Skip to content

Security attributes

A security attribute is a label from a security category that classifies a group or a project, such as its business impact. These actions create, update and delete attributes, apply and remove them on one project, and add, remove or replace them across several groups and projects at once. They are classification metadata, apart from the scanner output on Vulnerabilities.

  • “Create a security attribute called High under category 7”
  • “Apply security attribute 9 to project 42”
  • “Replace the security attributes of these projects”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as security_attribute.bulk_update, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_security_attribute with action set to the action’s name, such as bulk_update, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_bulk_update_security_attributes, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 5:

  • Free: 0
  • Premium: 0
  • Ultimate: 5

Read-only actions: 0 of 5, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).

ActionIndividual
security_attribute.bulk_updategitlab_bulk_update_security_attributes
security_attribute.creategitlab_create_security_attribute
security_attribute.deletegitlab_delete_security_attribute
security_attribute.project_updategitlab_update_project_security_attributes
security_attribute.updategitlab_update_security_attribute

Add, remove, or replace GitLab security attributes on multiple groups and projects via GraphQL. Requires Premium or Ultimate. Returns: bulk update status, execution mode, and selected target/attribute IDs. See also: security_attribute.create, project.get, group.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationbulkupdatesecurityattributes

  • Meta-tool: gitlab_security_attribute, action bulk_update
  • Individual tool: gitlab_bulk_update_security_attributes
  • Tier: Ultimate
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
attribute_idsinteger[]yesSecurity attribute IDs to apply
modestringyesBulk update mode: ADD, REMOVE, or REPLACE
group_idsinteger[]noNumeric group IDs to update
project_idsinteger[]noNumeric project IDs to update

Also needs at least one of: group_ids; project_ids.

Create one or more GitLab security attributes under a security category via GraphQL. Requires Premium or Ultimate. Returns: created security attributes and their categories. See also: security_category.create, project.get, group.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationsecurityattributecreate

  • Meta-tool: gitlab_security_attribute, action create
  • Individual tool: gitlab_create_security_attribute
  • Tier: Ultimate
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
attributesobject[]yesSecurity attributes to create
category_idintegeryesNumeric security category ID
namespace_idintegeryesNumeric namespace ID

Delete a GitLab security attribute via GraphQL. Requires Premium or Ultimate. Returns: deletion confirmation. See also: security_category.create, project.get, group.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationsecurityattributedestroy

  • Meta-tool: gitlab_security_attribute, action delete
  • Individual tool: gitlab_delete_security_attribute
  • Tier: Ultimate
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
attribute_idintegeryesNumeric security attribute ID

Add or remove GitLab security attributes on a project via GraphQL. Requires Premium or Ultimate. Returns: project security attribute assignments. See also: security_attribute.create, project.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationsecurityattributeprojectupdate

  • Meta-tool: gitlab_security_attribute, action project_update
  • Individual tool: gitlab_update_project_security_attributes
  • Tier: Ultimate
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idintegeryesNumeric project ID
add_attribute_idsinteger[]noSecurity attribute IDs to add
remove_attribute_idsinteger[]noSecurity attribute IDs to remove

Also needs at least one of: add_attribute_ids; remove_attribute_ids.

Update a GitLab security attribute name, description, or color via GraphQL. Requires Premium or Ultimate. Returns: updated security attribute metadata. See also: security_category.create, project.get, group.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationsecurityattributeupdate

  • Meta-tool: gitlab_security_attribute, action update
  • Individual tool: gitlab_update_security_attribute
  • Tier: Ultimate
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
attribute_idintegeryesNumeric security attribute ID
colorstringnoNew security attribute color as a hex code (e.g. #FF0000)
descriptionstringnoNew security attribute description
namestringnoNew security attribute name

Also needs at least one of: name; description; color.