Security scan profiles
A security scan profile bundles a scanning configuration, such as secret detection or dependency scanning, that applies to the projects and groups it is attached to. security_scan_profile.attach takes the name of one of GitLab’s default profiles, or a persisted profile’s numeric ID, and attaches it; security_scan_profile.detach takes the persisted profile’s ID; security_scan_profile.list_project_statuses reports each profile’s status on a project.
Scan profiles need GitLab 18.7 or later, and each default profile has its own minimum release, which an attach refusal names. Every target must belong to a group namespace, all of one root namespace.
Sample questions
Section titled “Sample questions”- “Attach the dependency scanning profile to project 42”
- “Which scan profiles are active on project 42?”
- “Detach the scan profile from these groups”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such assecurity_scan_profile.attach, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_security_scan_profilewithactionset to the action’s name, such asattach, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_attach_security_scan_profile, with its parameters as the arguments.
Availability
Section titled “Availability”How many of these actions an instance serves at each tier, out of a total of 3:
- Free: 0
- Premium: 0
- Ultimate: 3
Read-only actions: 1 of 3, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).
| Action | Individual |
|---|---|
security_scan_profile.attach | gitlab_attach_security_scan_profile |
security_scan_profile.detach | gitlab_detach_security_scan_profile |
security_scan_profile.list_project_statuses | gitlab_list_project_scan_profile_statuses |
security_scan_profile.attach
Section titled “security_scan_profile.attach”Attach a GitLab security scan profile to one or more projects and/or groups via GraphQL. Requires Ultimate. Returns: attach confirmation with the resolved profile and targets. See also:
security_scan_profile.detach,security_scan_profile.list_project_statuses,project.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationsecurityscanprofileattach
- Meta-tool:
gitlab_security_scan_profile, actionattach - Individual tool:
gitlab_attach_security_scan_profile - Tier: Ultimate
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
security_scan_profile_id | string | yes | Security scan profile identifier: the name of a GitLab default profile (secret_detection, sast, dependency_scanning, dependency_scanning_post_processing, triage_and_remediation_conservative, triage_and_remediation_standard, or triage_and_remediation_proactive), for which attach creates the namespace’s default profile on the fly, or the persisted profile’s numeric database ID (required by detach). A full gid:// global ID is also accepted. sast needs GitLab 18.10 and dependency_scanning needs 18.11, both behind a feature flag until 19.0, dependency_scanning_post_processing needs 19.2, and the triage_and_remediation presets need 19.4. container_scanning and business_logic have no default profile, and the bare triage_and_remediation names none of its presets, so attach refuses all three by name |
group_ids | integer[] | no | Numeric IDs of the groups to attach the profile to |
project_ids | integer[] | no | Numeric IDs of the projects to attach the profile to |
Also needs at least one of: project_ids; group_ids.
security_scan_profile.detach
Section titled “security_scan_profile.detach”Detach a GitLab security scan profile from one or more projects and/or groups via GraphQL. Requires Ultimate. Returns: detach confirmation with the resolved profile and targets. See also:
security_scan_profile.attach,security_scan_profile.list_project_statuses,project.get. API docs:https://docs.gitlab.com/api/graphql/reference/#mutationsecurityscanprofiledetach
- Meta-tool:
gitlab_security_scan_profile, actiondetach - Individual tool:
gitlab_detach_security_scan_profile - Tier: Ultimate
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
security_scan_profile_id | string | yes | Persisted scan profile identifier: the profile’s numeric database ID (obtained from security_scan_profile.list_project_statuses) or a full gid:// global ID. A scan-type name (dependency_scanning, sast, …) is not accepted by detach |
group_ids | integer[] | no | Numeric IDs of the groups to detach the profile from |
project_ids | integer[] | no | Numeric IDs of the projects to detach the profile from |
Also needs at least one of: project_ids; group_ids.
security_scan_profile.list_project_statuses
Section titled “security_scan_profile.list_project_statuses”List the security scan profile statuses for a GitLab project via GraphQL. Requires Ultimate. Returns: per-scan-type profile status (NOT_CONFIGURED, PENDING, ACTIVE, WARNING, FAILED, or STALE). See also:
security_scan_profile.attach,security_scan_profile.detach,project.get. API docs:https://docs.gitlab.com/api/graphql/reference/#project-scanprofilestatuses
- Meta-tool:
gitlab_security_scan_profile, actionlist_project_statuses - Individual tool:
gitlab_list_project_scan_profile_statuses - Tier: Ultimate
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_full_path | string | yes | Full project path (namespace/project). Numeric project IDs are not accepted by the GraphQL project(fullPath:) field |