Agent skill

GitLab MCP Skill

by zereight in zereight/gitlab-mcp

A skill your agent uses when working with the GitLab MCP server tools for merge requests, issues, repositories, pipelines, work items, variables, dependency proxy, vulnerabilities, webhooks, search…

MITAuto-check passedBackend & APIs

Install GitLab MCP Skill

skills CLI
$ npx skills add zereight/gitlab-mcp --skill gitlab-mcp-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zereight/gitlab-mcp gitlab-mcp-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zereight/gitlab-mcp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gitlab-mcp .claude/skills/gitlab-mcp-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gitlab-mcp-skill
GitHub stars
2k
Token cost
~2k tokens
SKILL.md length
654 words
Files
9
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when working with the GitLab MCP server tools for merge requests, issues, repositories, pipelines, work items, variables, dependency proxy, vulnerabilities, webhooks, search…

  • Works in 4 steps: list_merge_request_changed_files - get… → get_merge_request_file_diff - get diffs… → create_merge_request_thread or… → …
  • Working with the GitLab MCP server tools for merge requests
  • SKILL.md covers Toolsets, Key Workflows, Parameter Hints and Destructive Tools (require…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

GitLab MCP Skill is an agent skill from zereight/gitlab-mcp. Use this skill when working with the GitLab MCP server tools for merge requests, issues, repositories, pipelines, work items, variables, dependency proxy, vulnerabilities, webhooks, search, CI catalog, and related GitLab workflows.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files (for example `reference/code-review.md`, `reference/issues.md` and `reference/merge-requests.md`).

It sits in Backend & APIs, covering Webhooks and MCP servers. It works with GitLab, Model Context Protocol and GraphQL. The repository describes itself as: First gitlab mcp for you, building together. The licence is MIT.

When your agent uses it

  • Working with the GitLab MCP server tools for merge requests
  • Dependency proxy
  • Vulnerabilities
  • Related GitLab workflows

Example prompts

  • “/gitlab-mcp-skill”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. list_merge_request_changed_files - get file paths only (no diffs)
  2. get_merge_request_file_diff - get diffs for 3-5 files per call (batch)
  3. create_merge_request_thread or create_draft_note - leave review comments
  4. bulk_publish_draft_notes - publish all drafts at once

What it can do on your machine

Read from SKILL.md and the folder at commit 0109168. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitLab MCP Skill loads about 2k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 654 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zereight/gitlab-mcp at commit 0109168, republished under its MIT licence (© zereight). 654 words, ~1,967 tokens.

Download SKILL.mdSave it as .claude/skills/gitlab-mcp-skill/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
gitlab-mcp-skill
description
Use this skill when working with the GitLab MCP server tools for merge requests, issues, repositories, pipelines, work items, variables, dependency proxy, vulnerabilities, webhooks, search, CI catalog, and related GitLab workflows.

gitlab-mcp

GitLab MCP server providing 268 tools: 266 tools across 22 toolsets, plus execute_graphql and the always-available discover_tools meta-tool.

For exact generated parameter tables, see docs/tools/. Use this file for workflow shape and high-signal parameter hints.

Toolsets

ToolsetDefaultEnable with
merge_requests (45 tools)yes-
issues (24 tools)yes-
repositories (7 tools)yes-
branches (15 tools)yes-
projects (11 tools)yes-
labels (5 tools)yes-
ci (4 tools)yes-
groups (1 tool)yes-
users (7 tools)yes-
pipelines (56 tools)noUSE_PIPELINE=true or GITLAB_TOOLSETS=pipelines
milestones (17 tools)noUSE_MILESTONE=true or GITLAB_TOOLSETS=milestones
wiki (10 tools)noUSE_GITLAB_WIKI=true or GITLAB_TOOLSETS=wiki
releases (7 tools)noGITLAB_TOOLSETS=releases
tags (5 tools)noGITLAB_TOOLSETS=tags
snippets (5 tools)noGITLAB_TOOLSETS=snippets
workitems (18 tools)noGITLAB_TOOLSETS=workitems
webhooks (6 tools)noGITLAB_TOOLSETS=webhooks
search (3 tools)noGITLAB_TOOLSETS=search
variables (10 tools)noGITLAB_TOOLSETS=variables
dependency_proxy (4 tools)noGITLAB_TOOLSETS=dependency_proxy
vulnerabilities (4 tools)noGITLAB_TOOLSETS=vulnerabilities
orbit (4 tools)noGITLAB_TOOLSETS=orbit

Enable all: GITLAB_TOOLSETS=all. Use GITLAB_TOOLS to enable individual tools outside their toolset. discover_tools can list and activate opt-in categories for the current session. execute_graphql is not in a toolset; enable it explicitly with GITLAB_TOOLS=execute_graphql.

The per-toolset counts above sum to 268 because get_branch and list_branches are each listed in both merge_requests and branches; the unique tool count across all toolsets is 266.

Key Workflows

Code Review (see reference/code-review.md)
  1. list_merge_request_changed_files - get file paths only (no diffs)
  2. get_merge_request_file_diff - get diffs for 3-5 files per call (batch)
  3. create_merge_request_thread or create_draft_note - leave review comments
  4. bulk_publish_draft_notes - publish all drafts at once
MR Lifecycle (see reference/merge-requests.md)

create_merge_request -> review -> approve_merge_request -> merge_merge_request

Issue Management (see reference/issues.md)

create_issue -> create_issue_link -> create_issue_note -> update_issue

Use update_issue_description_patch for small edits to long issue descriptions instead of resending the full body.

Projects & Namespaces
  • get_project, list_projects, update_project - inspect or change project settings
  • list_project_members, list_group_members - search members by name or username within a project or group
  • list_namespaces, get_namespace, verify_namespace - find target namespaces before creating projects/groups
  • verify_namespace.parent_id scopes nested namespace checks
  • create_repository.namespace_id creates a project under a group namespace
Branches & Commits
  • create_branch, list_branches, get_branch, delete_branch
  • Protected branches: list_protected_branches, get_protected_branch, protect_branch, unprotect_branch, update_default_branch
  • Commits: list_commits, get_commit, get_commit_diff, get_file_blame, list_commit_statuses, create_commit_status
CI
  • Lint configs: validate_ci_lint, validate_project_ci_lint
  • Catalog: list_ci_catalog_resources, get_ci_catalog_resource
  • Pipelines/jobs/deployments: see reference/pipelines.md
Work Items (see reference/work-items.md)

list_work_items -> get_work_item -> update_work_item -> create_work_item_note

Variables & Dependency Proxy

Enable with GITLAB_TOOLSETS=variables or GITLAB_TOOLSETS=dependency_proxy.

  • Variables: project/group CRUD tools (list_*_variables, get_*_variable, create_*_variable, update_*_variable, delete_*_variable)
  • Dependency proxy: get_dependency_proxy_settings, update_dependency_proxy_settings, list_dependency_proxy_blobs, purge_dependency_proxy_cache
  • Webhooks: see reference/webhooks.md
  • Code search: see reference/search.md
Show full SKILL.md (259 more words)Show less
Vulnerability Triage (see reference/vulnerability-triage.md)

Enable with GITLAB_TOOLSETS=vulnerabilities (requires GitLab Ultimate).

list_project_vulnerabilities -> get_vulnerability -> dismiss_vulnerability or confirm_vulnerability

File Operations
  • Read: get_file_contents, get_repository_tree
  • Write: create_or_update_file (single file), push_files (multiple files in one commit)

Parameter Hints

  • project_id: numeric ID or URL-encoded path (group%2Fsubgroup%2Fproject)
  • namespace_id: numeric namespace ID for create_repository; use list_namespaces/verify_namespace first
  • parent_id: scope subgroup creation or verify_namespace for nested groups
  • MR lookup: provide mergeRequestIid OR branchName (not both)
  • list_issues: default scope = created by current user. Use scope: "all" for all issues
  • list_merge_requests: without project_id returns user's MRs across all projects
  • CI catalog resource lookup: provide exactly one of id or full_path
  • emoji reactions: merge request, issue, and work item reaction tools use GitLab emoji names like thumbsup, rocket, or eyes
  • work items: status and custom fields require GitLab Premium/Ultimate features
  • execute_graphql: escape double quotes in query strings

Destructive Tools (require caution)

cancel_pipeline, cancel_pipeline_job, delete_branch, delete_deployment, approve_deployment, delete_draft_note, delete_environment, erase_pipeline_job, delete_group_milestone, delete_group_variable, delete_group_wiki_page, delete_issue, delete_issue_emoji_reaction, delete_issue_link, delete_issue_note_emoji_reaction, delete_label, delete_merge_request_discussion_note, delete_merge_request_emoji_reaction, delete_merge_request_note, delete_merge_request_note_emoji_reaction, delete_milestone, delete_pipeline, delete_pipeline_schedule, delete_pipeline_schedule_variable, delete_pipeline_trigger, delete_project_variable, delete_release, delete_review_app_environments, delete_snippet, delete_tag, delete_webhook, delete_wiki_page, delete_work_item_emoji_reaction, delete_work_item_note_emoji_reaction, merge_merge_request, protect_branch, purge_dependency_proxy_cache, push_files, stop_environment, stop_stale_environments, unprotect_branch, update_default_branch

Advanced

  • Dynamic discovery: discover_tools lists and activates opt-in toolsets at runtime
  • GraphQL: execute_graphql for queries not covered by REST tools
  • Tool docs: docs/tools/ is generated from tools/registry.ts; prefer it for exact schemas
  • Remote MCP OAuth: when GITLAB_MCP_OAUTH=true, POST /register (DCR) is rate-limited per client IP (default 20/hour via MCP SDK; tune with OAUTH_REGISTER_RATE_LIMIT_PER_HOUR). Separate from MAX_REQUESTS_PER_MINUTE and GitLab API quotas — see environment-variables.md
  • Zoekt search: search_code, search_project_code, search_group_code (requires advanced search enabled)
  • Work Items: GraphQL-based alternative to issues (Premium/Ultimate features)

© zereight, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files in skills/gitlab-mcp of zereight/gitlab-mcp.

  • SKILL.md
  • reference/code-review.md
  • reference/issues.md
  • reference/merge-requests.md
  • reference/pipelines.md
  • reference/search.md
  • reference/vulnerability-triage.md
  • reference/webhooks.md
  • reference/work-items.md

Open the folder on GitHubat commit 0109168

Compare with similar skills

GitLab MCP Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitLab MCP Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitLab MCP Skill this skillzereight/gitlab-mcp2k—~2kAutomated safety check: PassMIT
Zalo AgentPhucMPham/zalo-agent-cli161—~2.3kAutomated safety check: PassMIT
SpikardGoldziher/spikard123—~799Automated safety check: PassMIT
X Twitter ScraperXquik-dev/x-twitter-scraper209—~2.6kAutomated safety check: PassMIT
Yolfi Paymentsyolfinance/yolfi-agent178—~1.2kAutomated safety check: PassMIT
Frontmcp Channelsagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Zalo Agent

    PhucMPham/zalo-agent-cli

    Automate Zalo messaging, Official Account (OA), and MCP server integration via zalo-agent-cli.

    161 GitHub stars~2.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Spikard

    Goldziher/spikard

    Scaffold Spikard projects and generate code from OpenAPI, AsyncAPI, OpenRPC, GraphQL, and Protobuf schemas using the Spikard CLI or its MCP server.

    123 GitHub stars~799 tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • X Twitter Scraper

    Xquik-dev/x-twitter-scraper

    Use Xquik to fetch X (Twitter) data or act through a connected account: search, profiles, followers, replies, threads, timelines, media downloads, bulk exports, trends, monitors, signed webhooks…

    209 GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Yolfi Payments

    yolfinance/yolfi-agent

    Add Yolfi crypto checkout, payment links, and webhook handling to an app through @yolfi/agent or the Yolfi MCP server.

    178 GitHub stars~1.2k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Frontmcp Channels

    agentfront/frontmcp

    A skill your agent uses when pushing real-time notifications or events into Claude Code (or another MCP client) sessions, or building two-way chat bridges.

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • E2a Doctor

    tokencanopy/e2a

    A skill your agent uses when an existing e2a MCP connection, inbox, custom domain, protection policy, webhook, or message delivery is failing or unclear.

    192 GitHub stars~994 tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from zereight/gitlab-mcp

All 24 skills in this repo
  • OMG Mode Canceller

    zereight/gitlab-mcp

    Detects which autonomous OMG mode is currently active - Autopilot, Ralph, Ultrawork, UltraQA, Team or Self-Improve - and shuts it down cleanly.

    2k GitHub starsUsed in 1 repo~690 tokens
    Auto-check passed
  • CCG Tri-Model Orchestration

    zereight/gitlab-mcp

    Runs a task through Codex and Gemini CLIs in parallel alongside Claude, then synthesizes the three outputs into one answer with agreements and conflicts called out.

    2k GitHub starsUsed in 1 repo~657 tokens
    Auto-check passed
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Remember Project Knowledge

    zereight/gitlab-mcp

    Sorts what you learned in a session into the right memory surface, filtering out ephemeral notes and duplicates before anything is stored.

    2k GitHub starsUsed in 1 repo~846 tokens
    Auto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    Auto-check: notes
  • Skill Inventory Stocktake

    zereight/gitlab-mcp

    Audits a project's skill directories for broken frontmatter, missing template sync and quality gaps, then produces a health report of what needs fixing.

    2k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed

Categories

Questions about GitLab MCP Skill

What does GitLab MCP Skill do?

A skill your agent uses when working with the GitLab MCP server tools for merge requests, issues, repositories, pipelines, work items, variables, dependency proxy, vulnerabilities, webhooks, search…. GitLab MCP Skill is an agent skill from zereight/gitlab-mcp. Use this skill when working with the GitLab MCP server tools for merge requests, issues, repositories, pipelines, work items, variables, dependency proxy, vulnerabilities, webhooks, search, CI catalog, and related GitLab workflows.

When should I use GitLab MCP Skill?

GitLab MCP Skill fits situations like: working with the GitLab MCP server tools for merge requests; dependency proxy; vulnerabilities; related GitLab workflows.

How do I install GitLab MCP Skill in Claude Code?

Run `npx skills add zereight/gitlab-mcp --skill gitlab-mcp-skill -a claude-code`. Or copy the skill folder (skills/gitlab-mcp in zereight/gitlab-mcp) into .claude/skills/gitlab-mcp-skill in your project. Claude Code loads it when a task matches its description.

How do I install GitLab MCP Skill in Codex?

Run `npx skills add zereight/gitlab-mcp --skill gitlab-mcp-skill -a codex`. Or copy the skill folder (skills/gitlab-mcp in zereight/gitlab-mcp) into .agents/skills/gitlab-mcp-skill in your project. Codex loads it when a task matches its description.

Can I use GitLab MCP Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zereight/gitlab-mcp --skill gitlab-mcp-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gitlab-mcp-skill, .gemini/skills/gitlab-mcp-skill, .github/skills/gitlab-mcp-skill and .opencode/skills/gitlab-mcp-skill in your project.

What does GitLab MCP Skill need to run?

SKILL.md names no scripts, command-line tools or credentials: GitLab MCP Skill is instructions for the agent only.

Does GitLab MCP Skill access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is GitLab MCP Skill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitLab MCP Skill use?

GitLab MCP Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitLab MCP Skill use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitLab MCP Skill?

Skills that share tags, products or a category with GitLab MCP Skill: Zalo Agent (PhucMPham/zalo-agent-cli, 161 stars), Spikard (Goldziher/spikard, 123 stars), X Twitter Scraper (Xquik-dev/x-twitter-scraper, 209 stars) and Yolfi Payments (yolfinance/yolfi-agent, 178 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitLab MCP Skill?

zereight (a GitHub user) maintains it in zereight/gitlab-mcp, which has 2,027 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: zereight/gitlab-mcp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.