Security attributes
A security attribute is a label from a security category that classifies a group or a project, such as its business impact. These actions create, update and delete attributes, apply and remove them on one project, and add, remove or replace them across several groups and projects at once. They are classification metadata, apart from the scanner output on Vulnerabilities.
Sample questions
Section titled “Sample questions”- “Create a security attribute called High under category 7”
- “Apply security attribute 9 to project 42”
- “Replace the security attributes of these projects”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such assecurity_attribute.bulk_update, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_security_attributewithactionset to the action’s name, such asbulk_update, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_bulk_update_security_attributes, with its parameters as the arguments.
Availability
Section titled “Availability”How many of these actions an instance serves at each tier, out of a total of 5:
- Free: 0
- Premium: 0
- Ultimate: 5
Read-only actions: 0 of 5, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).
| Action | Individual |
|---|---|
security_attribute.bulk_update | gitlab_bulk_update_security_attributes |
security_attribute.create | gitlab_create_security_attribute |
security_attribute.delete | gitlab_delete_security_attribute |
security_attribute.project_update | gitlab_update_project_security_attributes |
security_attribute.update | gitlab_update_security_attribute |
security_attribute.bulk_update
Section titled “security_attribute.bulk_update”Add, remove, or replace GitLab security attributes on multiple groups and projects via GraphQL. Requires Premium or Ultimate. Returns: bulk update status, execution mode, and selected target/attribute IDs. See also:
security_attribute.create,project.get,group.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationbulkupdatesecurityattributes
- Meta-tool:
gitlab_security_attribute, actionbulk_update - Individual tool:
gitlab_bulk_update_security_attributes - Tier: Ultimate
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
attribute_ids | integer[] | yes | Security attribute IDs to apply |
mode | string | yes | Bulk update mode: ADD, REMOVE, or REPLACE |
group_ids | integer[] | no | Numeric group IDs to update |
project_ids | integer[] | no | Numeric project IDs to update |
Also needs at least one of: group_ids; project_ids.
security_attribute.create
Section titled “security_attribute.create”Create one or more GitLab security attributes under a security category via GraphQL. Requires Premium or Ultimate. Returns: created security attributes and their categories. See also:
security_category.create,project.get,group.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationsecurityattributecreate
- Meta-tool:
gitlab_security_attribute, actioncreate - Individual tool:
gitlab_create_security_attribute - Tier: Ultimate
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
attributes | object[] | yes | Security attributes to create |
category_id | integer | yes | Numeric security category ID |
namespace_id | integer | yes | Numeric namespace ID |
security_attribute.delete
Section titled “security_attribute.delete”Delete a GitLab security attribute via GraphQL. Requires Premium or Ultimate. Returns: deletion confirmation. See also:
security_category.create,project.get,group.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationsecurityattributedestroy
- Meta-tool:
gitlab_security_attribute, actiondelete - Individual tool:
gitlab_delete_security_attribute - Tier: Ultimate
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
attribute_id | integer | yes | Numeric security attribute ID |
security_attribute.project_update
Section titled “security_attribute.project_update”Add or remove GitLab security attributes on a project via GraphQL. Requires Premium or Ultimate. Returns: project security attribute assignments. See also:
security_attribute.create,project.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationsecurityattributeprojectupdate
- Meta-tool:
gitlab_security_attribute, actionproject_update - Individual tool:
gitlab_update_project_security_attributes - Tier: Ultimate
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | integer | yes | Numeric project ID |
add_attribute_ids | integer[] | no | Security attribute IDs to add |
remove_attribute_ids | integer[] | no | Security attribute IDs to remove |
Also needs at least one of: add_attribute_ids; remove_attribute_ids.
security_attribute.update
Section titled “security_attribute.update”Update a GitLab security attribute name, description, or color via GraphQL. Requires Premium or Ultimate. Returns: updated security attribute metadata. See also:
security_category.create,project.get,group.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationsecurityattributeupdate
- Meta-tool:
gitlab_security_attribute, actionupdate - Individual tool:
gitlab_update_security_attribute - Tier: Ultimate
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
attribute_id | integer | yes | Numeric security attribute ID |
color | string | no | New security attribute color as a hex code (e.g. #FF0000) |
description | string | no | New security attribute description |
name | string | no | New security attribute name |
Also needs at least one of: name; description; color.