Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
AI disclosure
Summary
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had
Discussion on
Trending posts from X.
Agreed, and even for the tools I've built for myself I've found myself constantly killing old agent versions of them that were useful then, that are now folded into mega agents that I use everything through
— Ben Davis (@davis7) July 21, 2026