Atlas / MCP servers / tiberriver256 / Azure DevOps

Azure DevOpsCAUTION

mcp/tiberriver256/azure-devops-4

An MCP server for Azure DevOps

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
49 31r · 16w · 2d
Transport
stdio
License
MIT
Stars
394
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server implementation for Azure DevOps, allowing AI assistants to interact with Azure DevOps APIs through a standardized protocol.

Looking for the official server? Microsoft maintains a product-supported Azure DevOps MCP at microsoft/azure-devops-mcp. If you use Azure DevOps Services (cloud), start there. This community server remains a good fit when you need Azure DevOps Server (on-premises) support — especially older versions that may not work with Microsoft's MCP — or features not yet available in the official server. See Discussion #237 for more context. See ROADMAP.md for where this server differentiates and what is planned.

Overview

This server implements the Model Context Protocol (MCP) for Azure DevOps, enabling AI assistants like Claude to interact with Azure DevOps resources securely. The server acts as a bridge between AI models and Azure DevOps APIs, providing a standardized way to:

  • Access and manage projects, work items, repositories, and more
  • Create and update work items, branches, and pull requests
  • Execute common DevOps workflows through natural language
  • Access repository content via standardized resource URIs
  • Safely authenticate and interact with Azure DevOps resources

Server Structure

The server is structured around the Model Context Protocol (MCP) for communicating with AI assistants. It provides tools for interacting with Azure DevOps resources including:

  • Projects
  • Work Items
  • Repositories
  • Pull Requests
  • Branches
  • Pipelines

Core Components

  • AzureDevOpsServer: Main server class that initializes the MCP server and registers tools
  • Feature Modules: Organized by feature area (work-items, projects, repositories, etc.)
  • Request Handlers: Each feature module
Read from source at commit f11663873237OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-server-azure-devops --env AZURE_DEVOPS_AUTH_METHOD=${AZURE_DEVOPS_AUTH_METHOD} -- npx -y @tiberriver256/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server-azure-devops": {
      "command": "npx",
      "args": [
        "-y",
        "@tiberriver256/[email protected]"
      ],
      "env": {
        "AZURE_DEVOPS_AUTH_METHOD": "${AZURE_DEVOPS_AUTH_METHOD}"
      }
    }
  }
}
03

Exposed tools (49)

31 read · 16 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AgilereadAgile process
BugreadTracks defects in the product
add_pull_request_commentwriteAdd a comment to a pull request (repositoryId optional; derived from pullRequestId when omitted)
create_branchwriteCreate a new branch from an existing one
create_pull_requestwriteCreate a new pull request, including reviewers, linked work items, and optional tags
create_wikiwriteCreate a new wiki in the project
create_wiki_pagewriteCreate a new page in a wiki. If the page already exists at the specified path, it will be updated.
create_work_itemwriteCreate a new work item
create_work_item_attachmentwriteUpload a file and attach it to a work item. The file is read from the local filesystem, uploaded to Azure DevOps, and linked to the specified work item.
delete_work_item_attachmentdestructiveDelete an attachment from a work item. The attachment ID can be obtained from the work item relations.
download_pipeline_artifactwriteDownload a file from a pipeline run artifact and return its textual content
get_all_repositories_treereadDisplays a hierarchical tree view of files and directories across multiple Azure DevOps repositories within a project, based on their default branches
get_file_contentreadGet content of a file or directory from a repository
get_mereadGet details of the authenticated user (id, displayName, email)
get_pipelinereadGet details of a specific pipeline
get_pipeline_logreadRetrieve a specific pipeline log using the timeline log identifier
get_pipeline_runwriteGet details for a specific pipeline run
get_projectreadGet details of a specific project
get_project_detailsreadGet comprehensive details of a project including process, work item types, and teams
get_pull_requestreadGet a pull request by ID (no repositoryId required; best for Azure DevOps Server where PR IDs are project-scoped)
get_pull_request_changesreadGet the files changed in a pull request, their unified diffs, source/target branch names, and the status of policy evaluations
get_pull_request_commentsreadGet comments from a specific pull request
get_repositoryreadGet details of a specific repository
get_repository_detailsreadGet detailed information about a repository including statistics and refs
get_repository_treereadDisplays a hierarchical tree view of files and directories within a single repository starting from an optional path
get_wiki_pagereadGet the content of a wiki page
get_wikisreadGet details of wikis in a project
get_work_itemreadGet details of a specific work item
get_work_item_attachmentwriteDownload an attachment from Azure DevOps and save it to the local filesystem. The attachment ID can be obtained from the work item relations.
get_work_item_commentsreadGet comments and discussion history for a specific work item
list_commitsreadList recent commits on a branch including file-level diff content for each commit
list_organizationsreadList all Azure DevOps organizations accessible to the current authentication
list_pipeline_runsreadList recent runs for a pipeline
list_pipelinesreadList pipelines in a project
list_projectsreadList all projects in an organization
list_pull_requestsreadList pull requests in a repository
list_repositoriesreadList repositories in a project
list_wiki_pagesreadList pages within an Azure DevOps wiki
list_work_itemsreadList work items in a project
manage_work_item_linkdestructiveAdd or remove links between work items
pipeline_timelinewriteRetrieve the timeline of stages and jobs for a pipeline run, to reduce the amount of data returned, you can filter by state and result
search_codereadSearch for code across repositories in a project
search_wikireadSearch for content across wiki pages in a project
search_work_itemsreadSearch for work items across projects in Azure DevOps
trigger_pipelinewriteTrigger a pipeline run
update_pull_requestwriteUpdate an existing pull request with new properties, manage reviewers and work items, and add or remove tags
update_pull_request_thread_statuswriteUpdate the status of a comment thread in a pull request (repositoryId optional; derived from pullRequestId when omitted)
update_wiki_pagewriteUpdate content of a wiki page
update_work_itemwriteUpdate an existing work item
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (13)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/features/search/search-work-items/feature.spec.unit.ts:21
.mockResolvedValue({ token: 'mock-azure-identity-token' }),
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_work_item_attachment, manage_work_item_link
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxfmtrc.json
.oxfmtrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
.pi/extensions/test-watch.ts:134
return createHash('sha1').update(text).digest('hex');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/organizations/__test__/test-helpers.ts:1
import { AzureDevOpsConfig } from '../../../shared/types';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/organizations/__test__/test-helpers.ts:2
import { AuthenticationMethod } from '../../../shared/auth';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/organizations/index.spec.unit.ts:4
import { AuthenticationMethod } from '../../shared/auth';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/organizations/index.ts:16
} from '../../shared/types/request-handler';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/organizations/index.ts:18
import { AzureDevOpsConfig } from '../../shared/types';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@azure/identity, @modelcontextprotocol/sdk, axios, azure-devops-node-api, diff, dotenv, jszip, minimatch
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
shrimp-rules.md:169
- Used in [`src/index.ts`](src/index.ts:1) to load environment variables from a `.env` file.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha f11663873237full audit observations/trust-audit/mcp-server/tiberriver256__azure-devops-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-02f11663873237CAUTIONB87first audit
06

Questions

What is the Azure DevOps MCP server?

An MCP server for Azure DevOps

What tools does Azure DevOps expose?

49 in total: 31 read-only, 16 that write, and 2 that can delete or overwrite (delete_work_item_attachment, manage_work_item_link). Every one is listed on this page with its risk.

Is Azure DevOps safe to connect to an agent?

With care. The audit graded it B (87/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Azure DevOps need?

It reads AZURE_DEVOPS_AUTH_METHOD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Azure DevOps run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @tiberriver256/mcp-server-azure-devops at 0.1.48.

How current is this page?

The grade is for one exact copy of the source (f11663873237), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement