Skip to content

Security categories

A security category groups the security attributes of a namespace and decides whether more than one of them can be applied to the same group or project. These actions create, update and delete categories. Deleting a category deletes its attributes too.

  • “Create a security category named Business impact”
  • “Rename security category 7”
  • “Delete a custom security category and its attributes”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as security_category.create, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_security_category with action set to the action’s name, such as create, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_create_security_category, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 3:

  • Free: 0
  • Premium: 0
  • Ultimate: 3

Read-only actions: 0 of 3, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).

ActionIndividual
security_category.creategitlab_create_security_category
security_category.deletegitlab_delete_security_category
security_category.updategitlab_update_security_category

Create a GitLab security category in a namespace via GraphQL. Requires Premium or Ultimate. Returns: created security category. See also: security_attribute.create, group.get, project.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationsecuritycategorycreate

  • Meta-tool: gitlab_security_category, action create
  • Individual tool: gitlab_create_security_category
  • Tier: Ultimate
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
namestringyesSecurity category name
namespace_idintegeryesNumeric namespace ID
descriptionstringnoSecurity category description
multiple_selectionbooleannoWhether multiple attributes can be selected for the category

Delete a GitLab security category and its associated security attributes via GraphQL. Requires Premium or Ultimate. Returns: deletion confirmation and the IDs of the security attributes deleted with the category. See also: security_attribute.create, group.get, project.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationsecuritycategorydestroy

  • Meta-tool: gitlab_security_category, action delete
  • Individual tool: gitlab_delete_security_category
  • Tier: Ultimate
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
category_idintegeryesNumeric security category ID

Update a GitLab security category name or description via GraphQL. Requires Premium or Ultimate. Returns: updated security category. See also: security_attribute.create, group.get, project.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationsecuritycategoryupdate

  • Meta-tool: gitlab_security_category, action update
  • Individual tool: gitlab_update_security_category
  • Tier: Ultimate
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
category_idintegeryesNumeric security category ID
namespace_idintegeryesNumeric namespace ID
descriptionstringnoNew security category description
namestringnoNew security category name

Also needs at least one of: name; description.