The break is in the trust boundary between what a human sees and what an AI agent reads. In Azure DevOps, a comment can be invisible in the web UI but still return through the API as raw text, so a reviewer’s agent can take attacker-written instructions and use the reviewer’s own permissions across projects.
Manifold Security says Microsoft’s official Azure DevOps MCP server leaves pull request descriptions without the prompt-injection guardrail it applied to other tools. That means the same workflow can expose source code, secrets, and work items, not just the pull request under review. Google also moved CodeMender from research into a managed enterprise agent, which broadens the set of AI systems now able to act inside production development environments.
The forward risk is the same across these tools: content that looks like data can become instructions once an agent is allowed to act on it. A routine review request can turn into a cross-project exfiltration path when the agent carries live workspace permissions.