@fabriciofs/mcp-azure-devops
npm
v1.0.2
Published by @fabriciofs — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
MCP Server for Azure DevOps with PAT-only authentication - All 82 tools from Microsoft's official MCP with simple PAT auth
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 4 = 96. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Untrusted-input tools ([repo_list_pull_request_thread_comments, pipelines_download_artifact, wiki_get_page, wiki_get_page_content]) co-exist with external-action tools ([repo_create_pull_request, repo_create_pull_request_thread]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [repo_list_pull_request_thread_comments, pipelines_download_artifact, wiki_get_page, wiki_get_page_content] → sinks [repo_create_pull_request, repo_cr
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow repo_list_pull_request_thread_comments → repo_create_pull_request
Tool "wit_work_item_unlink" can write, overwrite or delete files (keyword "unlink" in tool name). Verify it is scoped to a safe directory.
Fix: Constrain file operations to an explicit, non-sensitive root; reject path traversal.
Location: tool wit_work_item_unlink
Tool "wit_work_item_unlink" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool wit_work_item_unlink
Each tool and what it can reach — statically extracted from the published source.
pipelines_download_artifactingests untrusted inputrepo_create_pull_requestnetwork egressrepo_create_pull_request_threadnetwork egressrepo_list_pull_request_thread_commentsingests untrusted inputwiki_get_pageingests untrusted inputwiki_get_page_contentingests untrusted inputwit_work_item_unlinkwrites filesadvsec_get_alert_detailsno sensitive capabilityadvsec_get_alertsno sensitive capabilitycore_get_identity_idsno sensitive capabilitycore_list_project_teamsno sensitive capabilitycore_list_projectsno sensitive capabilitypipelines_create_pipelineno sensitive capabilitypipelines_get_build_changesno sensitive capabilitypipelines_get_build_definition_revisionsno sensitive capabilitypipelines_get_build_definitionsno sensitive capabilitypipelines_get_build_logno sensitive capabilitypipelines_get_build_log_by_idno sensitive capabilitypipelines_get_build_statusno sensitive capabilitypipelines_get_buildsno sensitive capabilitypipelines_get_runno sensitive capabilitypipelines_list_artifactsno sensitive capabilitypipelines_list_runsno sensitive capabilitypipelines_run_pipelineno sensitive capabilitypipelines_update_build_stageno sensitive capabilityrepo_create_branchno sensitive capabilityrepo_get_branch_by_nameno sensitive capabilityrepo_get_pull_request_by_idno sensitive capabilityrepo_get_repo_by_name_or_idno sensitive capabilityrepo_list_branches_by_repono sensitive capabilityrepo_list_my_branches_by_repono sensitive capabilityrepo_list_pull_request_threadsno sensitive capabilityrepo_list_pull_requests_by_commitsno sensitive capabilityrepo_list_pull_requests_by_repo_or_projectno sensitive capabilityrepo_list_repos_by_projectno sensitive capabilityrepo_reply_to_commentno sensitive capabilityrepo_search_commitsno sensitive capabilityrepo_update_pull_requestno sensitive capabilityrepo_update_pull_request_reviewersno sensitive capabilityrepo_update_pull_request_threadno sensitive capabilitysearch_codeno sensitive capabilitysearch_wikino sensitive capabilitysearch_workitemno sensitive capabilitytestplan_add_test_cases_to_suiteno sensitive capabilitytestplan_create_test_caseno sensitive capabilitytestplan_create_test_planno sensitive capabilitytestplan_create_test_suiteno sensitive capabilitytestplan_list_test_casesno sensitive capabilitytestplan_list_test_plansno sensitive capabilitytestplan_list_test_suitesno sensitive capabilitytestplan_show_test_results_from_build_idno sensitive capabilitytestplan_update_test_case_stepsno sensitive capabilitywiki_create_or_update_pageno sensitive capabilitywiki_get_wikino sensitive capabilitywiki_list_pagesno sensitive capabilitywiki_list_wikisno sensitive capabilitywit_add_artifact_linkno sensitive capabilitywit_add_child_work_itemsno sensitive capabilitywit_add_work_item_commentno sensitive capabilitywit_create_work_itemno sensitive capabilitywit_get_queryno sensitive capabilitywit_get_query_results_by_idno sensitive capabilitywit_get_work_itemno sensitive capabilitywit_get_work_item_typeno sensitive capabilitywit_get_work_items_batch_by_idsno sensitive capabilitywit_get_work_items_for_iterationno sensitive capabilitywit_link_work_item_to_pull_requestno sensitive capabilitywit_list_backlog_work_itemsno sensitive capabilitywit_list_backlogsno sensitive capabilitywit_list_work_item_commentsno sensitive capabilitywit_list_work_item_revisionsno sensitive capabilitywit_my_work_itemsno sensitive capabilitywit_update_work_itemno sensitive capabilitywit_update_work_items_batchno sensitive capabilitywit_work_items_linkno sensitive capabilitywork_assign_iterationsno sensitive capabilitywork_create_iterationsno sensitive capabilitywork_get_iteration_capacitiesno sensitive capabilitywork_get_team_capacityno sensitive capabilitywork_list_iterationsno sensitive capabilitywork_list_team_iterationsno sensitive capabilitywork_update_team_capacityno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.0.2 latest |
A 96/100 | 3 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @fabriciofs/mcp-azure-devops --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 17 side by side →
MCP server for Azure DevOps Server 2022 / TFS - READ-ONLY access to builds, work items, releases, git, pipelines, and test results
MCP server for interacting with Azure DevOps
MCP server for interacting with Azure DevOps
MCP server for Azure DevOps integration with wikis, test plans, and work items
MCP server for Azure DevOps agent and queue management
MCP server for Azure DevOps Work Item Tracking integration
Hotel booking MCP server — 300K+ properties, real confirmation numbers, loyalty programs. Builders monetize every booking via Stripe Connect. The first MCP server that completes real hotel reservations inside AI conversations.
Manage AdGuard Home through AI assistants
Read-only Azure DevOps for MCP clients using only your existing browser session — no PAT, no Azure CLI. Browse work items, pull requests, comments, attachments and Artifacts feeds across every project, repo and feed you can access.
MCP server for Adobe Experience Manager Assets integration development
Servidor MCP para el tiempo oficial de España (API pública OpenData de AEMET). Predicción, observación y avisos como herramientas MCP tipadas.
A standalone MCP stdio bridge for Affinity by Canva's local MCP SSE server.