Atlas / MCP servers / yoda-digital / GitLab

GitLabCAUTION

mcp/yoda-digital/gitlab-1

Production-grade GitLab MCP server with 86 tools — full GitLab control from any AI agent (Claude, Cursor, Zed).

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
89 44r · 39w · 6d
Transport
sse · stdio · streamable-http
License
MIT
Stars
64
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The most comprehensive Model Context Protocol (MCP) server for GitLab — 86 tools, enterprise-ready, actively maintained.

What it is

GitLab MCP Server lets an AI agent (Claude Desktop, Claude Code, Cursor, Zed, VS Code, or any [Model Context Proto

Read from source at commit dd2254ff34ecOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add gitlab-mcp-server --env AUTH_MODE=${AUTH_MODE} --env GITLAB_PERSONAL_ACCESS_TOKEN=${GITLAB_PERSONAL_ACCESS_TOKEN} --env GITLAB_ROOT_PASSWORD=${GITLAB_ROOT_PASSWORD} -- npx -y @yoda.digital/[email protected]
claude-desktop
{
  "mcpServers": {
    "gitlab-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@yoda.digital/[email protected]"
      ],
      "env": {
        "AUTH_MODE": "${AUTH_MODE}",
        "GITLAB_PERSONAL_ACCESS_TOKEN": "${GITLAB_PERSONAL_ACCESS_TOKEN}",
        "GITLAB_ROOT_PASSWORD": "${GITLAB_ROOT_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (89)

44 read · 39 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
approve_merge_requestwriteApprove a merge request
cancel_auto_mergewriteCancel auto-merge for a merge request
cancel_jobreadCancel a running job
cancel_pipelinereadCancel a running pipeline
compare_branchesreadCompare two branches, tags, or commits
create_branchwriteCreate a new branch in a GitLab project
create_groupwriteCreate a new GitLab group
create_group_wiki_pagewriteCreate a new wiki page for a GitLab group
create_issuewriteCreate a new issue in a GitLab project
create_issue_notewriteAdd a comment to an issue
create_labelwriteCreate a new label in a GitLab project
create_merge_requestwriteCreate a new merge request in a GitLab project
create_merge_request_discussionwriteCreate a new discussion on a merge request
create_merge_request_notewriteAdd a comment to a merge request
create_milestonewriteCreate a new milestone in a GitLab project
create_or_update_filewriteCreate or update a single file in a GitLab project
create_project_wiki_pagewriteCreate a new wiki page for a GitLab project
create_releasewriteCreate a new release for a GitLab project
create_repositorywriteCreate a new GitLab project
create_tagwriteCreate a new tag in a GitLab project
delete_branchdestructiveDelete a branch from a GitLab project
delete_groupdestructiveDelete a GitLab group
delete_group_wiki_pagedestructiveDelete a wiki page from a GitLab group
delete_project_wiki_pagedestructiveDelete a wiki page from a GitLab project
edit_group_wiki_pagewriteEdit an existing wiki page for a GitLab group
edit_project_wiki_pagewriteEdit an existing wiki page for a GitLab project
fork_repositoryreadFork a GitLab project to your account or specified namespace
get_current_userreadGet details of the currently authenticated user
get_environmentreadGet details of a specific environment
get_file_contentsreadGet the contents of a file or directory from a GitLab project
get_groupreadGet details of a specific group
get_group_wiki_pagereadGet a specific wiki page for a GitLab group
get_jobreadGet details of a specific job
get_job_logreadGet the raw log/trace output of a job
get_job_log_smartreadGet a job
get_merge_request_changeswriteGet the changes/diffs for a merge request
get_merge_request_commitswriteGet the commits for a merge request
get_pipelinereadGet details of a specific pipeline
get_pipeline_summaryreadGet a complete pipeline investigation summary: pipeline details, jobs grouped by stage, and log tails for failed jobs — all in one call
get_projectreadGet details of a GitLab project
get_project_eventsreadGet recent events/activities for a GitLab project
get_project_wiki_pagereadGet a specific wiki page for a GitLab project
get_repository_treereadGet the repository file tree
get_userreadGet details of a specific user
list_branchesreadList branches for a GitLab project
list_commitswriteGet commit history for a GitLab project
list_environmentsreadList environments for a GitLab project
list_group_membersreadList all members of a GitLab group (including inherited members)
list_group_projectsreadList all projects (repositories) within a specific GitLab group
list_group_subgroupsreadList subgroups of a group
list_group_wiki_pagesreadList all wiki pages for a GitLab group
list_groupsreadList GitLab groups
list_issue_discussionsreadFetch all discussions (threaded comments) for a GitLab issue
list_issue_notesreadFetch all comments and system notes for a GitLab issue
list_issuesreadGet issues for a GitLab project
list_labelsreadList labels for a GitLab project
list_merge_request_discussionswriteList all discussions (threaded comments) on a merge request
list_merge_request_noteswriteList all comments and notes on a merge request
list_merge_requestswriteGet merge requests for a GitLab project
list_milestonesreadList milestones for a GitLab project
list_pipeline_jobsreadList jobs for a specific pipeline. Use scope=[
list_pipelinesreadList pipelines for a GitLab project
list_project_membersreadList all members of a GitLab project (including inherited members)
list_project_wiki_pagesreadList all wiki pages for a GitLab project
list_protected_branchesreadList protected branches for a GitLab project
list_releasesreadList releases for a GitLab project
list_tagsreadList tags for a GitLab project
list_usersreadList GitLab users
merge_merge_requestwriteMerge a merge request
protect_branchreadProtect a branch in a GitLab project
push_fileswritePush multiple files to a GitLab project in a single commit
rebase_merge_requestwriteRebase a merge request onto the target branch
retry_jobreadRetry a failed job
retry_pipelinereadRetry failed jobs in a pipeline
search_repositoriesreadSearch for GitLab projects
set_auto_mergewriteSet a merge request to merge when pipeline succeeds (auto-merge)
test_toolreadTool for ${token}
trigger_pipelinewriteTrigger a new pipeline for a branch or tag
unapprove_merge_requestdestructiveRemove your approval from a merge request
unprotect_branchdestructiveRemove protection from a branch
update_groupwriteUpdate a GitLab group
update_issuewriteUpdate an existing issue
update_labelwriteUpdate an existing label
update_merge_requestwriteUpdate an existing merge request
update_merge_request_notewriteEdit a comment on a merge request
update_milestonewriteUpdate an existing milestone
update_projectwriteUpdate a GitLab project
upload_group_wiki_attachmentwriteUpload an attachment to a GitLab group wiki
upload_project_wiki_attachmentwriteUpload an attachment to a GitLab project wiki
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:45
CMD wget --quiet --tries=1 --spider http://127.0.0.1:${PORT:-3000}/livez || exit 1
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_branch, delete_group, delete_group_wiki_page, delete_project_wiki_page, unapprove_merge_request, unprotect_branch
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.trivyignore
.trivyignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
chart/.helmignore
.helmignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONTRIBUTING.md:226
export MCP_SERVER_URL=http://127.0.0.1:3000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/plans/2026-05-18-full-resolution-megasession.md:749
curl -sf http://127.0.0.1:3000/livez && echo " [server live]"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/plans/2026-05-18-full-resolution-megasession.md:762
export MCP_SERVER_URL=http://127.0.0.1:3000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/plans/2026-05-18-full-resolution-megasession.md:919
export MCP_SERVER_URL=http://127.0.0.1:3000
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
e2e/package.json
@modelcontextprotocol/sdk, node-fetch, @types/node, tsx, typescript, vitest
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, cors, express, node-fetch, zod, zod-to-json-schema, @types/cors, @types/express
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:131
Streamable HTTP runs `POST /mcp`, `GET /mcp`, and `DELETE /mcp`, with session management via the `MCP-Session-Id` header. The `/healthz` endpoint returns 503 when active sessions exceed `HEALTHZ_MAX_S
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha dd2254ff34ecfull audit observations/trust-audit/mcp-server/yoda-digital__gitlab-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07dd2254ff34ecCAUTIONB89first audit
06

Questions

What is the GitLab MCP server?

Production-grade GitLab MCP server with 86 tools — full GitLab control from any AI agent (Claude, Cursor, Zed).

What tools does GitLab expose?

89 in total: 44 read-only, 39 that write, and 6 that can delete or overwrite (delete_branch, delete_group, delete_group_wiki_page, delete_project_wiki_page, unapprove_merge_request). Every one is listed on this page with its risk.

Is GitLab safe to connect to an agent?

With care. The audit graded it B (89/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GitLab need?

It reads AUTH_MODE, GITLAB_PERSONAL_ACCESS_TOKEN and GITLAB_ROOT_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does GitLab run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @yoda.digital/gitlab-mcp-server at 0.9.1.

How current is this page?

The grade is for one exact copy of the source (dd2254ff34ec), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement