Gitlab Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Gitlab Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Advanced GitLab MCP server — 58 CQRS tools exposing 230 GitLab operations across 26 entity types. The tool catalog and parameters are filtered to each instance's GitLab version, tier, and token scopes, so the agent sees only what the connected instance actually supports.
This is a monorepo with two npm packages:
OAUTH_STORAGE_TYPE=postgresql; see the PostgreSQL deployment guide for the full setup.{
"mcpServers": {
"gitlab": {
"command": "npx",
"args": ["-y", "@structured-world/gitlab-mcp"],
"env": {
"GITLAB_TOKEN": "your_gitlab_token",
"GITLAB_API_URL": "https://gitlab.com"
}
}
}
}Requirements: Node.js >= 24
browse_* for queries, manage_* for commandsghcr.io/structured-world/gitlab-mcp:latestGitLab exposes hundreds of API operations. Giving each its own MCP tool floods an agent's context; a thin API wrapper pushes that complexity back onto the agent. This server takes a third path: 58 CQRS tools, each holding several typed actions, expose 230 operations across 26 entity types.
browse_* tools are read-only queries; manage_* tools are writes.browse_pipelines coverspipelines, jobs, and logs in a single tool.
against GitLab version, tier, token scopes, admin-mode, feature flags, and profiles.
Examples:
browse_pipelines — list, get, jobs, job, logs, triggersmanage_pipeline — create, retry, cancelbrowse_environments — list, get, list_deploymentsmanage_environment — create, update, stop, delete, update_deployment_statusbrowse_deploy_keys / manage_deploy_key — list, get / add, enable, update, deleteFull documentation is available at [gitlab-mcp.sw.foundation](https://gitlab-mcp.sw.foundation)
| Section | Description |
|---|---|
| Installation | npm, Docker, VS Code, Codex |
| Configuration | Environment variables, feature flags |
| Multi-Instance | Connect to multiple GitLab instances |
| Tool Reference | All 58 tools with parameters |
| OAuth Setup | Team authentication with Claude |
| TLS/HTTPS | Production deployment with SSL |
| Customization | Tool descriptions, action filtering |
| CLI Tools | Browse and export tool documentation |
For the complete tool reference with parameters:
# View locally
yarn list-tools --detail
# Generate documentation
yarn list-tools --export --toc > docs/tools/api-reference.mdSee the Full API Reference for the auto-generated tool documentation.
# HTTP mode
docker run -e PORT=3002 -e GITLAB_TOKEN=your_token -p 3333:3002 \
ghcr.io/structured-world/gitlab-mcp:latest
# stdio mode
docker run -i --rm -e GITLAB_TOKEN=your_token \
ghcr.io/structured-world/gitlab-mcp:latestThe server handles GitLab connectivity issues gracefully:
GITLAB_INIT_TIMEOUT_MS (default 5s) regardless of GitLab availabilitydisconnected/failed state), only the manage_context tool is exposed, with local actions such as whoami, switch_profile, and set_scope for diagnostics. During active reconnect (connecting state), the full tool list remains available so MCP clients don't lose their tool catalog during brief outages. MCP clients are notified of tool availability changes via tools/list_changedfailed state (no auto-reconnect). Mid-session token revocation is detected via an authenticated HEAD /api/v4/user check that runs alongside each periodic health check (static token mode only; skipped in OAuth mode). A 401 or 403 on this check transitions the instance to failed state immediately.| Variable | Default | Description |
|---|---|---|
GITLAB_INIT_TIMEOUT_MS | 5000 | Max time to wait for GitLab during startup |
GITLAB_RECONNECT_BASE_DELAY_MS | 5000 | Initial reconnect delay (doubles each attempt) |
GITLAB_RECONNECT_MAX_DELAY_MS | 60000 | Maximum reconnect delay |
GITLAB_HEALTH_CHECK_INTERVAL_MS | 60000 | Health check interval when connected |
GITLAB_FAILURE_THRESHOLD | 3 | Consecutive transient failures before disconnecting |
GITLAB_TOOL_TIMEOUT_MS | 120000 | Max time for tool/bootstrap execution before timeout |
GITLAB_RESPONSE_WRITE_TIMEOUT_MS | 10000 | Max time to flush a non-SSE response before destroying zombie connection (0 to disable; SSE uses heartbeat) |
GITLAB_INSTANCE_CACHE_MAX | 100 | Max number of per-URL instance states kept in memory (OAuth multi-tenant; LRU eviction when exceeded) |
GITLAB_INSTANCE_TTL_MS | 3600000 | TTL for idle per-URL instance states in ms; evicted on next insert (OAuth multi-tenant) |
| Flag | Default | Tools Enabled |
|---|---|---|
USE_LABELS | true | Label management |
USE_MRS | true | Merge requests |
USE_FILES | true | File operations |
USE_VARIABLES | true | CI/CD variables |
USE_WORKITEMS | true | Issues, epics, tasks |
USE_WEBHOOKS | true | Webhook management |
USE_SNIPPETS | true | Code snippets |
USE_INTEGRATIONS | true | 50+ integrations |
USE_GITLAB_WIKI | true | Wiki pages |
USE_MILESTONE | true | Milestones |
USE_PIPELINE | true | Pipelines & CI/CD |
USE_RELEASES | true | Release management |
USE_REFS | true | Branch & tag management |
USE_MEMBERS | true | Team members |
USE_SEARCH | true | Cross-project search |
USE_ITERATIONS | true | Iteration planning (sprints) |
USE_CI_TOKENS | true | CI access credentials: job token scope and deploy keys |
USE_ENVIRONMENTS | true | Environments and deployments |
USE_RUNNERS | true | CI runner management |
USE_REGISTRY | true | Container registry repositories and tags |
USE_ACCESS_TOKENS | true | Project/group/personal access token management |
USE_AUDIT_EVENTS | true | Audit events (Premium+) |
USE_VULNERABILITIES | true | Vulnerability management (Ultimate) |
See CONTRIBUTING.md for development setup, testing, and PR guidelines.
<div align="center">
USDT TRC-20 Donation QR Code
USDT (TRC-20): TFDsezHa1cBkoeZT5q2T49Wp66K8t2DmdA
</div>
Apache License 2.0 — see LICENSE for details.
Based on zereight/gitlab-mcp (MIT). See LICENSE.MIT.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.