Atlas / MCP servers / zereight / GitLab

GitLabCAUTION

mcp/zereight/gitlab

First gitlab mcp for you, building together

Verdict
CAUTION
Grade
F
Trust score
54 /100
Exposed tools
200 137r · 121w · 35d
Transport
sse · stdio · streamable-http
License
MIT
Stars
1,998
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/zereight/gitlab-mcp) [](https://www.npmjs.com/package/@zereight/mcp-gitlab) [](https://www.npmjs.com/package/@zereight/mcp-gitlab) [](https://github.com/zereight/gitlab-mcp/blob/main/LICENSE) [](vscode:mcp/install?%7B%22name%22%3A%22zereight.gitlab-mcp%22%2C%22type%22%3A%22stdio%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40zereight%2Fmcp-gitlab%40latest%22%5D%2C%22env%22%3A%7B%22GITLABPERSONALACCESSTOKEN%22%3A%22%24%7Binput%3Agitlab-token%7D%22%2C%22GITLABAPIURL%22%3A%22https%3A%2F%2Fgitlab.com%2Fapi%2Fv4%22%2C%22GITLABPERMISSION_MODE%22%3A%22full%22%7D%7D) [](https://deepwiki.com/zereight/gitlab-mcp) [](https://mcptoplist.com/server/io.github.zereight%2Fgitlab-mcp) [](https://mcpindex.ai/server/io-github-zereight-gitlab-mcp)

English | 한국어 | 简体中文

📖 [Documentation →](https://zereight.github.io/gitlab-mcp/) Setup guides, environment variables, and the full tool reference live on the hosted docs site.

[](https://www.star-history.com/?repos=zereight%2Fgitlab-mcp&type=date&legend=top-left)

@zereight/mcp-gitlab

Agent-workflow-optimized GitLab MCP — manage projects, merge requests, issues, pipelines, wiki, releases, tags, milestones, and more th

Read from source at commit a3e3bcbf574fOBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-gitlab --env GITLAB_PERSONAL_ACCESS_TOKEN=${GITLAB_PERSONAL_ACCESS_TOKEN} --env GITLAB_JOB_TOKEN=${GITLAB_JOB_TOKEN} -- npx -y @zereight/[email protected]
03

Exposed tools (200)

137 read · 121 write · 35 destructive. Blast radius: 35 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
DockerreadBuild Docker images
ProjectFromServer1readMock project from server 1
ProjectFromServer2readMock project from server 2
approve_deploymentreadApprove or reject a protected-environment deployment
approve_merge_requestwriteApprove a merge request
buildreadBuild an image
bulk_publish_draft_noteswritePublish all draft notes for a merge request. Optionally sets reviewer_state and posts a summary note (GitLab 19.2+). Can set reviewer_state even with no drafts.
cancel_pipelinereadCancel a running pipeline
cancel_pipeline_jobreadCancel a running pipeline job
cleanupreadState cleanup and completion
confirm_vulnerabilityreadConfirm a vulnerability as a real finding requiring remediation
convert_work_item_typereadConvert a work item to a different type
create_branchwriteCreate a new branch
create_commit_statuswriteCreate or update the status of a commit
create_deploymentwriteCreate a deployment
create_draft_notewriteCreate a draft note for a merge request
create_groupwriteCreate new group or subgroup
create_group_milestonewriteCreate a new group milestone
create_group_variablewriteCreate a CI/CD variable for a group
create_group_wiki_pagewriteCreate a wiki page in a group
create_issuewriteCreate a new issue
create_issue_emoji_reactionwriteAdd an emoji reaction to an issue (e.g. thumbsup, rocket, eyes)
create_issue_linkwriteCreate an issue link between two issues
create_issue_notewriteAdd a note to an issue, optionally replying to a discussion thread
create_issue_note_emoji_reactionwriteAdd an emoji reaction to an issue note. Pass discussion_id for discussion thread replies.
create_labelwriteCreate a new label in a project
create_merge_requestwriteCreate a new merge request
create_merge_request_discussion_notewriteAdd a new discussion note to an existing merge request thread
create_merge_request_emoji_reactionwriteAdd an emoji reaction to a merge request (e.g. thumbsup, rocket, eyes)
create_merge_request_notewriteAdd a new note to a merge request
create_merge_request_note_emoji_reactionwriteAdd an emoji reaction to a merge request note. Pass discussion_id for discussion thread replies.
create_merge_request_threadwriteCreate a new thread on a merge request
create_milestonewriteCreate a new milestone
create_notewriteCreate a new note (comment) to an issue or merge request
create_or_update_filewriteCreate or update a file in a GitLab project
create_pipelinewriteCreate a new pipeline for a branch or tag
create_pipeline_schedulewriteCreate a new pipeline schedule for a branch or tag
create_pipeline_schedule_variablewriteCreate a variable for a pipeline schedule
create_pipeline_triggerwriteCreate a project pipeline trigger
create_project_variablewriteCreate a CI/CD variable for a project
create_releasewriteCreate a new release
create_release_evidencewriteCreate release evidence (Premium/Ultimate)
create_repositorywriteCreate a new GitLab project
create_tagwriteCreate a new repository tag
create_timeline_eventwriteCreate a timeline event on an incident
create_webhookwriteCreate a webhook on a project or group
create_wiki_pagewriteCreate a wiki page in a project
create_work_itemwriteCreate a work item (issue, task, incident, epic, etc.) with full field support
create_work_item_emoji_reactionwriteAdd an emoji reaction to a work item (e.g. thumbsup, rocket, eyes)
create_work_item_notewriteAdd a note to a work item (supports Markdown, internal notes, threads)
create_work_item_note_emoji_reactionwriteAdd an emoji reaction to a work item note (comment, thread, or thread reply)
delete_branchdestructiveDelete branch from project
delete_deploymentdestructiveDelete a deployment
delete_draft_notedestructiveDelete a draft note
delete_environmentdestructiveDelete a stopped environment
delete_group_milestonedestructiveDelete a group milestone
delete_group_variabledestructiveDelete a CI/CD variable from a group
delete_group_wiki_pagedestructiveDelete a wiki page from a group
delete_issuedestructiveDelete an issue
delete_issue_emoji_reactiondestructiveRemove an emoji reaction from an issue
delete_issue_linkdestructiveDelete an issue link
delete_issue_note_emoji_reactiondestructiveRemove an emoji reaction from an issue note. Pass discussion_id for discussion thread replies.
delete_labeldestructiveDelete a label from a project
delete_merge_request_discussion_notedestructiveDelete a discussion note on a merge request
delete_merge_request_emoji_reactiondestructiveRemove an emoji reaction from a merge request
delete_merge_request_notedestructiveDelete an existing merge request note
delete_merge_request_note_emoji_reactiondestructiveRemove an emoji reaction from a merge request note. Pass discussion_id for discussion thread replies.
delete_milestonedestructiveDelete a milestone
delete_pipelinedestructiveDelete a pipeline. Requires the project Owner role, cannot be undone, and does not automatically delete child pipelines.
delete_pipeline_scheduledestructiveDelete a pipeline schedule
delete_pipeline_schedule_variabledestructiveDelete a variable from a pipeline schedule
delete_pipeline_triggerdestructiveDelete a project pipeline trigger
delete_project_variabledestructiveDelete a CI/CD variable from a project
delete_releasedestructiveDelete a release (does not delete the tag)
delete_review_app_environmentsdestructiveSchedule deletion of stopped review-app environments one week later; dry_run defaults to true and actual scheduling requires dry_run=false
delete_tagdestructiveDelete a repository tag
delete_webhookdestructiveDelete a project or group webhook
delete_wiki_pagedestructiveDelete a wiki page from a project
delete_work_item_emoji_reactiondestructiveRemove an emoji reaction from a work item
delete_work_item_note_emoji_reactiondestructiveRemove an emoji reaction from a work item note (comment, thread, or thread reply)
discover_toolsreadDiscover and activate additional tool categories for this session. Call without arguments to see available categories.
dismiss_vulnerabilityreadDismiss a vulnerability with a reason (acceptable_risk, false_positive, used_in_tests, mitigating_control, not_applicable) and optional comment
edit_group_milestonewriteEdit an existing group milestone
edit_milestonewriteEdit an existing milestone
erase_pipeline_jobdestructiveErase a pipeline job log and artifacts
execute_graphqlwriteExecute a GitLab GraphQL query
executionreadCode implementation
expansionreadRequirements analysis and spec generation
fork_repositoryreadFork a project to your account or specified namespace
get_branchwriteGet branch details (commit, protection status)
get_branch_diffsreadGet diffs between two branches or commits
get_ci_catalog_resourcereadGet details for a GitLab CI/CD Catalog resource, including versions and components
get_commitwriteGet details of a specific commit
get_commit_diffwriteGet changes/diffs of a specific commit
get_dependency_proxy_settingsreadGet dependency proxy settings for a group
get_deploymentreadGet deployment details, including approval_summary, approvals, and pending_approval_count when GitLab provides them
get_draft_notewriteGet a single draft note from a merge request
get_environmentreadGet details of a specific environment
get_file_blamereadGet git blame for a file at a given ref. Each entry maps a contiguous range of source lines to the commit that last changed them (id, author, authored_date, message). Use range_start/range_end to limit blame to specific lines.
get_file_contentsreadGet contents of a file or directory from a GitLab project
get_group_milestonereadGet details of a specific group milestone
get_group_milestone_burndown_eventsreadGet burndown events for a specific group milestone
get_group_milestone_issuereadGet issues associated with a specific group milestone
get_group_milestone_merge_requestswriteGet merge requests associated with a specific group milestone
get_group_variablereadGet a single CI/CD variable from a group
get_group_wiki_pagereadGet details of a specific group wiki page
get_issuewriteGet details of a specific issue. Returns a slim milestone by default; set full_response=true for the complete milestone object
get_issue_linkreadGet a specific issue link
get_job_artifact_filereadGet content of a single file from a job
get_labelreadGet a single label from a project
get_merge_requestwriteGet details of a merge request (mergeRequestIid or branchName required). Set include_summaries=true for deployment/commit/approval summaries
get_merge_request_approval_statewriteGet merge request approval details including approvers
get_merge_request_conflictswriteGet the conflicts of a merge request
get_merge_request_diffswriteGet the changes/diffs of a merge request (mergeRequestIid or branchName required)
get_merge_request_discussionwriteGet a single discussion item for a merge request
get_merge_request_file_diffwriteGet diffs for specific files from a merge request (mergeRequestIid or branchName required)
get_merge_request_notewriteGet a specific note for a merge request
get_merge_request_noteswriteList notes for a merge request
get_merge_request_versionwriteGet a specific version of a merge request
get_milestonereadGet details of a specific milestone
get_milestone_burndown_eventsreadGet burndown events for a specific milestone
get_milestone_issuereadGet issues associated with a specific milestone
get_milestone_merge_requestswriteGet merge requests associated with a specific milestone
get_namespacereadGet details of a namespace (user or group) by ID or path. Groups are namespaces with kind=
get_pipelinereadGet details of a specific pipeline
get_pipeline_jobreadGet details of a GitLab pipeline job number
get_pipeline_job_outputreadGet the output/trace of a pipeline job with optional pagination
get_pipeline_schedulewriteGet details of a specific pipeline schedule, including its variables and last pipeline
get_pipeline_schedule_variablewriteGet a single variable of a pipeline schedule
get_pipeline_test_reportreadGet pipeline test report
get_pipeline_test_report_summaryreadGet pipeline test report summary
get_pipeline_triggerwriteGet a project pipeline trigger
get_pipeline_variablesreadGet variables configured for a pipeline
get_projectreadGet details of a specific project
get_project_eventsreadList events for a project (before/after: YYYY-MM-DD)
get_project_variablereadGet a single CI/CD variable from a project
get_protected_branchdestructiveGet details of a single protected branch (access levels, force push settings)
get_releasereadGet a release by tag name
get_repository_treereadList files and directories in a repository
get_tagreadGet a repository tag by name
get_tag_signaturereadGet the X.509 signature of a signed tag (404 if unsigned)
get_timeline_eventsreadList timeline events for an incident
get_userreadGet user details by ID
get_usersreadGet GitLab user details by usernames
get_vulnerabilityreadGet full details of a specific vulnerability
get_webhook_eventreadGet full details of a specific webhook event
get_wiki_pagereadGet details of a specific wiki page
get_work_itemreadGet a work item with full details including status, hierarchy, type, and widgets
health_checkreadVerify server status and authentication. Always reports the MCP server version (mcp_server_version). When authenticated, also reports the GitLab instance version from GET /api/v4/version (version, revision, enterprise). Version lookup failures do not fail the health check — those fields are omitted.
imagereadImage name
list_branchesreadList branches in project with search filter
list_ci_catalog_resourcesreadList GitLab CI/CD Catalog resources/components visible to the user
list_commit_statuseswriteList statuses for a commit
list_commitsreadList repository commits with filtering options
list_custom_field_definitionsreadList custom field definitions for a work item type
list_dependency_proxy_blobsreadList cached dependency proxy blobs for a group
list_deployment_merge_requestswriteList merge requests shipped with a deployment
list_deploymentsreadList deployments with filtering options
list_draft_noteswriteList draft notes for a merge request
list_environmentsreadList environments in a project
list_eventsreadList events for the authenticated user (before/after: YYYY-MM-DD)
list_group_iterationsreadList group iterations with filtering options
list_group_membersreadList members of a GitLab group with optional name or username search
list_group_merge_requestswriteList merge requests across all projects of a group and its subgroups
list_group_milestonesreadList group milestones with filtering options
list_group_projectsreadList projects in a group
list_group_variablesreadList CI/CD variables for a group
list_group_wiki_pagesreadList wiki pages in a group
list_issue_discussionsreadList discussions for an issue
list_issue_emoji_reactionsreadList all emoji reactions on an issue
list_issue_linksreadList all issue links for a specific issue
list_issue_note_emoji_reactionsreadList all emoji reactions on an issue note. Pass discussion_id for discussion thread replies.
list_issuesreadList issues (default: created by current user; use scope=
list_job_artifactsreadList artifact files in a job
list_labelsreadList labels for a project
list_merge_request_changed_fileswriteList changed file paths in a merge request without diff content (mergeRequestIid or branchName required)
list_merge_request_diffswriteList merge request diffs with pagination (mergeRequestIid or branchName required)
list_merge_request_emoji_reactionswriteList all emoji reactions on a merge request
list_merge_request_note_emoji_reactionswriteList all emoji reactions on a merge request note. Pass discussion_id for discussion thread replies.
list_merge_request_pipelineswriteList pipelines for a merge request with pagination
list_merge_request_versionswriteList all versions of a merge request
list_merge_requestswriteList merge requests (without project_id: user
list_milestonesreadList milestones with filtering options
list_namespacesreadList all namespaces (users and groups) available to the current user. Filter by kind=
list_pipeline_jobsreadList all jobs in a specific pipeline
list_pipeline_schedule_pipelineswriteList the pipelines that a pipeline schedule has triggered
list_pipeline_schedulesreadList pipeline schedules in a project, optionally filtered to active or inactive
list_pipeline_trigger_jobswriteList trigger jobs (bridges) in a pipeline
list_pipeline_triggerswriteList project pipeline trigger tokens
list_pipelinesreadList pipelines with filtering options
list_project_membersreadList members of a GitLab project
list_project_variablesreadList CI/CD variables for a project
list_project_vulnerabilitiesreadList vulnerabilities for a project with optional state, severity, and report type filters (GraphQL-backed, cursor pagination)
list_projectsreadList projects accessible by the current user
list_protected_branchesreadList protected branches in a project, supports search filter
list_releasesreadList all releases for a project
list_tagsreadList repository tags for a project
list_todosreadList GitLab to-do items for the current user
list_webhook_eventsreadList recent webhook events (past 7 days)
list_webhooksreadList webhooks for a project or group
04

Trust audit

CAUTIONgrade F · trust 54/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
index.ts:15504
logger.info(`Session ${sessionId}: stored OAuth token (client: ${authInfo.clientId})`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
oauth-proxy.ts:625
logger.error(`Token exchange failed (${response.status}): ${body}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
oauth-proxy.ts:723
logger.error(`Token refresh failed (${response.status}): ${body}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
oauth-proxy.ts:874
logger.error(`Callback token exchange failed (${tokenResponse.status}): ${body}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
oauth.ts:264
logger.info(`Token saved to ${this.tokenStoragePath}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:22
# GITLAB_OAUTH_REDIRECT_URI=http://127.0.0.1:8888/callback
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Makefile:25
serve: install ## Preview docs at http://127.0.0.1:8000 (auto-reload)
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/stateless/session-id.test.ts:38
token: "glpat-ABCDEFG123456789-abcdef",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/stateless/session-id.test.ts:52
token: "glpat-ABCDEFG123456789-abcdef",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/stateless/session-id.test.ts:66
token: "glpat-ABCDEFG123456789-abcdef",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/stateless/session-id.test.ts:82
token: "some-token-value-at-least-20-chars",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_branch, delete_deployment, delete_draft_note, delete_environment, delete_group_milestone, delete_group_variable, delete_group_wiki_page, delete_issue, delete_issue_emoji_reaction, delete_issue_
Why it matters. 35 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.envrc
.envrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitlab-mcp-managed-policy.example.json
.gitlab-mcp-managed-policy.example.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitlab-mcp-mask.example.json
.gitlab-mcp-mask.example.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docker/masking-config/.gitlab-mcp-mask.json
.gitlab-mcp-mask.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/test/run-tests.mjs:32
assert.throws(() => validateMode("../../etc"), /Invalid mode name/);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/test/run-tests.mjs:150
assert.throws(() => getStatePath("../../etc"), /Invalid mode name/);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/version.ts:12
path.resolve(__dirname, "../../package.json"),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/path-segment-encoding.test.ts:72
const payload = "../../user";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/path-segment-encoding.test.ts:88
"../../../user",
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
test/stateless/callback-proxy.test.ts:38
const CALLBACK_URL = "https://mcp.example.com/callback";
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
test/stateless/callback-proxy.test.ts:67
callbackProxy ? CALLBACK_URL : "",
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
test/stateless/callback-proxy.test.ts:355
assert.equal(stub.calls[0].body.redirect_uri, CALLBACK_URL);

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha a3e3bcbf574ffull audit observations/trust-audit/mcp-server/zereight__gitlab.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-23a3e3bcbf574fCAUTIONF54score 56 -> 54
2026-09-19f75f9ef33ca3CAUTIONF56first audit
06

Questions

What is the GitLab MCP server?

First gitlab mcp for you, building together

What tools does GitLab expose?

200 in total: 137 read-only, 121 that write, and 35 that can delete or overwrite (delete_branch, delete_deployment, delete_draft_note, delete_environment, delete_group_milestone). Every one is listed on this page with its risk.

Is GitLab safe to connect to an agent?

With care. The audit graded it F (54/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 35 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GitLab need?

It reads DOWNLOAD_TOKEN_SECRET, DOWNLOAD_TOKEN_TTL, GH_TOKEN, GITHUB_TOKEN, GITLAB_JOB_TOKEN, GITLAB_OAUTH_CLIENT_ID, GITLAB_OAUTH_CLIENT_SECRET, GITLAB_OAUTH_REDIRECT_URI, GITLAB_OAUTH_TOKEN_PATH, GITLAB_OAUTH_TOKEN_SCRIPT, GITLAB_OAUTH_TOKEN_SCRIPT_TIMEOUT_SECONDS and GITLAB_PERSONAL_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does GitLab run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @zereight/mcp-gitlab at 2.1.65.

How current is this page?

The grade is for one exact copy of the source (a3e3bcbf574f), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement