Skip to content

Security findings

A finding is what one scanner reported in one pipeline; a vulnerability is the tracked record GitLab keeps of a finding across pipelines. security_finding.list lists the findings of one pipeline, filtered by severity, report type, scanner or state, which is what a pipeline’s security report showed.

  • “What did the SAST scan find in pipeline 456?”
  • “List the critical findings of the latest pipeline”
  • “Show the secret detection findings of pipeline 123”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as security_finding.list, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_security_finding with action set to the action’s name, such as list, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_list_security_findings, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 1:

  • Free: 0
  • Premium: 0
  • Ultimate: 1

Read-only actions: 1 of 1, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served.

ActionIndividual
security_finding.listgitlab_list_security_findings

List a pipeline’s security report findings with severity, scanner, report-type and state filters, severity sorting and keyset pagination. Returns: matching findings with UUID, title, severity and original severity, report type, scanner, identifiers (CVE, CWE, OWASP), location, state, who dismissed it and why, evidence with the recorded HTTP exchange, proposed remediations, report links, and linked vulnerability state. See also: vulnerability.list, vulnerability.pipeline_security_summary, vulnerability.severity_count.

  • Meta-tool: gitlab_security_finding, action list
  • Individual tool: gitlab_list_security_findings
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
pipeline_iidstringyesPipeline IID within the project
project_pathstringyesFull path of the project (e.g. my-group/my-project)
afterstringnoCursor for forward pagination (from previous response end_cursor)
beforestringnoCursor for backward pagination (from previous response start_cursor). The page size comes from last, or from first when last is omitted
firstintegernoNumber of items to return (default 20, max 100)
lastintegernoNumber of items to return from the end of the range (backward pagination). Cannot be combined with first
report_typestring[]noFilter by report type: SAST, DAST, DEPENDENCY_SCANNING, CONTAINER_SCANNING, SECRET_DETECTION, COVERAGE_FUZZING, API_FUZZING, CLUSTER_IMAGE_SCANNING, SARIF. SARIF needs GitLab 18.11, and an older GitLab drops it and answers with no findings
scannerstring[]noFilter by scanner external IDs
severitystring[]noFilter by severity: CRITICAL, HIGH, MEDIUM, LOW, INFO, UNKNOWN
sortstring (severity_desc, severity_asc)noSort order: severity_desc (default) or severity_asc
statestring[] (DETECTED, CONFIRMED, DISMISSED, RESOLVED)noFilter by state: DETECTED, CONFIRMED, DISMISSED, RESOLVED