Vinkius
Black Duck

Black Duck MCP. Audit open source risks instantly from your IDE.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Black Duck (Synopsys) MCP on Cursor AI Code Editor MCP Client Black Duck (Synopsys) MCP on Claude Desktop App MCP Integration Black Duck (Synopsys) MCP on OpenAI Agents SDK MCP Compatible Black Duck (Synopsys) MCP on Visual Studio Code MCP Extension Client Black Duck (Synopsys) MCP on GitHub Copilot AI Agent MCP Integration Black Duck (Synopsys) MCP on Google Gemini AI MCP Integration Black Duck (Synopsys) MCP on Lovable AI Development MCP Client Black Duck (Synopsys) MCP on Mistral AI Agents MCP Compatible Black Duck (Synopsys) MCP on Amazon AWS Bedrock MCP Support

Just plug in your AI agents and start using Vinkius.

Black Duck (Synopsys) connects your open source supply chain security directly into any AI agent. Check project metadata, audit code dependencies for known CVEs, and track compliance status without leaving your editor.

It gives you a single pane of glass view over all your software assets and licenses.

What your AI agents can do

Get bom status

Checks if a project's Bill of Materials (BOM) calculation is up to date for a specific version.

Get project

Retrieves detailed metadata about one specific software project by name or ID.

Get vulnerability details

Fetches the precise technical details for a known CVE or vulnerability identifier.

+ 7 more capabilities included
Search for software assets

Find specific projects by name or browse the entire catalog of known Black Duck projects.

Check project metadata

Retrieve deep details about a specific software project, including its current status and versions.

Track vulnerabilities by version

List all known vulnerabilities (CVEs) linked to an entire project's dependency tree for quick risk assessment.

Audit security policies

View and audit the exact security policy rules currently defined across your organization’s codebases.

Monitor compliance status

Verify if a project's Bill of Materials (BOM) calculation is current, ensuring up-to-date compliance data for reporting.

Supported MCP Clients

OAuth 2.0 Compatible
Vinkius runs on Claude Claude
Vinkius runs on ChatGPT ChatGPT
Vinkius runs on Cursor Cursor
Vinkius runs on Gemini Gemini
Vinkius runs on VS Code VS Code
Vinkius runs on JetBrains JetBrains
Vinkius runs on Vercel Vercel
Vinkius runs on Zendesk Zendesk
+ other MCP clients
Free for Subscribers

Waiting for input…

AI Agent

Black Duck (Synopsys) MCP - 10 Tools

Use these tools to run specific security audits on projects, check policy status, find vulnerable dependencies, and retrieve project metadata.

Make your AI actually useful.

Add this MCP to Claude, Cursor, or Windsurf and your AI stops guessing. It gets real tools to look things up, take action, and handle the stuff you keep doing by hand.

Start using Black Duck (Synopsys) on Vinkius
get019d755d

get bom status

Checks if a project's Bill of Materials (BOM) calculation is up to date for a specific version.

get019d755d

get project

Retrieves detailed metadata about one specific software project by name or ID.

get019d755d

get vulnerability details

Fetches the precise technical details for a known CVE or vulnerability identifier.

list019d755d

list code locations

Lists every location within your codebase that was scanned by Black Duck's security tools.

list019d755d

list policy rules

Retrieves a list of all security and compliance policies defined for the organization.

list019d755d

list project versions

Lists every available version number for a single project.

list019d755d

list projects

Returns a complete list of all Black Duck projects managed in the system.

list019d755d

list users

Lists all user accounts and profiles within the Black Duck platform.

list019d755d

list vulnerabilities

Generates a list of all identified vulnerabilities for an entire project version range.

search019d755d

search projects

Searches and filters the project database based on keywords or partial names.

Choose How to Get Started

Build a custom MCP for your own tools, or connect a ready-made integration from our catalog.

Build Your Own

Turn any API into an MCP. Import a spec, define Agent Skills, or deploy with MCPFusion.

  • Import from OpenAPI, Swagger, or YAML specs
  • Create Agent Skills with progressive disclosure
  • Deploy to edge with MCPFusion framework
  • Built in DLP, auth, and compliance on every call
  • Real time usage dashboard and cost metering
  • Publish to catalog or keep private
Start building

Make Your AI Do More

Start with Black Duck (Synopsys), then connect any of our 4,800+ other servers whenever your AI needs more. One click, no limits.

  • Use this MCP plus 4,800+ others, all in one place
  • Add new capabilities to your AI anytime you want
  • Every connection is secured and compliant automatically
  • Track usage and costs across all your servers
  • Works with Claude, ChatGPT, Cursor, and more
  • New servers added to the catalog every week
Black Duck MCP server cover

Independent Platform Disclaimer: Vinkius is an independent platform and is not affiliated with, endorsed by, sponsored by, verified by, or otherwise authorized by Black Duck (Synopsys). All third-party trademarks, logos, and brand names are the property of their respective owners. Their use on this website is strictly for informational purposes to identify service compatibility and interoperability.

VINKIUS INFRASTRUCTURE

Cloud Hosted

Managed infra

V8 Isolated

Sandboxed per request

Zero-Trust Proxy

No stored credentials

DLP Enforced

Policy on every call

GDPR Compliant

EU data residency

Token Compression

~60% cost reduction

Your data is protected. See how we built it.

Works with Claude, ChatGPT, Cursor, and more

The Model Context Protocol standardizes how applications expose capabilities to LLMs. Instead of operating in isolation, your AI gains direct access to external platforms, live data, and real-world actions through secure, standardized connections.

This server provides 10 capabilities that interface natively with Claude, ChatGPT, Cursor, and any MCP client. No middleware. No custom integration required.

Manual audits force you into a cycle of dashboards and exports.

Today, checking open-source risk means navigating multiple tabs: first finding the project, then listing all versions to see which build is vulnerable, then exporting that list to Excel so your team can manually cross-reference against policy rules. It's slow and prone to copy/paste errors.

With this MCP, you tell your agent exactly what you need—for example, 'List all projects with critical CVEs.' The agent handles the whole sequence of checks, pulling data from multiple sources in one query. You get a clean, actionable list that requires zero manual cleanup.

Using `list_project_versions` for precise tracking.

Previously, if you wanted to check a specific dependency's status, you had to guess which version was the most accurate and then click through several layers of menus just to see a list of available versions. It's guesswork based on UI labels.

Now, running `list_project_versions` gives your agent a definitive, structured list of every single version ID for that project. That precision lets you target vulnerability checks exactly where they need to go.

What you can do with this MCP connector

Managing the risk in modern open-source code is a nightmare if you rely on dashboards. You need to know exactly which projects are vulnerable, what their dependencies are, and whether they meet policy standards—all while moving fast. This MCP lets your AI client talk directly to Black Duck’s core security data.

Instead of exporting reports or clicking through dozens of tabs, you just ask the question: 'What's wrong with Project X?' Your agent handles the complex queries for project versions, vulnerability details, and compliance status immediately. It pulls together all that critical metadata so you can act on it right away.

This capability is hosted and managed by Vinkius, giving your agent access to thousands of specialized connectors across every industry.

Built · Hosted · Managed by Vinkius Black Duck MCP - Open Source Security & Compliance Server ID 019d755d-f2ec-70e4-962b-2b66dd956dd0
Vinkius Inspector
Compliance Grade A+
Score 100/100
Vinkius Inspector Badge — Score 100/100

Common Questions About Black Duck MCP

How do I check if my BOM is ready using get_bom_status? +

You run get_bom_status and it returns the current compliance status. If the result isn't 'UP_TO_DATE', you know your data needs manual review before deployment.

Which tool should I use to see all my projects? +

Use list_projects. It returns a complete list of every managed project ID. If you need more detail on one, follow up with get_project using the returned name.

Can I find out why a specific vulnerability exists? Use get_vulnerability_details. +

Yes, use get_vulnerability_details. You feed it the CVE ID and it pulls the technical write-up, severity rating, and exploit details instantly.

I need to see all policies. Should I use list_policy_rules? +

Yes, list_policy_rules is your go-to tool. It gives you a comprehensive rundown of every security rule currently active within the system.

How do I use `list_users` to audit who has access or manage user accounts? +

It provides a full list of all Black Duck users configured in your instance. You can use this output to audit which profiles have read/write permissions across the platform.

I need comprehensive metadata for one project; what does `get_project` provide? +

get_project returns detailed information about a single software asset. This includes overall status, associated compliance details, and key identifiers beyond just the name.

I know vulnerabilities exist for my project; how do I pinpoint exactly where they are located using `list_code_locations`? +

list_code_locations returns specific file paths within your codebase. This lets you track the exact location of a vulnerability or scan finding, which is critical for developers.

Before running vulnerability checks, how do I use `list_project_versions` to see all available versions? +

list_project_versions fetches an exhaustive list of every version recorded for a specific project. This ensures you are checking the security status against the correct build number.

Built & Managed by Vinkius 30s setup 10 tools

We've already built the connector for Black Duck. Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 10 tools are live and waiting. You're up and running in seconds.

Vinkius runs on Claude Claude
Vinkius runs on ChatGPT ChatGPT
Vinkius runs on Cursor Cursor
Vinkius runs on Gemini Gemini
Vinkius runs on Windsurf Windsurf
Vinkius runs on VS Code VS Code
Vinkius runs on JetBrains JetBrains
Vinkius runs on Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.