Azure DevOps MCP: an invisible comment in a PR diverts the AI reviewer agent
A simple comment hidden in an Azure DevOps pull request can turn the code reviewer's AI agent against them - and send it siphoning projects that the attacker normally wouldn't have access to. The vulnerability lies in Microsoft's official MCP server.
3 h ago 8 2


