GitLab WorkflowSAFE
GitLab MCP: supports creating issues from requirements or modifying code and submitting merge requests from existing issues, while also providing a set of atomic GitLab API tools for issue-driven development. 🚀 | GitLab MCP:支持基于需求创建 Issue,或基于现有 Issue 修改代码并提交 MR,同时提供一系列 GitLab API 原子化操作能力,面向 Issue 开
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 简体中文
mcp-gitlab-workflow is an MCP server for issue-driven GitLab development.
It can take a requirement or an existing GitLab issue and drive a standardized delivery flow: requirement analysis, issue creation, branching, coding, merge request creation, and issue updates. It also provides a set of atomic GitLab API tools for custom orchestration and fine-grained control.
1. Core Capabilities
workflow_*: higher-level tools that package common requirement-to-delivery flows into a single tool callgitlab_*: atomic GitLab API tools for custom orchestration and fine-grained control
Target projects for issues and code delivery are configured with WORKFLOW_ISSUE_PROJECT_ID and WORKFLOW_CODE_PROJECT_ID. See the environment variable section below for the full configuration matrix.
Workflow Tools
workflow_requirement_to_issue: analyze a requirement and create a GitLab issueworkflow_review_mr_post_comment: review a target merge request and post a review commentworkflow_issue_to_delivery: start from an existing issue and complete branch -> code change -> MR -> issue comment -> issue logworkflow_requirement_to_delivery: run the full end-to-end flow from a requirement
Atomic GitLab Tools
Issue tools fall back to WORKFLOW_ISSUE_PROJECT_ID by default, while code and merge request tools fall back to WORKFLOW_CODE_PROJECT_ID.
- Users and labels:
gitlab_get_current_user,gitlab_list_labels,gitlab_create_label,gitlab_update_label,gitlab_delete_label - Issues:
gitlab_create_issue,gitlab_get_issue,gitlab_get_issue_notes,gitlab_add_issue_comment,gitlab_get_issue_images - Repository:
gitlab_create_branch,gitlab_get_file,gitlab_commit_files,gitlab_upload_project_file - Merge requests:
gitlab_get_merge_request,gitlab_get_mr_notes,gitlab_create_merge_request,gitlab_create_mr_note,gitlab_get_mr_changes, `gitlab_approv
45cb4c8ff5e4OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-gitlab-workflow -- npx -y @chntif/[email protected]
{
"mcpServers": {
"mcp-gitlab-workflow": {
"command": "npx",
"args": [
"-y",
"@chntif/[email protected]"
]
}
}
}Exposed tools (28)
15 read · 12 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
gitlab_add_issue_comment | write | |
gitlab_approve_mr | read | |
gitlab_commit_files | write | |
gitlab_create_branch | write | |
gitlab_create_issue | write | |
gitlab_create_label | write | |
gitlab_create_merge_request | write | |
gitlab_create_mr_note | write | |
gitlab_delete_label | destructive | |
gitlab_get_current_user | read | |
gitlab_get_file | read | |
gitlab_get_issue | read | |
gitlab_get_issue_images | read | |
gitlab_get_issue_notes | read | |
gitlab_get_merge_request | write | |
gitlab_get_mr_changes | read | |
gitlab_get_mr_notes | read | |
gitlab_list_labels | read | |
gitlab_unapprove_mr | read | |
gitlab_update_label | write | |
gitlab_upload_project_file | write | |
workflow_issue_log_append | read | |
workflow_issue_to_delivery | read | |
workflow_prepare_delivery_workspace | read | |
workflow_requirement_to_delivery | read | |
workflow_requirement_to_issue | read | |
workflow_review_mr_post_comment | write | |
workflow_sync_local_branch | write |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
gitlab_delete_label
@modelcontextprotocol/sdk, zod, @types/node, rimraf, tsx, typescript
Gates applied: no_behavioural_pass.
45cb4c8ff5e4full audit observations/trust-audit/mcp-server/chntif__gitlab-workflow.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 45cb4c8ff5e4 | SAFE | B | 89 | first audit |
Questions
What is the GitLab Workflow MCP server?
GitLab MCP: supports creating issues from requirements or modifying code and submitting merge requests from existing issues, while also providing a set of atomic GitLab API tools for issue-driven development. 🚀 | GitLab MCP:支持基于需求创建 Issue,或基于现有 Issue 修改代码并提交 MR,同时提供一系列 GitLab API 原子化操作能力,面向 Issue 开
What tools does GitLab Workflow expose?
28 in total: 15 read-only, 12 that write, and 1 that can delete or overwrite (gitlab_delete_label). Every one is listed on this page with its risk.
Is GitLab Workflow safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does GitLab Workflow need?
No credential environment variables were found in its source, so it appears to need none.
How does GitLab Workflow run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @chntif/mcp-gitlab-workflow at 0.1.2.
How current is this page?
The grade is for one exact copy of the source (45cb4c8ff5e4), read on 2026-10-08. The repository is watched and re-audited when it changes.