Diátaxis type: Reference Domain: Security Attributes Individual tools: 5 Meta-tool:
gitlab_security_attribute(GITLAB_MCP_TOOL_SURFACE=metacatalog) Dynamic IDs:security_attribute.*(default surface, viagitlab_execute_action) GitLab API: SecurityAttribute GraphQL object · Create · Update · Delete · Project update · Bulk update Audience: End users, AI assistant users Requires: GitLab Ultimate or Premium
Security attributes are namespace-level labels that classify GitLab groups and projects. Attributes belong to a security category, can be applied directly to a project, and can be added, removed, or replaced across multiple groups and projects in bulk.
On the default dynamic surface, these operations are the security_attribute.* entries of the canonical action catalog: find them with gitlab_find_action and run them with gitlab_execute_action by domain.action ID. With GITLAB_MCP_TOOL_SURFACE=individual, each is the tool named in the tables below.
This domain is distinct from security findings and vulnerabilities: security attributes are classification metadata, while findings and vulnerabilities represent scanner output and triage state.
"Create a security attribute called High under category 7" "Apply security attribute 9 to project 42" "Replace the security attributes on these projects"
| Annotation | ReadOnly | Destructive | Idempotent | Description |
|---|---|---|---|---|
| Create | — | No | No | Creates one or more new attributes |
| Update | — | No | Yes | Modifies metadata or project assignments |
| Delete | — | Yes | Yes | Destroys an attribute; protected by confirmation |
| Bulk | — | Yes | Yes | Applies, removes, or replaces assignments at scale; protected by confirmation |
Tools marked Delete or Bulk require confirmation before execution.
Create one or more security attributes under an existing security category.
| Annotation | Create |
|---|
| Parameter | Type | Required | Description |
|---|---|---|---|
namespace_id |
int | Yes | Numeric namespace ID |
category_id |
int | Yes | Numeric security category ID |
attributes |
array | Yes | Attributes to create; each item has name, description, and color |
Update a security attribute name, description, or color.
| Annotation | Update |
|---|
| Parameter | Type | Required | Description |
|---|---|---|---|
attribute_id |
int | Yes | Numeric security attribute ID |
name |
string | No | New attribute name |
description |
string | No | New attribute description |
color |
string | No | New color as a hex code, such as #FF0000 |
At least one of name, description, or color must be provided.
Delete a custom security attribute.
| Annotation | Delete |
|---|
| Parameter | Type | Required | Description |
|---|---|---|---|
attribute_id |
int | Yes | Numeric security attribute ID |
Destructive: Protected by confirmation prompt.
Add or remove security attributes on a project.
| Annotation | Update |
|---|
| Parameter | Type | Required | Description |
|---|---|---|---|
project_id |
int | Yes | Numeric project ID |
add_attribute_ids |
int[] | No | Security attribute IDs to add |
remove_attribute_ids |
int[] | No | Security attribute IDs to remove |
At least one of add_attribute_ids or remove_attribute_ids must be provided.
Add, remove, or replace security attributes across multiple groups and projects.
| Annotation | Bulk |
|---|
| Parameter | Type | Required | Description |
|---|---|---|---|
group_ids |
int[] | No | Numeric group IDs to update |
project_ids |
int[] | No | Numeric project IDs to update |
attribute_ids |
int[] | Yes | Security attribute IDs to apply |
mode |
string | Yes | Bulk mode: ADD, REMOVE, or REPLACE |
At least one of group_ids or project_ids must be provided.
Destructive: Protected by confirmation prompt because
REMOVEandREPLACEcan remove existing assignments.
| # | Tool Name | Category | Annotation |
|---|---|---|---|
| 1 | gitlab_create_security_attribute |
Mutation | Create |
| 2 | gitlab_update_security_attribute |
Mutation | Update |
| 3 | gitlab_delete_security_attribute |
Mutation | Delete |
| 4 | gitlab_update_project_security_attributes |
Mutation | Update |
| 5 | gitlab_bulk_update_security_attributes |
Mutation | Bulk |
- GitLab SecurityAttribute GraphQL object
- Security Categories — category management for security attributes
- Security Findings — pipeline scan findings
- Vulnerabilities — tracked vulnerability lifecycle management