MCP that writes SARIF. They do not establish a Signal web console or classic Black Duck SCA/Hub coverage for this product identity.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| — | 6 | — | — | — | — | 6 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-09-06 |
license | declared | source | 2026-09-06 |
license | declared | source | 2026-09-06 |
platforms | declared | source | 2026-09-06 |
modalities.mcp.first_party | declared | source | 2026-09-06 |
modalities.mcp.first_party | declared | source | 2026-09-06 |
modalities.mcp.verdict | declared | source | 2026-09-06 |
modalities.data_access.export[0] | declared | source | 2026-09-06 |
verdict.scores.mcp | declared | source | 2026-09-06 |
freshness.watch[0].url | declared | source | 2026-09-06 |
freshness.watch[1].url | declared | source | 2026-09-06 |
freshness.watch[2].url | declared | source | 2026-09-06 |
freshness.watch[3].url | declared | source | 2026-09-06 |
Related tools
Other products in this database that share a category with Black Duck Signal.
Last verified 2026-09-06 · volatility high · JSON record