gitlab-mcp-serverBLOCK
Open source GitLab MCP server for AI assistants: 2-tool dynamic find/execute over 850+ GitLab actions (1,000+ Enterprise), stdio/HTTP/OAuth, safe/read-only modes.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/jmrplens/gitlab-mcp-server/releases/latest) [](https://www.npmjs.com/package/@jmrp.io/gitlab-mcp-server) [](https://pypi.org/project/jmrplens-gitlab-mcp-server/) [](https://www.nuget.org/packages/gitlab-mcp-server) [](LICENSE) [](https://github.com/jmrplens/gitlab-mcp-server/actions/workflows/ci.yml) [](https://sonarcloud.io/summary/overall?id=jmrplensgitlab-mcp-server) [](https://sonarcloud.io/summary/overall?id=jmrplensgitlab-mcp-server) [](https://pkg.go.dev/github.com/jmrplens/gitlab-mcp-server/v3)
[
16 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
both | read | prod-fleet |
case_insensitive | read | One of Enabled or DISABLED |
code_review | write | Code review checklist and best practices for GitLab merge request reviews. |
conventional_commits | write | Conventional commit message format and examples for consistent Git history. |
empty | read | |
git_workflow | read | Best practices for Git branching strategies with GitLab (feature branches, trunk-based, GitLab Flow). |
given | read | issued for the staging cluster |
guidance_heading_with_no_bullets | read | Use {\ |
header_with_no_body | read | Use {\ |
integers | read | Access level (0=No access 30=Developer 40=Maintainer) |
listed | read | Package ecosystem: cargo, composer, or npm |
merge_request_hygiene | write | Guidelines for creating and reviewing high-quality merge requests. |
negated_sentence_skipped | read | Access level (10=Guest, 20=Reporter). 5 and 60 are not valid for shares |
negation_after_semicolon | read | one of red or blue; green is invalid |
omitted | read | |
pipeline_troubleshooting | read | Common GitLab CI/CD pipeline issues and how to diagnose and fix them. |
premium | read | Evaluate a package (Premium, experimental). Returns: the verdict. |
ultimate | read | Read a project |
usage_example_without_the_schema_hint | read | Use {\ |
whole_tokens_only | write | set npm_token before use |
Trust audit
BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
`|exec(?:[ \t]+-[cl]+)*|command(?:[ \t]+-p)?|nohup|time(?:[ \t]+-p)?` +
CallbackURL string `json:"callback_url"`
@echo "Serving local Go documentation at http://127.0.0.1:6060"
ALLOWED_ORIGINS="http://localhost:6274,http://127.0.0.1:6274,http://0.0.0.0:6274" \
const token = "glpat-not-a-real-token"
const token = "caller-chosen-stub-token"
token = "glpat-rejected-token-" + loggedTokenTail
const secret = "glpat-secret-in-the-panic-message"
token = "glpat-same-string-on-both"
if err := os.WriteFile(noCert, []byte("-----BEGIN PRIVATE KEY-----\nAA==\n-----END PRIVATE KEY-----\n"), 0o600); err != nil {Key: "-----BEGIN PRIVATE KEY-----\nfake\n-----END PRIVATE KEY-----",
Key: "-----BEGIN PRIVATE KEY-----\ncreated key\n-----END PRIVATE KEY-----",
"key": "-----BEGIN PRIVATE KEY-----\ncreated key\n-----END PRIVATE KEY-----",
Key: "-----BEGIN PRIVATE KEY-----\nfake\n-----END PRIVATE KEY-----",
.coderabbit.yaml
.gitguardian.yaml
.mailmap
.markdownlint-cli2.yaml
.claude/agents/debug.agent.md
.claude/agents/documentation-writer.agent.md
.claude/agents/go-mcp-expert.agent.md
.claude/agents/go-source-documenter.agent.md
.claude/agents/plan-expert.agent.md
func Mutate(c *gl.Client) error { return exec(c.GraphQL) }func exec(g gl.GraphQLInterface) error {Gates applied: no_behavioural_pass.
3adbf13ee328full audit observations/trust-audit/mcp-server/jmrplens__gitlab-mcp-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3adbf13ee328 | BLOCK | F | 43 | first audit |
Questions
What is the gitlab-mcp-server MCP server?
Open source GitLab MCP server for AI assistants: 2-tool dynamic find/execute over 850+ GitLab actions (1,000+ Enterprise), stdio/HTTP/OAuth, safe/read-only modes.
What tools does gitlab-mcp-server expose?
20 in total: 16 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is gitlab-mcp-server safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (43/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does gitlab-mcp-server need?
It reads GITLAB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does gitlab-mcp-server run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @jmrp.io/gitlab-mcp-server at 3.1.0.
How current is this page?
The grade is for one exact copy of the source (3adbf13ee328), read on 2026-10-08. The repository is watched and re-audited when it changes.