GitLabCAUTION
Production-grade GitLab MCP server with 86 tools — full GitLab control from any AI agent (Claude, Cursor, Zed).
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The most comprehensive Model Context Protocol (MCP) server for GitLab — 86 tools, enterprise-ready, actively maintained.
What it is
GitLab MCP Server lets an AI agent (Claude Desktop, Claude Code, Cursor, Zed, VS Code, or any [Model Context Proto
dd2254ff34ecOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add gitlab-mcp-server --env AUTH_MODE=${AUTH_MODE} --env GITLAB_PERSONAL_ACCESS_TOKEN=${GITLAB_PERSONAL_ACCESS_TOKEN} --env GITLAB_ROOT_PASSWORD=${GITLAB_ROOT_PASSWORD} -- npx -y @yoda.digital/[email protected]{
"mcpServers": {
"gitlab-mcp-server": {
"command": "npx",
"args": [
"-y",
"@yoda.digital/[email protected]"
],
"env": {
"AUTH_MODE": "${AUTH_MODE}",
"GITLAB_PERSONAL_ACCESS_TOKEN": "${GITLAB_PERSONAL_ACCESS_TOKEN}",
"GITLAB_ROOT_PASSWORD": "${GITLAB_ROOT_PASSWORD}"
}
}
}
}Exposed tools (89)
44 read · 39 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
approve_merge_request | write | Approve a merge request |
cancel_auto_merge | write | Cancel auto-merge for a merge request |
cancel_job | read | Cancel a running job |
cancel_pipeline | read | Cancel a running pipeline |
compare_branches | read | Compare two branches, tags, or commits |
create_branch | write | Create a new branch in a GitLab project |
create_group | write | Create a new GitLab group |
create_group_wiki_page | write | Create a new wiki page for a GitLab group |
create_issue | write | Create a new issue in a GitLab project |
create_issue_note | write | Add a comment to an issue |
create_label | write | Create a new label in a GitLab project |
create_merge_request | write | Create a new merge request in a GitLab project |
create_merge_request_discussion | write | Create a new discussion on a merge request |
create_merge_request_note | write | Add a comment to a merge request |
create_milestone | write | Create a new milestone in a GitLab project |
create_or_update_file | write | Create or update a single file in a GitLab project |
create_project_wiki_page | write | Create a new wiki page for a GitLab project |
create_release | write | Create a new release for a GitLab project |
create_repository | write | Create a new GitLab project |
create_tag | write | Create a new tag in a GitLab project |
delete_branch | destructive | Delete a branch from a GitLab project |
delete_group | destructive | Delete a GitLab group |
delete_group_wiki_page | destructive | Delete a wiki page from a GitLab group |
delete_project_wiki_page | destructive | Delete a wiki page from a GitLab project |
edit_group_wiki_page | write | Edit an existing wiki page for a GitLab group |
edit_project_wiki_page | write | Edit an existing wiki page for a GitLab project |
fork_repository | read | Fork a GitLab project to your account or specified namespace |
get_current_user | read | Get details of the currently authenticated user |
get_environment | read | Get details of a specific environment |
get_file_contents | read | Get the contents of a file or directory from a GitLab project |
get_group | read | Get details of a specific group |
get_group_wiki_page | read | Get a specific wiki page for a GitLab group |
get_job | read | Get details of a specific job |
get_job_log | read | Get the raw log/trace output of a job |
get_job_log_smart | read | Get a job |
get_merge_request_changes | write | Get the changes/diffs for a merge request |
get_merge_request_commits | write | Get the commits for a merge request |
get_pipeline | read | Get details of a specific pipeline |
get_pipeline_summary | read | Get a complete pipeline investigation summary: pipeline details, jobs grouped by stage, and log tails for failed jobs — all in one call |
get_project | read | Get details of a GitLab project |
get_project_events | read | Get recent events/activities for a GitLab project |
get_project_wiki_page | read | Get a specific wiki page for a GitLab project |
get_repository_tree | read | Get the repository file tree |
get_user | read | Get details of a specific user |
list_branches | read | List branches for a GitLab project |
list_commits | write | Get commit history for a GitLab project |
list_environments | read | List environments for a GitLab project |
list_group_members | read | List all members of a GitLab group (including inherited members) |
list_group_projects | read | List all projects (repositories) within a specific GitLab group |
list_group_subgroups | read | List subgroups of a group |
list_group_wiki_pages | read | List all wiki pages for a GitLab group |
list_groups | read | List GitLab groups |
list_issue_discussions | read | Fetch all discussions (threaded comments) for a GitLab issue |
list_issue_notes | read | Fetch all comments and system notes for a GitLab issue |
list_issues | read | Get issues for a GitLab project |
list_labels | read | List labels for a GitLab project |
list_merge_request_discussions | write | List all discussions (threaded comments) on a merge request |
list_merge_request_notes | write | List all comments and notes on a merge request |
list_merge_requests | write | Get merge requests for a GitLab project |
list_milestones | read | List milestones for a GitLab project |
list_pipeline_jobs | read | List jobs for a specific pipeline. Use scope=[ |
list_pipelines | read | List pipelines for a GitLab project |
list_project_members | read | List all members of a GitLab project (including inherited members) |
list_project_wiki_pages | read | List all wiki pages for a GitLab project |
list_protected_branches | read | List protected branches for a GitLab project |
list_releases | read | List releases for a GitLab project |
list_tags | read | List tags for a GitLab project |
list_users | read | List GitLab users |
merge_merge_request | write | Merge a merge request |
protect_branch | read | Protect a branch in a GitLab project |
push_files | write | Push multiple files to a GitLab project in a single commit |
rebase_merge_request | write | Rebase a merge request onto the target branch |
retry_job | read | Retry a failed job |
retry_pipeline | read | Retry failed jobs in a pipeline |
search_repositories | read | Search for GitLab projects |
set_auto_merge | write | Set a merge request to merge when pipeline succeeds (auto-merge) |
test_tool | read | Tool for ${token} |
trigger_pipeline | write | Trigger a new pipeline for a branch or tag |
unapprove_merge_request | destructive | Remove your approval from a merge request |
unprotect_branch | destructive | Remove protection from a branch |
update_group | write | Update a GitLab group |
update_issue | write | Update an existing issue |
update_label | write | Update an existing label |
update_merge_request | write | Update an existing merge request |
update_merge_request_note | write | Edit a comment on a merge request |
update_milestone | write | Update an existing milestone |
update_project | write | Update a GitLab project |
upload_group_wiki_attachment | write | Upload an attachment to a GitLab group wiki |
upload_project_wiki_attachment | write | Upload an attachment to a GitLab project wiki |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
CMD wget --quiet --tries=1 --spider http://127.0.0.1:${PORT:-3000}/livez || exit 1delete_branch, delete_group, delete_group_wiki_page, delete_project_wiki_page, unapprove_merge_request, unprotect_branch
.trivyignore
.helmignore
export MCP_SERVER_URL=http://127.0.0.1:3000
curl -sf http://127.0.0.1:3000/livez && echo " [server live]"
export MCP_SERVER_URL=http://127.0.0.1:3000
export MCP_SERVER_URL=http://127.0.0.1:3000
@modelcontextprotocol/sdk, node-fetch, @types/node, tsx, typescript, vitest
@modelcontextprotocol/sdk, cors, express, node-fetch, zod, zod-to-json-schema, @types/cors, @types/express
Streamable HTTP runs `POST /mcp`, `GET /mcp`, and `DELETE /mcp`, with session management via the `MCP-Session-Id` header. The `/healthz` endpoint returns 503 when active sessions exceed `HEALTHZ_MAX_S
Gates applied: no_behavioural_pass.
dd2254ff34ecfull audit observations/trust-audit/mcp-server/yoda-digital__gitlab-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | dd2254ff34ec | CAUTION | B | 89 | first audit |
Questions
What is the GitLab MCP server?
Production-grade GitLab MCP server with 86 tools — full GitLab control from any AI agent (Claude, Cursor, Zed).
What tools does GitLab expose?
89 in total: 44 read-only, 39 that write, and 6 that can delete or overwrite (delete_branch, delete_group, delete_group_wiki_page, delete_project_wiki_page, unapprove_merge_request). Every one is listed on this page with its risk.
Is GitLab safe to connect to an agent?
With care. The audit graded it B (89/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does GitLab need?
It reads AUTH_MODE, GITLAB_PERSONAL_ACCESS_TOKEN and GITLAB_ROOT_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does GitLab run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @yoda.digital/gitlab-mcp-server at 0.9.1.
How current is this page?
The grade is for one exact copy of the source (dd2254ff34ec), read on 2026-10-07. The repository is watched and re-audited when it changes.