Invisible PR comment lets Azure DevOps AI abuse access
🛡️ A hidden HTML comment in an Azure DevOps pull request can instruct a reviewer's AI coding agent to act beyond an attacker's privileges, leaking sensitive data. The flaw exists because the MCP server returns PR descriptions without the spotlighting guardrail applied elsewhere, so the agent receives hidden instructions the human reviewer cannot see. Manifold Security demonstrated a proof-of-concept that chains permitted agent calls to read cross-project resources and exfiltrate content using reviewer credentials. Microsoft acknowledged the report and recommended limiting project access and reviewing changes before running AI tools.
