Microsoft's Azure DevOps MCP Server Passes Hidden Pull Request Instructions Directly to AI Agents
Manifold Security researchers found that Microsoft's official Azure DevOps MCP server returns pull request descriptions verbatim, hidden HTML comments included. When developers ask AI agents to review those PRs, the agents follow the attacker's embedded instructions using the developer's own credentials, gaining access to projects the attacker could never reach directly.