azure-devops

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
README.md

This document is an operational guide for using an Azure DevOps Personal Access Token (AZURE_DEVOPS_TOKEN). It is not malware and contains no malicious code, but it demonstrates insecure practices that materially increase the chance of accidental credential exposure (embedding PATs in git remote URLs and using tokens directly on the command line). Treat the guidance as legitimate but risky: follow secure alternatives (credential helpers, Azure CLI, limited-scope short-lived tokens, avoid inline secrets, and rotate tokens if exposed).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:33 PM
Package URL
pkg:socket/skills-sh/openhands%2Fextensions%2Fazure-devops%2F@50e9ac414f88637cec0d4cee6cb978549edb00a0