mcp-server-azure-devops (Tiberriver256/mcp-server-azure-devops) is an MCP server listed on the M8ven Trust Index. It scores 55 out of 100, grade D. It declares 46 tools. No publisher has claimed this listing.
An MCP server for Azure DevOps
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
Tiberriver256
Source: github_topic · also listed on mcp.so, ModelScope, github_code, github_repo_search
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
list_organizationsList all Azure DevOps organizations accessible to the current authentication
list_pipelinesList pipelines in a project
get_pipelineGet details of a specific pipeline
list_pipeline_runsList recent runs for a pipeline
get_pipeline_runGet details for a specific pipeline run
download_pipeline_artifactDownload a file from a pipeline run artifact and return its textual content
pipeline_timelineRetrieve the timeline of stages and jobs for a pipeline run, to reduce the amount of data returned, you can filter by state and result
get_pipeline_logRetrieve a specific pipeline log using the timeline log identifier
trigger_pipelineTrigger a pipeline run
list_projectsList all projects in an organization
get_projectGet details of a specific project
get_project_detailsGet comprehensive details of a project including process, work item types, and teams
create_pull_requestCreate a new pull request, including reviewers, linked work items, and optional tags
get_pull_requestGet a pull request by ID (no repositoryId required; best for Azure DevOps Server where PR IDs are project-scoped)
list_pull_requestsList pull requests in a repository
get_pull_request_commentsGet comments from a specific pull request
add_pull_request_commentAdd a comment to a pull request (repositoryId optional; derived from pullRequestId when omitted)
update_pull_requestUpdate an existing pull request with new properties, manage reviewers and work items, and add or remove tags
get_pull_request_changesGet the files changed in a pull request, their unified diffs, source/target branch names, and the status of policy evaluations
get_pull_request_checksupdate_pull_request_thread_statusUpdate the status of a comment thread in a pull request (repositoryId optional; derived from pullRequestId when omitted)
get_repositoryGet details of a specific repository
get_repository_detailsGet detailed information about a repository including statistics and refs
list_repositoriesList repositories in a project
get_file_contentGet content of a file or directory from a repository
get_all_repositories_treeDisplays a hierarchical tree view of files and directories across multiple Azure DevOps repositories within a project, based on their default branches
get_repository_treeDisplays a hierarchical tree view of files and directories within a single repository starting from an optional path
create_branchCreate a new branch from an existing one
create_commitlist_commitsList recent commits on a branch including file-level diff content for each commit
search_codeSearch for code across repositories in a project
search_wikiSearch for content across wiki pages in a project
search_work_itemsSearch for work items across projects in Azure DevOps
get_meGet details of the authenticated user (id, displayName, email)
get_wikisGet details of wikis in a project
get_wiki_pageGet the content of a wiki page
create_wikiCreate a new wiki in the project
update_wiki_pageUpdate content of a wiki page
list_wiki_pagesList pages within an Azure DevOps wiki
create_wiki_pageCreate a new page in a wiki. If the page already exists at the specified path, it will be updated.
list_work_itemsList work items in a project
get_work_itemGet details of a specific work item
create_work_itemCreate a new work item
update_work_itemUpdate an existing work item
manage_work_item_linkAdd or remove links between work items
get_work_item_commentsGet comments and discussion history for a specific work item
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
AZURE_DEVOPS_API_VERSIONAPI version to use No LatestAZURE_DEVOPS_AUTH_METHOD"": "azure-identity",AZURE_DEVOPS_DEFAULT_PROJECT"": "your-project-name"AZURE_DEVOPS_ORG_URL"": "https://dev.azure.com/your-organization",AZURE_DEVOPS_PAT"": "<YOUR_PAT>",Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
46/46 tools missing one or more hints — list_organizations (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_pipelines (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_pipeline (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +43 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 0/46 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Secrets not written to files
1 secret value written to files
Avoid persisting secrets to disk. Keep them in memory or your secret manager.
Secrets not logged
1 secret value sent to console.log
Redact or omit secret values from log output.
Production dependencies are patched
0 critical, 14 high severity in production deps — @modelcontextprotocol/sdk@1.6.0 (high), @modelcontextprotocol/sdk@1.6.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/tiberriver256/mcp-server-azure-devops)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check