Security categories
A security category groups the security attributes of a namespace and decides whether more than one of them can be applied to the same group or project. These actions create, update and delete categories. Deleting a category deletes its attributes too.
Sample questions
Section titled “Sample questions”- “Create a security category named Business impact”
- “Rename security category 7”
- “Delete a custom security category and its attributes”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such assecurity_category.create, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_security_categorywithactionset to the action’s name, such ascreate, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_create_security_category, with its parameters as the arguments.
Availability
Section titled “Availability”How many of these actions an instance serves at each tier, out of a total of 3:
- Free: 0
- Premium: 0
- Ultimate: 3
Read-only actions: 0 of 3, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).
| Action | Individual |
|---|---|
security_category.create | gitlab_create_security_category |
security_category.delete | gitlab_delete_security_category |
security_category.update | gitlab_update_security_category |
security_category.create
Section titled “security_category.create”Create a GitLab security category in a namespace via GraphQL. Requires Premium or Ultimate. Returns: created security category. See also:
security_attribute.create,group.get,project.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationsecuritycategorycreate
- Meta-tool:
gitlab_security_category, actioncreate - Individual tool:
gitlab_create_security_category - Tier: Ultimate
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
name | string | yes | Security category name |
namespace_id | integer | yes | Numeric namespace ID |
description | string | no | Security category description |
multiple_selection | boolean | no | Whether multiple attributes can be selected for the category |
security_category.delete
Section titled “security_category.delete”Delete a GitLab security category and its associated security attributes via GraphQL. Requires Premium or Ultimate. Returns: deletion confirmation and the IDs of the security attributes deleted with the category. See also:
security_attribute.create,group.get,project.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationsecuritycategorydestroy
- Meta-tool:
gitlab_security_category, actiondelete - Individual tool:
gitlab_delete_security_category - Tier: Ultimate
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
category_id | integer | yes | Numeric security category ID |
security_category.update
Section titled “security_category.update”Update a GitLab security category name or description via GraphQL. Requires Premium or Ultimate. Returns: updated security category. See also:
security_attribute.create,group.get,project.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationsecuritycategoryupdate
- Meta-tool:
gitlab_security_category, actionupdate - Individual tool:
gitlab_update_security_category - Tier: Ultimate
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
category_id | integer | yes | Numeric security category ID |
namespace_id | integer | yes | Numeric namespace ID |
description | string | no | New security category description |
name | string | no | New security category name |
Also needs at least one of: name; description.