
Application security company Black Duck has added its Signal engine to the Claude Directory, Anthropic’s marketplace of tools that Claude can call on directly during a conversation. The move lets anyone using Claude Desktop ask the assistant to scan code for vulnerabilities without opening a separate application, one more example of specialist enterprise software being rebuilt to sit inside an AI agent’s workflow rather than alongside it.
The integration runs on the Model Context Protocol, or MCP, the increasingly standard way for AI assistants to reach outside their own training and call real, live services. In this case, that means Claude can send a set of code changes, a file, or an entire project off to Black Duck’s Signal Code Analysis engine, get back a structured report of any security flaws, and then talk the developer through what was found and how to fix it, all inside the same chat window used to write the code in the first place.
What makes the launch notable isn’t the scanning itself, which Black Duck has offered in various forms for years, but where it now happens. As AI coding assistants take on more of the actual writing of software, the tools built to check that software for problems are being pulled into the same conversational interface. Rather than a developer finishing a coding session and then switching to a separate security dashboard, the check becomes another thing they can simply ask Claude to do.
Black Duck’s Chief Product & Technology Officer, Dipto Chakravarty, tied the release directly to the speed at which AI-assisted development now moves, arguing that the point of the integration is to make sure “security keeps pace with how fast teams are building.”
That framing captures a tension a lot of enterprises are currently sitting with. AI coding tools have made it dramatically faster to produce working software, but the processes built to govern that software, security review chief among them, were largely designed for a slower pace of human-written code. Vendors across the AppSec market are racing to fold their products into AI-native workflows before that gap becomes a liability rather than a talking point.
It’s also a small case study in what the Claude Directory is turning into. Since Anthropic opened the door for outside companies to publish MCP servers that Claude can use, the directory has steadily filled with tools spanning project management, data analysis, and now application security, each betting that being reachable from inside an AI assistant will matter more, over time, than being a destination in its own right.
Signal is live in the Claude Directory now, though Black Duck says organisations wanting to deploy it should go through a company representative rather than a simple self-serve install, a reminder that even as these tools get easier to reach, the enterprise sales motion behind them hasn’t gone anywhere.



