Mcp Devops On Prem — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Devops On Prem (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<div align="center">
Model Context Protocol MCP server for on-premises Azure DevOps that lets AI assistants browse repositories, review pull requests, manage work items, and interact with wikis.
<!-- mcp-name: io.github.zwitbaum/mcp-devops-on-prem -->
<div class="toc"> <a href="#overview">Overview</a> • <a href="#getting-started">Getting Started</a> • <a href="#updating">Updating</a> • <a href="#available-tools">Available Tools</a> • <a href="#development">Development</a> </div>
</div>
Many organizations use on-premise DevOps solutions such as TFS or Azure DevOps Server in their projects. Integrating these systems with modern agentic AI tools and LLMs can be difficult. The official Microsoft Azure DevOps MCP server does not support these environments and is unlikely to support them in the future.
This MCP server closes that gap and enables smooth integration with on-premise DevOps systems.
This project is under active development, with features continuously added to meet current requirements. Community needs are highly valued — if you miss any features, please submit an Issue. User-requested features are fast-tracked and will be prioritized and added as soon as possible.
One of the most important features of this MCP server is NTLM authentication support. NTLM is required by many on-premises and enterprise environments where users authenticate with Windows domain credentials, either directly or over VPN. Most MCP servers for Azure DevOps target only cloud-hosted Azure DevOps Services with token-based auth and cannot connect to these environments.
Python 3.10+ and uv are required. If not yet installed, see installation guide.
Click one of the buttons below to install directly in your IDE. You will be prompted for credentials:
For other platforms, see Manual Installation in the Getting Started guide.
The MCP server can be installed manually in the following AI tools: VS Code, Visual Studio, Cursor, Goose, LM Studio, Amp, Claude Code, Claude Desktop, Codex, Gemini CLI, OpenCode, Qodo Gen, Warp, Windsurf, GitHub Copilot CLI, GitHub Copilot Coding Agent, and others.
For step-by-step instructions, see Manual Installation in the Getting Started guide.
The DEVOPS_API_URL must point to your full project URL:
https://<your-devops-server>/<organization>/<project>The server supports three authentication methods. If you are unsure which one to use, start with NTLM because it is the most common for on-prem/VPN setups.
| Method | Description |
|---|---|
| NTLM (username + password) | Most common for on-prem/VPN. Usually the simplest first setup and best fallback if other options fail. |
| PAT (Personal Access Token) | Use when PAT is enabled and allowed. Tokens can expire, and token-based auth may be blocked by policy. Advantage: you do not store your account password in config. |
| OAuth Bearer Token | Advanced option for CI/CD pipelines. Requires OAuth 2.0 configured on your DevOps Server and a token source defined by your administrators. |
For detailed setup instructions for each method, see Authentication in the Getting Started guide.
#### With NTLM (username + password)
{
"mcpServers": {
"devops-onprem": {
"command": "uvx",
"args": ["mcp-devops-onpremise@latest"],
"env": {
"DEVOPS_API_URL": "https://your-devops-server/your-organization/your-project",
"DEVOPS_USERNAME": "DOMAIN\\your-username",
"DEVOPS_PASSWORD": "your-password"
}
}
}
}#### With PAT
{
"mcpServers": {
"devops-onprem": {
"command": "uvx",
"args": ["mcp-devops-onpremise@latest"],
"env": {
"DEVOPS_API_URL": "https://your-devops-server/your-organization/your-project",
"DEVOPS_PAT": "your-personal-access-token"
}
}
}
}If you used a permanent install, replace"command": "uvx"with"command": "mcp-devops-onpremise"and remove the"args"line.
All configuration examples use mcp-devops-onpremise@latest, which instructs uvx to fetch the latest version automatically on every run.
For permanent installs and release notes, see Updating in the Getting Started guide.
| Tool | Description | Read-only |
|---|---|---|
devops_pull_request_get | Retrieve a pull request by ID, including linked work items and commit SHAs for diffing | ✅ |
devops_pull_request_list_threads | Returns a hierarchical list of non-deleted comment threads and their text comments | ✅ |
devops_pull_request_list_thread_comments | List non-deleted text comments in a specific thread | ✅ |
devops_pull_request_create_comment | Create a new thread with an initial comment (general or inline on a file/line) | ❌ |
devops_pull_request_reply_comment | Reply to an existing comment thread | ❌ |
devops_pull_request_update_thread | Update the status of a comment thread | ❌ |
devops_pull_request_update_comment | Update the text of an existing comment | ❌ |
devops_pull_request_delete_comment | Delete a comment from a pull request thread | ❌ |
| Tool | Description | Read-only |
|---|---|---|
devops_repository_list | List all repositories in the project | ✅ |
devops_repository_get | Retrieve repository details by name or ID | ✅ |
devops_repository_commit_changes | List files changed in a specific commit | ✅ |
devops_repository_diffs_commits | Get the difference between two commits (changed file paths) | ✅ |
devops_repository_item_content | Get raw file content at a specific commit or branch | ✅ |
devops_get_item_content_diff | Get line-level textual diff of a file between two commits (added lines prefixed +, removed -) | ✅ |
| Tool | Description | Read-only |
|---|---|---|
devops_work_item_get | Retrieve a work item (PBI, bug, task) by numeric ID. Returns a compact object with key fields, attachments (files and inline images), and linked items (work items, pull requests, commits) | ✅ |
devops_work_item_attachment_get | Download a work item attachment by its GUID, either saving locally or returning base64-encoded content | ✅ |
devops_work_item_type_get | Get the definition of a work item type by name (e.g. Bug, User Story) | ✅ |
devops_work_item_query_by_wiql | Execute a WIQL (Work Item Query Language) query and return matching work items | ✅ |
devops_work_item_create | Create a new work item with typed fields; Html is the default format | ❌ |
devops_work_item_update | Update fields on a work item using JSON Patch (add / replace / remove) | ❌ |
devops_work_item_delete | Delete a work item, moves to Recycle Bin by default; use destroy=True for permanent deletion (requires project permission) | ❌ |
devops_work_item_undelete | Restore a soft-deleted work item from the Recycle Bin | ❌ |
devops_work_item_link_update | Add or remove a relation link between two work items (parent, child, related, successor, predecessor, etc.) | ❌ |
devops_work_item_artifact_link_update | Add or remove an artifact link (Pull Request, Build, Commit, Branch, Changeset) on a work item | ❌ |
devops_work_item_comment_list | List comments on a work item with configurable page size and format | ✅ |
devops_work_item_comment_add | Add a comment to a work item | ❌ |
devops_work_item_comment_update | Update an existing comment on a work item | ❌ |
devops_work_item_comment_delete | Delete a comment from a work item | ❌ |
| Tool | Description | Read-only |
|---|---|---|
devops_wiki_page_get_by_url | Get wiki page metadata (id, path) and optional content by its URL | ✅ |
devops_wiki_page_create_or_update | Create or update a wiki page under a specified parent page | ❌ |
devops_wiki_page_update | Update an existing wiki page by ID | ❌ |
devops_wiki_page_delete | Delete an existing wiki page by ID | ❌ |
# Install dev dependencies
uv sync --group dev
# Run linting
uv run ruff check src/
uv run black --check src/
# Run tests
uv run pytest tests/~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.