Atlas / MCP servers / jmrplens / gitlab-mcp-server

gitlab-mcp-serverBLOCK

mcp/jmrplens/gitlab-mcp-server

Open source GitLab MCP server for AI assistants: 2-tool dynamic find/execute over 850+ GitLab actions (1,000+ Enterprise), stdio/HTTP/OAuth, safe/read-only modes.

Verdict
BLOCK
Grade
F
Trust score
43 /100
Exposed tools
20 16r · 4w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
43
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/jmrplens/gitlab-mcp-server/releases/latest) [](https://www.npmjs.com/package/@jmrp.io/gitlab-mcp-server) [](https://pypi.org/project/jmrplens-gitlab-mcp-server/) [](https://www.nuget.org/packages/gitlab-mcp-server) [](LICENSE) [](https://github.com/jmrplens/gitlab-mcp-server/actions/workflows/ci.yml) [](https://sonarcloud.io/summary/overall?id=jmrplensgitlab-mcp-server) [](https://sonarcloud.io/summary/overall?id=jmrplensgitlab-mcp-server) [](https://pkg.go.dev/github.com/jmrplens/gitlab-mcp-server/v3)

[![Glama MCP Score](https://glama.ai/mcp/servers/jm

Read from source at commit 3adbf13ee328OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add gitlab-mcp-server:3.1.0@sha256:87e483299a2663a7a5d4d28679859b0c7fba2b1a421b7de2652441a569d4a2fc --env GITLAB_TOKEN=${GITLAB_TOKEN} --env GITLAB_TOKEN=${GITLAB_TOKEN} --env GITLAB_TOKEN=${GITLAB_TOKEN} --env GITLAB_TOKEN=${GITLAB_TOKEN} -- docker run -i --rm ghcr.io/jmrplens/gitlab-mcp-server:3.1.0@sha256:87e483299a2663a7a5d4d28679859b0c7fba2b1a421b7de2652441a569d4a2fc:None
claude-code (oci)
claude mcp add gitlab-mcp-server:3.1.0@sha256:87e483299a2663a7a5d4d28679859b0c7fba2b1a421b7de2652441a569d4a2fc --env GITLAB_TOKEN=${GITLAB_TOKEN} --env GITLAB_TOKEN=${GITLAB_TOKEN} --env GITLAB_TOKEN=${GITLAB_TOKEN} --env GITLAB_TOKEN=${GITLAB_TOKEN} -- docker run -i --rm docker.io/jmrplens/gitlab-mcp-server:3.1.0@sha256:87e483299a2663a7a5d4d28679859b0c7fba2b1a421b7de2652441a569d4a2fc:None
03

Exposed tools (20)

16 read · 4 write · 0 destructive.

ToolRiskDescription
bothreadprod-fleet
case_insensitivereadOne of Enabled or DISABLED
code_reviewwriteCode review checklist and best practices for GitLab merge request reviews.
conventional_commitswriteConventional commit message format and examples for consistent Git history.
emptyread
git_workflowreadBest practices for Git branching strategies with GitLab (feature branches, trunk-based, GitLab Flow).
givenreadissued for the staging cluster
guidance_heading_with_no_bulletsreadUse {\
header_with_no_bodyreadUse {\
integersreadAccess level (0=No access 30=Developer 40=Maintainer)
listedreadPackage ecosystem: cargo, composer, or npm
merge_request_hygienewriteGuidelines for creating and reviewing high-quality merge requests.
negated_sentence_skippedreadAccess level (10=Guest, 20=Reporter). 5 and 60 are not valid for shares
negation_after_semicolonreadone of red or blue; green is invalid
omittedread
pipeline_troubleshootingreadCommon GitLab CI/CD pipeline issues and how to diagnose and fix them.
premiumreadEvaluate a package (Premium, experimental). Returns: the verdict.
ultimatereadRead a project
usage_example_without_the_schema_hintreadUse {\
whole_tokens_onlywriteset npm_token before use
04

Trust audit

BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (8 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cmd/audit_supply_chain/make.go:36
`|exec(?:[ \t]+-[cl]+)*|command(?:[ \t]+-p)?|nohup|time(?:[ \t]+-p)?` +
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
internal/tools/applications/applications.go:33
CallbackURL     string   `json:"callback_url"`
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Makefile:2444
@echo "Serving local Go documentation at http://127.0.0.1:6060"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Makefile:2498
ALLOWED_ORIGINS="http://localhost:6274,http://127.0.0.1:6274,http://0.0.0.0:6274" \
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cmd/gen_graphql_schema/main_test.go:801
const token = "glpat-not-a-real-token"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cmd/internal/auditshared/audit_shared_test.go:193
const token = "caller-chosen-stub-token"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cmd/server/auth_gate_test.go:2950
token    = "glpat-rejected-token-" + loggedTokenTail
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cmd/server/recover_test.go:29
const secret = "glpat-secret-in-the-panic-message"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/oauth/cache_test.go:407
token     = "glpat-same-string-on-both"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
cmd/server/probe_test.go:381
if err := os.WriteFile(noCert, []byte("-----BEGIN PRIVATE KEY-----\nAA==\n-----END PRIVATE KEY-----\n"), 0o600); err != nil {
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
internal/tools/pages/pages_test.go:768
Key:         "-----BEGIN PRIVATE KEY-----\nfake\n-----END PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
internal/tools/pages/pages_test.go:801
Key:            "-----BEGIN PRIVATE KEY-----\ncreated key\n-----END PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
internal/tools/pages/pages_test.go:807
"key":              "-----BEGIN PRIVATE KEY-----\ncreated key\n-----END PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
internal/tools/pages/pages_test.go:877
Key:         "-----BEGIN PRIVATE KEY-----\nfake\n-----END PRIVATE KEY-----",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coderabbit.yaml
.coderabbit.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitguardian.yaml
.gitguardian.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mailmap
.mailmap
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint-cli2.yaml
.markdownlint-cli2.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
.claude/agents/debug.agent.md
.claude/agents/debug.agent.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
.claude/agents/documentation-writer.agent.md
.claude/agents/documentation-writer.agent.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
.claude/agents/go-mcp-expert.agent.md
.claude/agents/go-mcp-expert.agent.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
.claude/agents/go-source-documenter.agent.md
.claude/agents/go-source-documenter.agent.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
.claude/agents/plan-expert.agent.md
.claude/agents/plan-expert.agent.md
Why it matters. link not followed
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cmd/audit_1to1/internal/sdk/analyze_test.go:214
func Mutate(c *gl.Client) error { return exec(c.GraphQL) }
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cmd/audit_1to1/internal/sdk/analyze_test.go:217
func exec(g gl.GraphQLInterface) error {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 3adbf13ee328full audit observations/trust-audit/mcp-server/jmrplens__gitlab-mcp-server.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-083adbf13ee328BLOCKF43first audit
06

Questions

What is the gitlab-mcp-server MCP server?

Open source GitLab MCP server for AI assistants: 2-tool dynamic find/execute over 850+ GitLab actions (1,000+ Enterprise), stdio/HTTP/OAuth, safe/read-only modes.

What tools does gitlab-mcp-server expose?

20 in total: 16 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is gitlab-mcp-server safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (43/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does gitlab-mcp-server need?

It reads GITLAB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does gitlab-mcp-server run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @jmrp.io/gitlab-mcp-server at 3.1.0.

How current is this page?

The grade is for one exact copy of the source (3adbf13ee328), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement