Atlas / MCP servers / chntif / GitLab Workflow

GitLab WorkflowSAFE

mcp/chntif/gitlab-workflow

GitLab MCP: supports creating issues from requirements or modifying code and submitting merge requests from existing issues, while also providing a set of atomic GitLab API tools for issue-driven development. 🚀 | GitLab MCP:支持基于需求创建 Issue,或基于现有 Issue 修改代码并提交 MR,同时提供一系列 GitLab API 原子化操作能力,面向 Issue 开

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
28 15r · 12w · 1d
Transport
stdio
License
MIT
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 简体中文

mcp-gitlab-workflow is an MCP server for issue-driven GitLab development.

It can take a requirement or an existing GitLab issue and drive a standardized delivery flow: requirement analysis, issue creation, branching, coding, merge request creation, and issue updates. It also provides a set of atomic GitLab API tools for custom orchestration and fine-grained control.

1. Core Capabilities

  • workflow_*: higher-level tools that package common requirement-to-delivery flows into a single tool call
  • gitlab_*: atomic GitLab API tools for custom orchestration and fine-grained control

Target projects for issues and code delivery are configured with WORKFLOW_ISSUE_PROJECT_ID and WORKFLOW_CODE_PROJECT_ID. See the environment variable section below for the full configuration matrix.

Workflow Tools

  • workflow_requirement_to_issue: analyze a requirement and create a GitLab issue
  • workflow_review_mr_post_comment: review a target merge request and post a review comment
  • workflow_issue_to_delivery: start from an existing issue and complete branch -> code change -> MR -> issue comment -> issue log
  • workflow_requirement_to_delivery: run the full end-to-end flow from a requirement

Atomic GitLab Tools

Issue tools fall back to WORKFLOW_ISSUE_PROJECT_ID by default, while code and merge request tools fall back to WORKFLOW_CODE_PROJECT_ID.

  • Users and labels: gitlab_get_current_user, gitlab_list_labels, gitlab_create_label, gitlab_update_label, gitlab_delete_label
  • Issues: gitlab_create_issue, gitlab_get_issue, gitlab_get_issue_notes, gitlab_add_issue_comment, gitlab_get_issue_images
  • Repository: gitlab_create_branch, gitlab_get_file, gitlab_commit_files, gitlab_upload_project_file
  • Merge requests: gitlab_get_merge_request, gitlab_get_mr_notes, gitlab_create_merge_request, gitlab_create_mr_note, gitlab_get_mr_changes, `gitlab_approv
Read from source at commit 45cb4c8ff5e4OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-gitlab-workflow -- npx -y @chntif/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-gitlab-workflow": {
      "command": "npx",
      "args": [
        "-y",
        "@chntif/[email protected]"
      ]
    }
  }
}
03

Exposed tools (28)

15 read · 12 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
gitlab_add_issue_commentwrite
gitlab_approve_mrread
gitlab_commit_fileswrite
gitlab_create_branchwrite
gitlab_create_issuewrite
gitlab_create_labelwrite
gitlab_create_merge_requestwrite
gitlab_create_mr_notewrite
gitlab_delete_labeldestructive
gitlab_get_current_userread
gitlab_get_fileread
gitlab_get_issueread
gitlab_get_issue_imagesread
gitlab_get_issue_notesread
gitlab_get_merge_requestwrite
gitlab_get_mr_changesread
gitlab_get_mr_notesread
gitlab_list_labelsread
gitlab_unapprove_mrread
gitlab_update_labelwrite
gitlab_upload_project_filewrite
workflow_issue_log_appendread
workflow_issue_to_deliveryread
workflow_prepare_delivery_workspaceread
workflow_requirement_to_deliveryread
workflow_requirement_to_issueread
workflow_review_mr_post_commentwrite
workflow_sync_local_branchwrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
gitlab_delete_label
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, rimraf, tsx, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 45cb4c8ff5e4full audit observations/trust-audit/mcp-server/chntif__gitlab-workflow.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0845cb4c8ff5e4SAFEB89first audit
06

Questions

What is the GitLab Workflow MCP server?

GitLab MCP: supports creating issues from requirements or modifying code and submitting merge requests from existing issues, while also providing a set of atomic GitLab API tools for issue-driven development. 🚀 | GitLab MCP:支持基于需求创建 Issue,或基于现有 Issue 修改代码并提交 MR,同时提供一系列 GitLab API 原子化操作能力,面向 Issue 开

What tools does GitLab Workflow expose?

28 in total: 15 read-only, 12 that write, and 1 that can delete or overwrite (gitlab_delete_label). Every one is listed on this page with its risk.

Is GitLab Workflow safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GitLab Workflow need?

No credential environment variables were found in its source, so it appears to need none.

How does GitLab Workflow run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @chntif/mcp-gitlab-workflow at 0.1.2.

How current is this page?

The grade is for one exact copy of the source (45cb4c8ff5e4), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement