Azure Devops (fabriciofs) MCP Server

@fabriciofs/mcp-azure-devops npm v1.0.2

Published by @fabriciofs — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.

MCP Server for Azure DevOps with PAT-only authentication - All 82 tools from Microsoft's official MCP with simple PAT auth

Trust grade
A
96/100
Last scanned get badge →
Trust
A · 96/100
Adoption risk for you: the threat score, then adjusted down for blast radius, publisher verification and how much the scan could see. Deterministic; every point is auditable.
Capability
Moderate
Blast radius if it went rogue — what the server’s tools could reach. Independent of trust.
Coverage
Source
How much the scan could actually inspect. Shallow coverage is stated, never hidden.
Share this Trust Score
𝕏 Share LinkedIn Reddit
A Why this grade threat 100 − adoption risk = 96/100

The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.

1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:

The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.

2. Client adoption risk — 100 − 4 = 96. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:

PointsAdoption-risk factor
−3 capability blast radius (moderate) — client exposure if the model is manipulated
−1 publisher verification (public source) — no provenance, but the source is public and inspectable

Capability observations and info notes are shown under Findings but never scored. Open any row's finding below for the file, line and evidence behind a deduction.

Findings 3

medium Untrusted input can drive an external actionMTC-FLOW-005

Untrusted-input tools ([repo_list_pull_request_thread_comments, pipelines_download_artifact, wiki_get_page, wiki_get_page_content]) co-exist with external-action tools ([repo_create_pull_request, repo_create_pull_request_thread]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.

Evidence: untrusted [repo_list_pull_request_thread_comments, pipelines_download_artifact, wiki_get_page, wiki_get_page_content] → sinks [repo_create_pull_request, repo_cr

Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.

Location: flow repo_list_pull_request_thread_comments → repo_create_pull_request

medium Tool "wit_work_item_unlink" can modify the filesystemMTC-CAP-002

Tool "wit_work_item_unlink" can write, overwrite or delete files (keyword "unlink" in tool name). Verify it is scoped to a safe directory.

Fix: Constrain file operations to an explicit, non-sensitive root; reject path traversal.

Location: tool wit_work_item_unlink

low Mutating tool "wit_work_item_unlink" declares no destructiveHintMTC-CAP-005

Tool "wit_work_item_unlink" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.

Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.

Location: tool wit_work_item_unlink

Tools 82

Each tool and what it can reach — statically extracted from the published source.

  • pipelines_download_artifactingests untrusted input
  • repo_create_pull_requestnetwork egress
  • repo_create_pull_request_threadnetwork egress
  • repo_list_pull_request_thread_commentsingests untrusted input
  • wiki_get_pageingests untrusted input
  • wiki_get_page_contentingests untrusted input
  • wit_work_item_unlinkwrites files
  • advsec_get_alert_detailsno sensitive capability
  • advsec_get_alertsno sensitive capability
  • core_get_identity_idsno sensitive capability
Show 72 more tools ↓
  • core_list_project_teamsno sensitive capability
  • core_list_projectsno sensitive capability
  • pipelines_create_pipelineno sensitive capability
  • pipelines_get_build_changesno sensitive capability
  • pipelines_get_build_definition_revisionsno sensitive capability
  • pipelines_get_build_definitionsno sensitive capability
  • pipelines_get_build_logno sensitive capability
  • pipelines_get_build_log_by_idno sensitive capability
  • pipelines_get_build_statusno sensitive capability
  • pipelines_get_buildsno sensitive capability
  • pipelines_get_runno sensitive capability
  • pipelines_list_artifactsno sensitive capability
  • pipelines_list_runsno sensitive capability
  • pipelines_run_pipelineno sensitive capability
  • pipelines_update_build_stageno sensitive capability
  • repo_create_branchno sensitive capability
  • repo_get_branch_by_nameno sensitive capability
  • repo_get_pull_request_by_idno sensitive capability
  • repo_get_repo_by_name_or_idno sensitive capability
  • repo_list_branches_by_repono sensitive capability
  • repo_list_my_branches_by_repono sensitive capability
  • repo_list_pull_request_threadsno sensitive capability
  • repo_list_pull_requests_by_commitsno sensitive capability
  • repo_list_pull_requests_by_repo_or_projectno sensitive capability
  • repo_list_repos_by_projectno sensitive capability
  • repo_reply_to_commentno sensitive capability
  • repo_search_commitsno sensitive capability
  • repo_update_pull_requestno sensitive capability
  • repo_update_pull_request_reviewersno sensitive capability
  • repo_update_pull_request_threadno sensitive capability
  • search_codeno sensitive capability
  • search_wikino sensitive capability
  • search_workitemno sensitive capability
  • testplan_add_test_cases_to_suiteno sensitive capability
  • testplan_create_test_caseno sensitive capability
  • testplan_create_test_planno sensitive capability
  • testplan_create_test_suiteno sensitive capability
  • testplan_list_test_casesno sensitive capability
  • testplan_list_test_plansno sensitive capability
  • testplan_list_test_suitesno sensitive capability
  • testplan_show_test_results_from_build_idno sensitive capability
  • testplan_update_test_case_stepsno sensitive capability
  • wiki_create_or_update_pageno sensitive capability
  • wiki_get_wikino sensitive capability
  • wiki_list_pagesno sensitive capability
  • wiki_list_wikisno sensitive capability
  • wit_add_artifact_linkno sensitive capability
  • wit_add_child_work_itemsno sensitive capability
  • wit_add_work_item_commentno sensitive capability
  • wit_create_work_itemno sensitive capability
  • wit_get_queryno sensitive capability
  • wit_get_query_results_by_idno sensitive capability
  • wit_get_work_itemno sensitive capability
  • wit_get_work_item_typeno sensitive capability
  • wit_get_work_items_batch_by_idsno sensitive capability
  • wit_get_work_items_for_iterationno sensitive capability
  • wit_link_work_item_to_pull_requestno sensitive capability
  • wit_list_backlog_work_itemsno sensitive capability
  • wit_list_backlogsno sensitive capability
  • wit_list_work_item_commentsno sensitive capability
  • wit_list_work_item_revisionsno sensitive capability
  • wit_my_work_itemsno sensitive capability
  • wit_update_work_itemno sensitive capability
  • wit_update_work_items_batchno sensitive capability
  • wit_work_items_linkno sensitive capability
  • work_assign_iterationsno sensitive capability
  • work_create_iterationsno sensitive capability
  • work_get_iteration_capacitiesno sensitive capability
  • work_get_team_capacityno sensitive capability
  • work_list_iterationsno sensitive capability
  • work_list_team_iterationsno sensitive capability
  • work_update_team_capacityno sensitive capability

Toxic flows 1

Cross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).

What this scan could not see

Versions 1

Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.

VersionScoreFindingsEngineScanned
v1.0.2 latest A 96/100 3 1.13.0 2026-09-07

Embed this score

Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.

MCP Trust Score: A · 96/100
Markdown (GitHub README)
[![MCP Trust Score](https://mcptrustchecker.com/registry/fabriciofs-mcp-azure-devops/badge.svg)](https://mcptrustchecker.com/registry/fabriciofs-mcp-azure-devops)
HTML
<a href="https://mcptrustchecker.com/registry/fabriciofs-mcp-azure-devops"><img src="https://mcptrustchecker.com/registry/fabriciofs-mcp-azure-devops/badge.svg" alt="MCP Trust Score" height="20"></a>
Prefer shields.io styling? Point it at https://mcptrustchecker.com/registry/fabriciofs-mcp-azure-devops/badge.json via https://img.shields.io/endpoint?url=…

Verify this score yourself

The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.

npx mcptrustchecker scan @fabriciofs/mcp-azure-devops --online

Use the free API → How scoring works

Other implementations of Azure Devops 16

Independent packages implementing the same tool, scanned with the same engine. Compare all 17 side by side →

More in Developer Tools