Skip to content

Security scan profiles

A security scan profile bundles a scanning configuration, such as secret detection or dependency scanning, that applies to the projects and groups it is attached to. security_scan_profile.attach takes the name of one of GitLab’s default profiles, or a persisted profile’s numeric ID, and attaches it; security_scan_profile.detach takes the persisted profile’s ID; security_scan_profile.list_project_statuses reports each profile’s status on a project.

Scan profiles need GitLab 18.7 or later, and each default profile has its own minimum release, which an attach refusal names. Every target must belong to a group namespace, all of one root namespace.

  • “Attach the dependency scanning profile to project 42”
  • “Which scan profiles are active on project 42?”
  • “Detach the scan profile from these groups”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as security_scan_profile.attach, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_security_scan_profile with action set to the action’s name, such as attach, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_attach_security_scan_profile, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 3:

  • Free: 0
  • Premium: 0
  • Ultimate: 3

Read-only actions: 1 of 3, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).

ActionIndividual
security_scan_profile.attachgitlab_attach_security_scan_profile
security_scan_profile.detachgitlab_detach_security_scan_profile
security_scan_profile.list_project_statusesgitlab_list_project_scan_profile_statuses

Attach a GitLab security scan profile to one or more projects and/or groups via GraphQL. Requires Ultimate. Returns: attach confirmation with the resolved profile and targets. See also: security_scan_profile.detach, security_scan_profile.list_project_statuses, project.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationsecurityscanprofileattach

  • Meta-tool: gitlab_security_scan_profile, action attach
  • Individual tool: gitlab_attach_security_scan_profile
  • Tier: Ultimate
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
security_scan_profile_idstringyesSecurity scan profile identifier: the name of a GitLab default profile (secret_detection, sast, dependency_scanning, dependency_scanning_post_processing, triage_and_remediation_conservative, triage_and_remediation_standard, or triage_and_remediation_proactive), for which attach creates the namespace’s default profile on the fly, or the persisted profile’s numeric database ID (required by detach). A full gid:// global ID is also accepted. sast needs GitLab 18.10 and dependency_scanning needs 18.11, both behind a feature flag until 19.0, dependency_scanning_post_processing needs 19.2, and the triage_and_remediation presets need 19.4. container_scanning and business_logic have no default profile, and the bare triage_and_remediation names none of its presets, so attach refuses all three by name
group_idsinteger[]noNumeric IDs of the groups to attach the profile to
project_idsinteger[]noNumeric IDs of the projects to attach the profile to

Also needs at least one of: project_ids; group_ids.

Detach a GitLab security scan profile from one or more projects and/or groups via GraphQL. Requires Ultimate. Returns: detach confirmation with the resolved profile and targets. See also: security_scan_profile.attach, security_scan_profile.list_project_statuses, project.get. API docs: https://docs.gitlab.com/api/graphql/reference/#mutationsecurityscanprofiledetach

  • Meta-tool: gitlab_security_scan_profile, action detach
  • Individual tool: gitlab_detach_security_scan_profile
  • Tier: Ultimate
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
security_scan_profile_idstringyesPersisted scan profile identifier: the profile’s numeric database ID (obtained from security_scan_profile.list_project_statuses) or a full gid:// global ID. A scan-type name (dependency_scanning, sast, …) is not accepted by detach
group_idsinteger[]noNumeric IDs of the groups to detach the profile from
project_idsinteger[]noNumeric IDs of the projects to detach the profile from

Also needs at least one of: project_ids; group_ids.

security_scan_profile.list_project_statuses

Section titled “security_scan_profile.list_project_statuses”

List the security scan profile statuses for a GitLab project via GraphQL. Requires Ultimate. Returns: per-scan-type profile status (NOT_CONFIGURED, PENDING, ACTIVE, WARNING, FAILED, or STALE). See also: security_scan_profile.attach, security_scan_profile.detach, project.get. API docs: https://docs.gitlab.com/api/graphql/reference/#project-scanprofilestatuses

  • Meta-tool: gitlab_security_scan_profile, action list_project_statuses
  • Individual tool: gitlab_list_project_scan_profile_statuses
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_full_pathstringyesFull project path (namespace/project). Numeric project IDs are not accepted by the GraphQL project(fullPath:) field