{"name":"io.github.zereight/gitlab-mcp","slug":"zereight-gitlab-mcp","title":null,"description":"GitLab MCP server for projects, merge requests, issues, pipelines, wiki, releases, and more.","url":"https://mcp.market/server/zereight-gitlab-mcp","rating":null,"grade":"B","score":75,"certified":false,"status":"active","category":"devtools","tags":["devtools"],"presence":{"score":72,"stars":1986,"forks":357,"downloads_week":96949,"last_push_at":"2026-09-16T21:13:02.000Z","license":"MIT"},"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/zereight/gitlab-mcp","website":null,"version":"2.1.63","remotes":[],"packages":[{"registryType":"npm","identifier":"@zereight/mcp-gitlab","version":"2.1.63","transport":{"type":"stdio"},"environmentVariables":[{"description":"GitLab personal access token for local stdio use. Create a token with the GitLab scopes needed by the tools you plan to use, such as api or read_api.","isRequired":true,"format":"string","isSecret":true,"name":"GITLAB_PERSONAL_ACCESS_TOKEN"},{"description":"Optional GitLab CI job token to use instead of a personal access token when running inside GitLab CI.","format":"string","isSecret":true,"name":"GITLAB_JOB_TOKEN"},{"description":"Optional path to a GitLab authentication cookie file for cookie-based authentication.","format":"filepath","name":"GITLAB_AUTH_COOKIE_PATH"},{"description":"GitLab API base URL. Use https://gitlab.com/api/v4 for GitLab.com or your self-managed GitLab API URL.","format":"string","default":"https://gitlab.com/api/v4","name":"GITLAB_API_URL"},{"description":"Optional comma-separated list of GitLab project IDs that this server is allowed to access.","format":"string","name":"GITLAB_ALLOWED_PROJECT_IDS"},{"description":"Set to true to expose only read-only tools and block write operations.","format":"string","default":"false","name":"GITLAB_READ_ONLY_MODE"},{"description":"Set to true to enable GitLab wiki tools.","format":"string","default":"false","name":"USE_GITLAB_WIKI"},{"description":"Optional comma-separated list of toolsets to enable, such as projects, issues, merge_requests, pipelines, releases, users, groups, wiki, or search.","format":"string","name":"GITLAB_TOOLSETS"},{"description":"Optional comma-separated list of individual tool names to add on top of enabled toolsets.","format":"string","name":"GITLAB_TOOLS"},{"description":"Optional regular expression used to hide matching tools from the server.","format":"string","name":"GITLAB_DENIED_TOOLS_REGEX"},{"description":"Optional comma-separated list of tool names that require explicit approval before execution.","format":"string","name":"GITLAB_TOOL_POLICY_APPROVE"},{"description":"Optional comma-separated list of tool names to hide from tools/list.","format":"string","name":"GITLAB_TOOL_POLICY_HIDDEN"},{"description":"Set to 0 only when you intentionally need to connect to a GitLab instance with invalid or self-signed TLS certificates.","format":"string","name":"NODE_TLS_REJECT_UNAUTHORIZED"},{"description":"Optional path to a custom CA certificate file for self-managed GitLab instances.","format":"filepath","name":"GITLAB_CA_CERT_PATH"},{"description":"Set to true to mask text tool results and returned errors using built-in or configured rules.","format":"string","default":"false","name":"GITLAB_MASKING_ENABLED"},{"description":"Optional path to a response-masking JSON configuration file.","format":"filepath","name":"GITLAB_MASKING_CONFIG"},{"description":"Optional protected server-owned JSON file containing managed masking policies.","format":"filepath","name":"GITLAB_MASKING_POLICY_FILE"},{"description":"Directory used to resolve response-masking configuration paths.","format":"filepath","name":"GITLAB_MASKING_WORKSPACE_DIR"}]}],"tools":[],"scan":{"score":75,"grade":"B","scanned_at":"2026-09-19T09:57:48.294Z","report":{"scannerVersion":"0.1.3","scannedAt":"2026-09-19T09:57:48.272Z","components":{"code":{"score":20,"max":25,"notes":["52 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 3 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[{"id":"net.raw-ip","severity":"medium","component":"code","title":"Network call to a raw IP address","evidence":"build/auth-cli.js: …lab.com\"; const DEFAULT_REDIRECT_URI = \"http://127.0.0.1:8888/callback\"; export const AUTH_CLI_HELP = …"}],"inputs":{"packages":[{"registryType":"npm","identifier":"@zereight/mcp-gitlab","version":"2.1.63","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":14,"publishedAt":"2026-09-16T21:08:22.882Z","repositoryUrl":"git+https://github.com/zereight/gitlab-mcp.git","weeklyDownloads":96949}],"repo":{"found":true,"owner":"zereight","repo":"gitlab-mcp","archived":false,"pushedAt":"2026-09-16T21:13:02Z","stars":1986,"forks":357,"openIssues":18,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/42544600?v=4","ownerCreatedAt":"2018-08-20T13:52:19Z","license":"MIT"},"icon":{"url":"https://avatars.githubusercontent.com/u/42544600?v=4&s=128","source":"github"},"presence":{"stars":1986,"forks":357,"downloadsWeek":96949,"license":"MIT","lastPushAt":"2026-09-16T21:13:02.000Z","score":72}}}},"grade_history":[],"reviews":[]}