Gitlab MCP Server logo

Gitlab MCP Server

Claimed

by jmrplens

Open source GitLab MCP server for AI assistants: 2-tool dynamic find/execute over 850+ GitLab actions (1,000+ Enterprise), stdio/HTTP/OAuth, safe/read-only modes.

Set up this server

01 / Choose your client

02 / Before you connect

OAuth is required. Follow the provider’s sign-in instructions in your client.

Install the runtime required by the project and make it available to your client.

Project instructions

Use names from the project instructions, separated by commas. Enter names only, never secret values.

03 / Add the configuration

Source: maintainer launch command

claude mcp add --transport stdio 'gitlab-mcp-server' -- 'npx' '-y' '@jmrp.io/gitlab-mcp-server'

Run in your terminal after replacing any placeholders.

04 / Check it in your client

Open your client’s MCP settings and confirm the server connects and lists its tools. A copied configuration does not confirm a working connection.

ai-toolsgitlabgitlab-apigollmmcpmcp-servermodel-context-protocol

More in Developer Tools

Browse the full directory

Badge

Show this listing on your README and website

Get verified and your listing links back to your site with a do-follow link. The badge is optional while first-100 launch spots remain.

Security profile

Exposure: Limited

Runs commands or loads code on your machine, but does not reach secrets or other agents.

What this server can reach, from a static read of the shipped code. Nothing was executed and nothing here is a verdict: a browser tool has to run commands and an API wrapper has to call its API. Decide what fits your setup.

NVIDIA SkillSpector v2.11.0, MCPVault MCP-server policy. Scanned yesterday @ 2b8b835.

Detected

  • Talks to external services1 places

    Makes outbound requests. The hosts are listed so you can see where data goes.

    api.nuget.org

  • Runs shell commands25 places

    Spawns processes on your machine. Expected for command, browser and build tools.

  • Contains instructions aimed at AI agents2 places

    Text in code or agent-facing files that steers a model. Worth reading before you trust it.

  • Runs unpinned packages at runtime37 places

    Executes npx or uvx without a version, so a compromised upstream release would run.

Not detected: reads environment variables in bulk, sends conversation content outward, reads or writes other agents' configuration, accesses credential files, uses elevated privileges, installs itself to run later, matches a known malicious pattern.

Dependencies with known advisories

None found in the lockfiles and manifests checked against OSV.dev.

Left out of the profile

31 pattern matches in documentation, configuration or CI files were recorded but are not part of the profile, because they do not run when the server does. The owner dashboard lists them.

How the profile works Maintainers see file, line and a fix for each item in their dashboard.

Documented tools (1)

From project documentation. A server handshake does not verify each tool’s description or behavior.

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about Gitlab MCP Server

How do I connect Gitlab MCP Server to Claude?
Run `claude mcp add gitlab-mcp-server -- npx -y @jmrp.io/gitlab-mcp-server` in Claude Code, or add the same command and arguments under mcpServers in Cursor's mcp.json or Claude Desktop's claude_desktop_config.json, then restart the client. The blocks above are ready to paste.
Is Gitlab MCP Server free?
The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can Gitlab MCP Server do?
Gitlab MCP Server documents 1 tool to the agent, including OpenAI. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.