azure-devops-skill
Warn
Audited by Snyk on Feb 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly fetches user-generated content (wiki pages, pull request threads/comments, code search results, work item descriptions, and build logs) from Azure DevOps (e.g., SKILL.md references mcp__ado__wiki_get_page_content and the scripts include get_wiki_page, search_code, list_pull_request_threads, get_build_log/get_log_content), which the agent is expected to read and which could contain instructions that materially influence actions like running pipelines or updating PRs.
Audit Metadata