Microsoft Copilot security directory
Azure DevOps
Published by Microsoft
High risk
Azure DevOps provides services for teams to share code, track work, and ship software - for any language, all in a single package. It's the perfect complement to your IDE.
Security assessment
Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
- Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
- Stores long-lived access tokens: This connector requires persistent credentials. If those tokens leak or are stolen, whoever holds them gets the same access you granted.
Available capabilities
This add-on exposes 35 tools or capabilities.
- Add work item link (Preview)
- Create a new release
- Create a work item
- Create work item comment (Preview)
- Delete work item comment (Preview)
- Delete work item link (Preview)
- Get a User Profile
- Get build (Preview)
- Get build timeline (Preview)
- Get query results
- Get query results [DEPRECATED]
- Get work item attachment (Preview)
- Get work item children
- Get work item comments (Preview)
- Get work item details
- Get work item details (V2) (Preview)
- List build requesters (Preview)
- List builds (Preview)
- List Git branches (Preview)
- List Git repositories
- List iterations
- List Organizations
- List pipeline runs
- List pipelines
The interactive security report will load automatically.