GitLabCAUTION
First gitlab mcp for you, building together
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/zereight/gitlab-mcp) [](https://www.npmjs.com/package/@zereight/mcp-gitlab) [](https://www.npmjs.com/package/@zereight/mcp-gitlab) [](https://github.com/zereight/gitlab-mcp/blob/main/LICENSE) [](vscode:mcp/install?%7B%22name%22%3A%22zereight.gitlab-mcp%22%2C%22type%22%3A%22stdio%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40zereight%2Fmcp-gitlab%40latest%22%5D%2C%22env%22%3A%7B%22GITLABPERSONALACCESSTOKEN%22%3A%22%24%7Binput%3Agitlab-token%7D%22%2C%22GITLABAPIURL%22%3A%22https%3A%2F%2Fgitlab.com%2Fapi%2Fv4%22%2C%22GITLABPERMISSION_MODE%22%3A%22full%22%7D%7D) [](https://deepwiki.com/zereight/gitlab-mcp) [](https://mcptoplist.com/server/io.github.zereight%2Fgitlab-mcp) [](https://mcpindex.ai/server/io-github-zereight-gitlab-mcp)
English | 한국어 | 简体中文
📖 [Documentation →](https://zereight.github.io/gitlab-mcp/) Setup guides, environment variables, and the full tool reference live on the hosted docs site.
[](https://www.star-history.com/?repos=zereight%2Fgitlab-mcp&type=date&legend=top-left)
@zereight/mcp-gitlab
Agent-workflow-optimized GitLab MCP — manage projects, merge requests, issues, pipelines, wiki, releases, tags, milestones, and more th
a3e3bcbf574fOBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-gitlab --env GITLAB_PERSONAL_ACCESS_TOKEN=${GITLAB_PERSONAL_ACCESS_TOKEN} --env GITLAB_JOB_TOKEN=${GITLAB_JOB_TOKEN} -- npx -y @zereight/[email protected]Exposed tools (200)
137 read · 121 write · 35 destructive. Blast radius: 35 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Docker | read | Build Docker images |
ProjectFromServer1 | read | Mock project from server 1 |
ProjectFromServer2 | read | Mock project from server 2 |
approve_deployment | read | Approve or reject a protected-environment deployment |
approve_merge_request | write | Approve a merge request |
build | read | Build an image |
bulk_publish_draft_notes | write | Publish all draft notes for a merge request. Optionally sets reviewer_state and posts a summary note (GitLab 19.2+). Can set reviewer_state even with no drafts. |
cancel_pipeline | read | Cancel a running pipeline |
cancel_pipeline_job | read | Cancel a running pipeline job |
cleanup | read | State cleanup and completion |
confirm_vulnerability | read | Confirm a vulnerability as a real finding requiring remediation |
convert_work_item_type | read | Convert a work item to a different type |
create_branch | write | Create a new branch |
create_commit_status | write | Create or update the status of a commit |
create_deployment | write | Create a deployment |
create_draft_note | write | Create a draft note for a merge request |
create_group | write | Create new group or subgroup |
create_group_milestone | write | Create a new group milestone |
create_group_variable | write | Create a CI/CD variable for a group |
create_group_wiki_page | write | Create a wiki page in a group |
create_issue | write | Create a new issue |
create_issue_emoji_reaction | write | Add an emoji reaction to an issue (e.g. thumbsup, rocket, eyes) |
create_issue_link | write | Create an issue link between two issues |
create_issue_note | write | Add a note to an issue, optionally replying to a discussion thread |
create_issue_note_emoji_reaction | write | Add an emoji reaction to an issue note. Pass discussion_id for discussion thread replies. |
create_label | write | Create a new label in a project |
create_merge_request | write | Create a new merge request |
create_merge_request_discussion_note | write | Add a new discussion note to an existing merge request thread |
create_merge_request_emoji_reaction | write | Add an emoji reaction to a merge request (e.g. thumbsup, rocket, eyes) |
create_merge_request_note | write | Add a new note to a merge request |
create_merge_request_note_emoji_reaction | write | Add an emoji reaction to a merge request note. Pass discussion_id for discussion thread replies. |
create_merge_request_thread | write | Create a new thread on a merge request |
create_milestone | write | Create a new milestone |
create_note | write | Create a new note (comment) to an issue or merge request |
create_or_update_file | write | Create or update a file in a GitLab project |
create_pipeline | write | Create a new pipeline for a branch or tag |
create_pipeline_schedule | write | Create a new pipeline schedule for a branch or tag |
create_pipeline_schedule_variable | write | Create a variable for a pipeline schedule |
create_pipeline_trigger | write | Create a project pipeline trigger |
create_project_variable | write | Create a CI/CD variable for a project |
create_release | write | Create a new release |
create_release_evidence | write | Create release evidence (Premium/Ultimate) |
create_repository | write | Create a new GitLab project |
create_tag | write | Create a new repository tag |
create_timeline_event | write | Create a timeline event on an incident |
create_webhook | write | Create a webhook on a project or group |
create_wiki_page | write | Create a wiki page in a project |
create_work_item | write | Create a work item (issue, task, incident, epic, etc.) with full field support |
create_work_item_emoji_reaction | write | Add an emoji reaction to a work item (e.g. thumbsup, rocket, eyes) |
create_work_item_note | write | Add a note to a work item (supports Markdown, internal notes, threads) |
create_work_item_note_emoji_reaction | write | Add an emoji reaction to a work item note (comment, thread, or thread reply) |
delete_branch | destructive | Delete branch from project |
delete_deployment | destructive | Delete a deployment |
delete_draft_note | destructive | Delete a draft note |
delete_environment | destructive | Delete a stopped environment |
delete_group_milestone | destructive | Delete a group milestone |
delete_group_variable | destructive | Delete a CI/CD variable from a group |
delete_group_wiki_page | destructive | Delete a wiki page from a group |
delete_issue | destructive | Delete an issue |
delete_issue_emoji_reaction | destructive | Remove an emoji reaction from an issue |
delete_issue_link | destructive | Delete an issue link |
delete_issue_note_emoji_reaction | destructive | Remove an emoji reaction from an issue note. Pass discussion_id for discussion thread replies. |
delete_label | destructive | Delete a label from a project |
delete_merge_request_discussion_note | destructive | Delete a discussion note on a merge request |
delete_merge_request_emoji_reaction | destructive | Remove an emoji reaction from a merge request |
delete_merge_request_note | destructive | Delete an existing merge request note |
delete_merge_request_note_emoji_reaction | destructive | Remove an emoji reaction from a merge request note. Pass discussion_id for discussion thread replies. |
delete_milestone | destructive | Delete a milestone |
delete_pipeline | destructive | Delete a pipeline. Requires the project Owner role, cannot be undone, and does not automatically delete child pipelines. |
delete_pipeline_schedule | destructive | Delete a pipeline schedule |
delete_pipeline_schedule_variable | destructive | Delete a variable from a pipeline schedule |
delete_pipeline_trigger | destructive | Delete a project pipeline trigger |
delete_project_variable | destructive | Delete a CI/CD variable from a project |
delete_release | destructive | Delete a release (does not delete the tag) |
delete_review_app_environments | destructive | Schedule deletion of stopped review-app environments one week later; dry_run defaults to true and actual scheduling requires dry_run=false |
delete_tag | destructive | Delete a repository tag |
delete_webhook | destructive | Delete a project or group webhook |
delete_wiki_page | destructive | Delete a wiki page from a project |
delete_work_item_emoji_reaction | destructive | Remove an emoji reaction from a work item |
delete_work_item_note_emoji_reaction | destructive | Remove an emoji reaction from a work item note (comment, thread, or thread reply) |
discover_tools | read | Discover and activate additional tool categories for this session. Call without arguments to see available categories. |
dismiss_vulnerability | read | Dismiss a vulnerability with a reason (acceptable_risk, false_positive, used_in_tests, mitigating_control, not_applicable) and optional comment |
edit_group_milestone | write | Edit an existing group milestone |
edit_milestone | write | Edit an existing milestone |
erase_pipeline_job | destructive | Erase a pipeline job log and artifacts |
execute_graphql | write | Execute a GitLab GraphQL query |
execution | read | Code implementation |
expansion | read | Requirements analysis and spec generation |
fork_repository | read | Fork a project to your account or specified namespace |
get_branch | write | Get branch details (commit, protection status) |
get_branch_diffs | read | Get diffs between two branches or commits |
get_ci_catalog_resource | read | Get details for a GitLab CI/CD Catalog resource, including versions and components |
get_commit | write | Get details of a specific commit |
get_commit_diff | write | Get changes/diffs of a specific commit |
get_dependency_proxy_settings | read | Get dependency proxy settings for a group |
get_deployment | read | Get deployment details, including approval_summary, approvals, and pending_approval_count when GitLab provides them |
get_draft_note | write | Get a single draft note from a merge request |
get_environment | read | Get details of a specific environment |
get_file_blame | read | Get git blame for a file at a given ref. Each entry maps a contiguous range of source lines to the commit that last changed them (id, author, authored_date, message). Use range_start/range_end to limit blame to specific lines. |
get_file_contents | read | Get contents of a file or directory from a GitLab project |
get_group_milestone | read | Get details of a specific group milestone |
get_group_milestone_burndown_events | read | Get burndown events for a specific group milestone |
get_group_milestone_issue | read | Get issues associated with a specific group milestone |
get_group_milestone_merge_requests | write | Get merge requests associated with a specific group milestone |
get_group_variable | read | Get a single CI/CD variable from a group |
get_group_wiki_page | read | Get details of a specific group wiki page |
get_issue | write | Get details of a specific issue. Returns a slim milestone by default; set full_response=true for the complete milestone object |
get_issue_link | read | Get a specific issue link |
get_job_artifact_file | read | Get content of a single file from a job |
get_label | read | Get a single label from a project |
get_merge_request | write | Get details of a merge request (mergeRequestIid or branchName required). Set include_summaries=true for deployment/commit/approval summaries |
get_merge_request_approval_state | write | Get merge request approval details including approvers |
get_merge_request_conflicts | write | Get the conflicts of a merge request |
get_merge_request_diffs | write | Get the changes/diffs of a merge request (mergeRequestIid or branchName required) |
get_merge_request_discussion | write | Get a single discussion item for a merge request |
get_merge_request_file_diff | write | Get diffs for specific files from a merge request (mergeRequestIid or branchName required) |
get_merge_request_note | write | Get a specific note for a merge request |
get_merge_request_notes | write | List notes for a merge request |
get_merge_request_version | write | Get a specific version of a merge request |
get_milestone | read | Get details of a specific milestone |
get_milestone_burndown_events | read | Get burndown events for a specific milestone |
get_milestone_issue | read | Get issues associated with a specific milestone |
get_milestone_merge_requests | write | Get merge requests associated with a specific milestone |
get_namespace | read | Get details of a namespace (user or group) by ID or path. Groups are namespaces with kind= |
get_pipeline | read | Get details of a specific pipeline |
get_pipeline_job | read | Get details of a GitLab pipeline job number |
get_pipeline_job_output | read | Get the output/trace of a pipeline job with optional pagination |
get_pipeline_schedule | write | Get details of a specific pipeline schedule, including its variables and last pipeline |
get_pipeline_schedule_variable | write | Get a single variable of a pipeline schedule |
get_pipeline_test_report | read | Get pipeline test report |
get_pipeline_test_report_summary | read | Get pipeline test report summary |
get_pipeline_trigger | write | Get a project pipeline trigger |
get_pipeline_variables | read | Get variables configured for a pipeline |
get_project | read | Get details of a specific project |
get_project_events | read | List events for a project (before/after: YYYY-MM-DD) |
get_project_variable | read | Get a single CI/CD variable from a project |
get_protected_branch | destructive | Get details of a single protected branch (access levels, force push settings) |
get_release | read | Get a release by tag name |
get_repository_tree | read | List files and directories in a repository |
get_tag | read | Get a repository tag by name |
get_tag_signature | read | Get the X.509 signature of a signed tag (404 if unsigned) |
get_timeline_events | read | List timeline events for an incident |
get_user | read | Get user details by ID |
get_users | read | Get GitLab user details by usernames |
get_vulnerability | read | Get full details of a specific vulnerability |
get_webhook_event | read | Get full details of a specific webhook event |
get_wiki_page | read | Get details of a specific wiki page |
get_work_item | read | Get a work item with full details including status, hierarchy, type, and widgets |
health_check | read | Verify server status and authentication. Always reports the MCP server version (mcp_server_version). When authenticated, also reports the GitLab instance version from GET /api/v4/version (version, revision, enterprise). Version lookup failures do not fail the health check — those fields are omitted. |
image | read | Image name |
list_branches | read | List branches in project with search filter |
list_ci_catalog_resources | read | List GitLab CI/CD Catalog resources/components visible to the user |
list_commit_statuses | write | List statuses for a commit |
list_commits | read | List repository commits with filtering options |
list_custom_field_definitions | read | List custom field definitions for a work item type |
list_dependency_proxy_blobs | read | List cached dependency proxy blobs for a group |
list_deployment_merge_requests | write | List merge requests shipped with a deployment |
list_deployments | read | List deployments with filtering options |
list_draft_notes | write | List draft notes for a merge request |
list_environments | read | List environments in a project |
list_events | read | List events for the authenticated user (before/after: YYYY-MM-DD) |
list_group_iterations | read | List group iterations with filtering options |
list_group_members | read | List members of a GitLab group with optional name or username search |
list_group_merge_requests | write | List merge requests across all projects of a group and its subgroups |
list_group_milestones | read | List group milestones with filtering options |
list_group_projects | read | List projects in a group |
list_group_variables | read | List CI/CD variables for a group |
list_group_wiki_pages | read | List wiki pages in a group |
list_issue_discussions | read | List discussions for an issue |
list_issue_emoji_reactions | read | List all emoji reactions on an issue |
list_issue_links | read | List all issue links for a specific issue |
list_issue_note_emoji_reactions | read | List all emoji reactions on an issue note. Pass discussion_id for discussion thread replies. |
list_issues | read | List issues (default: created by current user; use scope= |
list_job_artifacts | read | List artifact files in a job |
list_labels | read | List labels for a project |
list_merge_request_changed_files | write | List changed file paths in a merge request without diff content (mergeRequestIid or branchName required) |
list_merge_request_diffs | write | List merge request diffs with pagination (mergeRequestIid or branchName required) |
list_merge_request_emoji_reactions | write | List all emoji reactions on a merge request |
list_merge_request_note_emoji_reactions | write | List all emoji reactions on a merge request note. Pass discussion_id for discussion thread replies. |
list_merge_request_pipelines | write | List pipelines for a merge request with pagination |
list_merge_request_versions | write | List all versions of a merge request |
list_merge_requests | write | List merge requests (without project_id: user |
list_milestones | read | List milestones with filtering options |
list_namespaces | read | List all namespaces (users and groups) available to the current user. Filter by kind= |
list_pipeline_jobs | read | List all jobs in a specific pipeline |
list_pipeline_schedule_pipelines | write | List the pipelines that a pipeline schedule has triggered |
list_pipeline_schedules | read | List pipeline schedules in a project, optionally filtered to active or inactive |
list_pipeline_trigger_jobs | write | List trigger jobs (bridges) in a pipeline |
list_pipeline_triggers | write | List project pipeline trigger tokens |
list_pipelines | read | List pipelines with filtering options |
list_project_members | read | List members of a GitLab project |
list_project_variables | read | List CI/CD variables for a project |
list_project_vulnerabilities | read | List vulnerabilities for a project with optional state, severity, and report type filters (GraphQL-backed, cursor pagination) |
list_projects | read | List projects accessible by the current user |
list_protected_branches | read | List protected branches in a project, supports search filter |
list_releases | read | List all releases for a project |
list_tags | read | List repository tags for a project |
list_todos | read | List GitLab to-do items for the current user |
list_webhook_events | read | List recent webhook events (past 7 days) |
list_webhooks | read | List webhooks for a project or group |
Trust audit
CAUTIONgrade F · trust 54/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
logger.info(`Session ${sessionId}: stored OAuth token (client: ${authInfo.clientId})`);logger.error(`Token exchange failed (${response.status}): ${body}`);logger.error(`Token refresh failed (${response.status}): ${body}`);logger.error(`Callback token exchange failed (${tokenResponse.status}): ${body}`);logger.info(`Token saved to ${this.tokenStoragePath}`);# GITLAB_OAUTH_REDIRECT_URI=http://127.0.0.1:8888/callback
serve: install ## Preview docs at http://127.0.0.1:8000 (auto-reload)
token: "glpat-ABCDEFG123456789-abcdef",
token: "glpat-ABCDEFG123456789-abcdef",
token: "glpat-ABCDEFG123456789-abcdef",
token: "some-token-value-at-least-20-chars",
delete_branch, delete_deployment, delete_draft_note, delete_environment, delete_group_milestone, delete_group_variable, delete_group_wiki_page, delete_issue, delete_issue_emoji_reaction, delete_issue_
.envrc
.gitlab-mcp-managed-policy.example.json
.gitlab-mcp-mask.example.json
.prettierignore
.gitlab-mcp-mask.json
assert.throws(() => validateMode("../../etc"), /Invalid mode name/);assert.throws(() => getStatePath("../../etc"), /Invalid mode name/);path.resolve(__dirname, "../../package.json"),
const payload = "../../user";
"../../../user",
const CALLBACK_URL = "https://mcp.example.com/callback";
callbackProxy ? CALLBACK_URL : "",
assert.equal(stub.calls[0].body.redirect_uri, CALLBACK_URL);
Gates applied: no_behavioural_pass.
a3e3bcbf574ffull audit observations/trust-audit/mcp-server/zereight__gitlab.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | a3e3bcbf574f | CAUTION | F | 54 | score 56 -> 54 |
| 2026-09-19 | f75f9ef33ca3 | CAUTION | F | 56 | first audit |
Questions
What is the GitLab MCP server?
First gitlab mcp for you, building together
What tools does GitLab expose?
200 in total: 137 read-only, 121 that write, and 35 that can delete or overwrite (delete_branch, delete_deployment, delete_draft_note, delete_environment, delete_group_milestone). Every one is listed on this page with its risk.
Is GitLab safe to connect to an agent?
With care. The audit graded it F (54/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 35 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does GitLab need?
It reads DOWNLOAD_TOKEN_SECRET, DOWNLOAD_TOKEN_TTL, GH_TOKEN, GITHUB_TOKEN, GITLAB_JOB_TOKEN, GITLAB_OAUTH_CLIENT_ID, GITLAB_OAUTH_CLIENT_SECRET, GITLAB_OAUTH_REDIRECT_URI, GITLAB_OAUTH_TOKEN_PATH, GITLAB_OAUTH_TOKEN_SCRIPT, GITLAB_OAUTH_TOKEN_SCRIPT_TIMEOUT_SECONDS and GITLAB_PERSONAL_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does GitLab run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @zereight/mcp-gitlab at 2.1.65.
How current is this page?
The grade is for one exact copy of the source (a3e3bcbf574f), read on 2026-09-23. The repository is watched and re-audited when it changes.