mcp-gitlab (rifqi96/mcp-gitlab) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 84 tools. No publisher has claimed this listing.
A Model Context Protocol server that enables interaction with GitLab accounts to manage repositories, merge requests, code reviews, and CI/CD pipelines through natural language.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
rifqi96
Source: ModelScope
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
gitlab_list_projectsList GitLab projects accessible to the user
gitlab_get_projectGet details of a specific GitLab project
gitlab_list_branchesList branches of a GitLab project
gitlab_list_merge_requestsList merge requests in a GitLab project
gitlab_get_merge_requestGet details of a specific merge request
gitlab_get_merge_request_changesGet changes (diff) of a specific merge request
gitlab_create_merge_request_noteAdd a comment to a merge request
gitlab_create_merge_request_note_internalAdd a comment to a merge request with option to make it an internal note
gitlab_update_merge_requestUpdate a merge request title and description
gitlab_create_merge_requestCreate a new merge request in a GitLab project
gitlab_list_issuesList issues in a GitLab project
gitlab_get_repository_fileGet content of a file in a repository
gitlab_compare_branchesCompare branches, tags or commits
gitlab_list_integrationsList all available project integrations/services
gitlab_get_integrationGet integration details for a project
gitlab_update_slack_integrationUpdate Slack integration settings for a project
gitlab_disable_slack_integrationDisable Slack integration for a project
gitlab_list_webhooksList webhooks for a project
gitlab_get_webhookGet details of a specific webhook
gitlab_add_webhookAdd a new webhook to a project
gitlab_update_webhookUpdate an existing webhook
gitlab_delete_webhookDelete a webhook
gitlab_test_webhookTest a webhook
gitlab_list_trigger_tokensList pipeline trigger tokens
gitlab_get_trigger_tokenGet details of a pipeline trigger token
gitlab_create_trigger_tokenCreate a new pipeline trigger token
gitlab_update_trigger_tokenUpdate a pipeline trigger token
gitlab_delete_trigger_tokenDelete a pipeline trigger token
gitlab_trigger_pipelineTrigger a pipeline run
gitlab_list_cicd_variablesList CI/CD variables for a project
gitlab_get_cicd_variableGet a specific CI/CD variable
gitlab_create_cicd_variableCreate a new CI/CD variable
gitlab_update_cicd_variableUpdate a CI/CD variable
gitlab_delete_cicd_variableDelete a CI/CD variable
gitlab_list_usersList GitLab users
gitlab_get_userGet details of a specific user
gitlab_list_groupsList GitLab groups
gitlab_get_groupGet details of a specific group
gitlab_list_group_membersList members of a group
gitlab_add_group_memberAdd a user to a group
gitlab_list_project_membersList members of a project
gitlab_add_project_memberAdd a user to a project
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
GITLAB_API_TOKEN"": "YOUR_GITLAB_API_TOKEN",GITLAB_API_URL"": "https://gitlab.com/api/v4"Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
84/84 tools missing one or more hints — gitlab_list_projects (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); gitlab_get_project (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); gitlab_list_branches (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +81 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 14 high severity in production deps — @modelcontextprotocol/sdk@1.7.0 (high), @modelcontextprotocol/sdk@1.7.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/rifqi96/mcp-gitlab)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check