azure_devops — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited azure_devops (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You have access to an environment variable, AZURE_DEVOPS_TOKEN, which allows you to interact with the Azure DevOps API.
<IMPORTANT> You can use curl with the AZURE_DEVOPS_TOKEN to interact with Azure DevOps's API. ALWAYS use the Azure DevOps API for operations instead of a web browser. </IMPORTANT>
If you encounter authentication issues when pushing to Azure DevOps (such as password prompts or permission errors), the old token may have expired. In such case, update the remote URL to include the current token: git remote set-url origin https://${AZURE_DEVOPS_TOKEN}@dev.azure.com/organization/project/_git/repository
Here are some instructions for pushing, but ONLY do this if the user asks you to:
main or master branchopenhands-workspace. Create a new branch with a better name before pushing.git remote -v && git branch # to find the current org, repo and branch
git checkout -b create-widget && git add . && git commit -m "Create widget" && git push -u origin create-widgetWhen working with Azure DevOps API, you need to use Basic authentication with your Personal Access Token (PAT). The username is ignored (empty string), and the password is the PAT.
Here's how to authenticate with curl:
# Convert PAT to base64
AUTH=$(echo -n ":$AZURE_DEVOPS_TOKEN" | base64)
# Make API call
curl -H "Authorization: Basic $AUTH" -H "Content-Type: application/json" https://dev.azure.com/{organization}/{project}/_apis/git/repositories?api-version=7.1Common API endpoints:
https://dev.azure.com/{organization}/{project}/_apis/git/repositories?api-version=7.1https://dev.azure.com/{organization}/{project}/_apis/git/repositories/{repositoryId}?api-version=7.1https://dev.azure.com/{organization}/{project}/_apis/git/pullrequests?api-version=7.1https://dev.azure.com/{organization}/{project}/_apis/git/repositories/{repositoryId}/pullrequests?api-version=7.1 (POST)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.