Azure DevOps MCP: Indirect prompt injection, the AI review agent as an exfiltration vector
The official Microsoft MCP server for Azure DevOps does not sanitize pull request descriptions before passing them to an LLM. As a result, a hidden instruction in a PR comment can redirect the AI review agent to projects the attacker does not control and silently exfiltrate their content.
Aug 13, 2026 7 2





