{"generated_at":"2026-09-18T12:54:00+00:00","item":{"added_at":"2026-07-30T07:10:45.087000+00:00","analysis_method":"capability_triage","category":"Desktop Extension","description":"AI-powered security vulnerability scanning via Black Duck Signal.","did":"ant-dir-gh-blackducksoftware-mcp-server","homepage_url":"","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.blackducksoftware.mcp-server/versions/1.1.8-push.1/icon.png","id":"ant.dir.gh.blackducksoftware.mcp-server","installs":0,"last_scanned":"","license":"","long_description":"Black Duck MCP brings Signal's AI-powered security analysis directly into Claude Desktop. Scan git changes, individual files, or full projects for security vulnerabilities. Results are exposed as MCP resources for detailed AI-driven analysis. Note: scanned source content is transmitted to Black Duck's remote analysis endpoint for processing.","name":"Black Duck Security Scanner","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-gh-blackducksoftware-mcp-server&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"","publisher_url":"","repository_url":"","risk":"medium","risk_severity":"medium","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"The desktop extension scans local git changes/files/projects and explicitly transmits source content to Black Duck’s remote analysis endpoint.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"The desktop extension scans local git changes/files/projects and explicitly transmits source content to Black Duck’s remote analysis endpoint.","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["desktop_extension","filesystem_access","forwards_data_to_third_party","network_access","reads_private_data"],"tools":[{"description":"","name":"run_changes_security_scan"},{"description":"","name":"run_security_scan"}],"tools_count":2,"type":"desktop_extension","url":"","uuid":"3b405b41-d49b-59ec-ab5c-fe8473ccbbac","version":"1.1.8-push.1"},"query_key":"black duck security scanner","schema_version":1,"status":"match"}
