Tag
A report on Microsoft's Azure DevOps MCP server reveals a confused-deputy attack where hidden PR text can manipulate AI review agents (Copilot CLI, Claude Code) into unintended tool calls with the user's permissions. Recommendations include using read-only identities and requiring separate approval steps.
OpenHands Enterprise now integrates with Azure DevOps, enabling users to comment on work items or PRs and have OpenHands automatically perform the work and open a pull request in Azure Repos.