Gitlab Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Gitlab Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server that provides tools to interact with GitLab merge requests. This server runs as a local tool using stdio transport, allowing MCP clients (like Claude Desktop) to retrieve comprehensive information about GitLab merge requests.
api or read_api scopenpm installnpm run build.env file based on .env.example:cp .env.example .env.env and add your GitLab credentials:GITLAB_INSTANCE_URL=https://gitlab.com
GITLAB_API_TOKEN=your-personal-access-token
GITLAB_PROJECT_ID=your-project-idGitLab Instance URL:
https://gitlab.comhttps://gitlab.example.com)API Token:
api or read_api scopeProject ID:
Add the following to your Claude Desktop MCP settings file:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"gitlab": {
"command": "node",
"args": ["/absolute/path/to/gitlab-mcp/dist/index.js"],
"env": {
"GITLAB_INSTANCE_URL": "https://gitlab.com",
"GITLAB_API_TOKEN": "your-api-token",
"GITLAB_PROJECT_ID": "12345678"
}
}
}
}Replace /absolute/path/to/gitlab-mcp with the actual path to this project.
Alternatively, if you want to use the .env file, you can omit the env section, but make sure the .env file is in the project root.
get_merge_requestGet basic information about a merge request.
Parameters:
merge_request_iid (number): The IID (internal ID) of the merge requestReturns: Basic MR info including title, description, state, branches, author, assignees, reviewers, labels, and merge status.
get_merge_request_commitsGet all commits in a merge request.
Parameters:
merge_request_iid (number): The IID of the merge requestReturns: Array of commits with messages, authors, timestamps, and SHAs.
get_merge_request_diffsGet all file changes and diffs in a merge request.
Parameters:
merge_request_iid (number): The IID of the merge requestReturns: Array of file changes with line-by-line diffs.
get_merge_request_discussionsGet all discussions and comments on a merge request.
Parameters:
merge_request_iid (number): The IID of the merge requestReturns: Array of discussion threads with notes, including review comments and system notes.
get_merge_request_approvalsGet approval status and information for a merge request.
Parameters:
merge_request_iid (number): The IID of the merge requestReturns: Approval state including required approvals, approvals left, and who approved.
get_merge_request_pipelinesGet CI/CD pipeline information for a merge request.
Parameters:
merge_request_iid (number): The IID of the merge requestReturns: Array of pipelines with status, ref, SHA, and timestamps.
get_merge_request_fullGet complete information about a merge request (all data in one call).
Parameters:
merge_request_iid (number): The IID of the merge requestReturns: Complete merge request data including MR info, commits, diffs, discussions, approvals, pipelines, and latest pipeline jobs.
Once configured in Claude Desktop, you can use natural language to interact with your GitLab merge requests:
"Show me the details of merge request 42"
"What commits are in MR 15?"
"Get the diffs for merge request 8"
"Show me all comments on MR 23"
"What's the approval status of merge request 10?"
"Get everything about merge request 5"npm run buildnpm run watchGITLAB_API_TOKEN is correct and has the necessary scopesGITLAB_PROJECT_ID is correctapi or read_api scopeThe API token needs one of the following scopes:
api - Full API access (recommended)read_api - Read-only API access (minimum required)Additionally, your GitLab account needs at least Reporter level access to the project to view merge request information.
ISC
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.