Skip to main content
Glama
causercode

azure-devops-server-mcp

by causercode

repo_pull_request_write

Destructive

Create Azure DevOps pull requests after verifying branches, or update title, description, or draft state; writes require an allowed repository.

Instructions

Create a PR after verifying both remote branches, or update its title, description, or draft state. Writes require a process-configured ADO_ALLOWED_REPOSITORIES entry; otherwise they are disabled. The agent supplies project/repository and local Git context. No merge, completion, autocomplete, policy bypass, retargeting, or branch deletion is supported. After an uncertain write outcome, list PRs before retrying.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
titleNoRequired for create; optional for update.
actionYes
isDraftNoCreate as draft, or change draft state on update.
projectNoProject name or ID. Defaults to ADO_PROJECT; discover with server_info/list_projects.
repositoryYesRepository name or ID in the selected project.
descriptionNoPR description. Empty string clears it on update.
sourceBranchNoRequired for create. Push the branch through Git first.
targetBranchNoRequired for create, such as develop.
pullRequestIdNoRequired for update; omit for create.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations by disclosing that writes are disabled unless a process-configured ADO_ALLOWED_REPOSITORIES entry exists, enumerating the unsupported operations, stating the input the agent must supply, and prescribing behavior after an ambiguous write outcome. This is exactly the kind of mutation-side context the hints (destructive=false read profile) cannot convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four front-loaded sentences: primary action first, then permission gate, then scope limits, then recovery. Each sentence carries distinct operational information with no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a write tool with no output schema, the description covers authorization, scope limits, prerequisites, and failure handling, leaving only the returned value (e.g., the new PR identifier needed for follow-up calls) unmentioned.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is already 89%, so parameter meaning is largely carried by the schema itself; the description's mention of project/repository and local Git context adds little. The 'verify both remote branches' remark loosely reinforces sourceBranch/targetBranch semantics but no format or constraint detail is added.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States specific verbs and resource ('Create a PR ... or update its title, description, or draft state'), covering both action modes the enum supports. The explicit exclusion list (no merge, completion, autocomplete, policy bypass, retargeting, or branch deletion) draws a clean boundary against other PR-related operations.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear preconditions ('after verifying both remote branches'), an authorization gate (ADO_ALLOWED_REPOSITORIES), and a recovery path ('After an uncertain write outcome, list PRs before retrying'). It does not name the sibling tool (repo_pull_request) that performs that listing, so routing is implied rather than explicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.