Azure DevOps AssistantSAFE
A Model Context Protocol (MCP) server enabling AI assistants to interact with Azure DevOps services via Python SDK.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
⚠️ NOTICE: Official Server Available Please use the official Microsoft Azure DevOps MCP server instead: https://github.com/microsoft/azure-devops-mcp This repository is no longer maintained. The official Microsoft server provides better support, ongoing maintenance, and the latest features.
A Model Context Protocol (MCP) server enabling AI assistants to interact with Azure DevOps services.
Overview
This project implements a Model Context Protocol (MCP) server that allows AI assistants (like Claude) to interact with Azure DevOps, providing a bridge between natural language interactions and the Azure DevOps REST API.
Features
Currently implemented:
Work Item Management
- Query Work Items: Search for work items using WIQL queries
- Get Work Item Details: View complete work item information
- Create Work Items: Add new tasks, bugs, user stories, and other work item types
- Update Work Items: Modify existing work items' fields and properties
- Add Comments: Post comments on work items
- View Comments: Retrieve the comment history for a work item
- Parent-Child Relationships: Establish hierarchy between work items
Project Management
- Get Projects: View all accessible projects in the organization
- Get Teams: List all teams within the organization
- Team Members: View team membership information
- Team Area Paths: Retrieve area paths assigned to teams
- Team Iterations: Access team iteration/sprint configurations
Planned features:
- Pipeline Operations: Query pipeline status and trigger new pipeline runs
- Pull Request Handling: Create, update, and review Pull Requests
- Sprint Management: Plan and manage sprints and iterations
- Branch Policy Administration: Configure and manage branch policies
Getting Started
Prerequisites
- Python 3.10+
- Azure DevOps account with appropriate permissions
- Personal Access Token (PA
b946a1bc59bdOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-azure-devops -- uvx mcp-azure-devops
{
"mcpServers": {
"mcp-azure-devops": {
"command": "uvx",
"args": [
"mcp-azure-devops"
]
}
}
}Exposed tools (21)
17 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_parent_child_link | write | |
add_work_item_comment | write | |
create_work_item | write | |
get_all_teams | read | |
get_process_details | read | |
get_project_process_id | read | |
get_projects | read | |
get_team_area_paths | read | |
get_team_iterations | read | |
get_team_members | read | |
get_work_item | read | |
get_work_item_comments | read | |
get_work_item_template | read | |
get_work_item_templates | read | |
get_work_item_type | read | |
get_work_item_type_field | read | |
get_work_item_type_fields | read | |
get_work_item_types | read | |
list_processes | read | |
query_work_items | read | |
update_work_item | write |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
b946a1bc59bdfull audit observations/trust-audit/mcp-server/vortiago__azure-devops-assistant.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b946a1bc59bd | SAFE | B | 89 | first audit |
Questions
What is the Azure DevOps Assistant MCP server?
A Model Context Protocol (MCP) server enabling AI assistants to interact with Azure DevOps services via Python SDK.
What tools does Azure DevOps Assistant expose?
21 in total: 17 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Azure DevOps Assistant safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Azure DevOps Assistant need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (b946a1bc59bd), read on 2026-10-07. The repository is watched and re-audited when it changes.