All skills
sanjay3290 avatar

/azure-devops

@eab1642

Manage Azure DevOps projects, work items, repos, PRs, pipelines, wikis, test plans, security alerts, variable groups, environments/approvals, branch policies, and attachments. Use when user asks to: manage sprints, create/update work items, list repos, create PRs, run pipelines, search code, manage wiki pages, check security alerts, manage variable groups, approve deployments, or configure branch policies. Covers 13 domains with 99 tools via REST API.

Use this Skill: https://skilld.dev/gh/sanjay3290/ai-skills/azure-devops

This session only. Nothing lands on disk.

README.md

≈747 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure DevOps Skill

Manage Azure DevOps projects, work items, repositories, pull requests, pipelines, wikis, test plans, and security alerts through a Python CLI. Reimplementation of the Azure DevOps MCP server as lightweight scripts.

Features

  • 13 domains, 99 tools covering the full Azure DevOps REST API
  • OAuth (device code flow) or PAT authentication stored securely in system keyring
  • Auto token refresh for OAuth - no manual re-login needed
  • No external dependencies beyond keyring - uses stdlib urllib.request
  • Consistent CLI pattern - argparse subcommands, JSON output

Domains

Domain Script Tools
Core core.py Projects, teams, identities (3)
Work Items work_items.py CRUD, queries, comments, backlogs (20)
Iterations work.py Sprints, capacity (7)
Git/PRs repos.py Repos, branches, pull requests (18)
Pipelines pipelines.py Builds, runs, artifacts (14)
Search search.py Code, wiki, work item search (3)
Wiki wiki.py Pages management (6)
Test Plans test_plans.py Plans, suites, cases, results (9)
Security security.py Advanced security alerts (2)
Variable Groups variable_groups.py Pipeline variable groups (7)
Environments environments.py Environments & approvals (8)
Policies policies.py Branch policies (8)
Attachments attachments.py Work item attachments (6)

Quick Start

1. Install dependency

pip install keyring>=24.0.0

2. Authenticate

Option A: OAuth (Recommended)

cd skills/azure-devops
python scripts/auth.py login --org MyOrganization
# Follow the URL, enter the device code to authorize
# Tokens auto-refresh - no need to re-login

Option B: PAT

Create a PAT at https://dev.azure.com/{org}/_usersSettings/tokens with scopes: Work Items (R&W), Code (R&W), Build (R&E), Wiki (R&W), Test Management (R&W), Advanced Security (R), Project and Team (R), Identity (R).

cd skills/azure-devops
python scripts/auth.py login --org MyOrganization --pat YOUR_PAT

3. Verify

python scripts/auth.py status
python scripts/core.py list-projects

Usage

All scripts follow the same pattern:

python scripts/<domain>.py <command> --project <name> [options]

Output is always JSON. Exit code 1 on errors.

See SKILL.md for complete command reference with examples.

Troubleshooting

"Not authenticated" error: Run python scripts/auth.py login

"HTTP 401": Token expired. For OAuth, run python scripts/auth.py login --org <org>. For PAT, create a new one and re-login.

"HTTP 403": PAT doesn't have the required scope for this operation.

"HTTP 404": Project, repo, or resource not found. Check the name/ID.

Keyring issues on Linux: Install secretstorage package: pip install secretstorage

Source: SKILL.md on GitHub

2 warnings16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a comprehensive CLI for managing Azure DevOps. It correctly uses the system keyring for secure token storage. However, it is susceptible to indirect prompt injection as it processes untrusted data from wikis and work items while maintaining high-privilege capabilities like approving deployments. It also includes a utility to print raw authentication tokens and a download tool that allows writing to arbitrary local file paths provided by the agent.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    18/18 files flagged

Signed by skilld at eab1642. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 weeks ago.

Activeupdated 7 months ago
metadata
{
  "author": "sanjay3290",
  "version": "1.0"
}

README badge

README badge for sanjay3290/ai-skills/azure-devops