# list_branches

A read tool on the Azure DevOps MCP Server MCP server.

Agent View of the PolicyLayer registry record for `list_branches`. HTML page: https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/list-branches

## Facts

- Tool: `list_branches`
- Server: Azure DevOps MCP Server (`abdelrhmansror/azuredevopsmcp`) — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp.md
- Homepage: https://github.com/AbdelrhmanSror/AzureDevopsMcp
- Risk category: Read (Low risk)
- Registry record: grade B, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "list_branches",
    "arguments": {}
  }
}
```

## Why list_branches is rated Low

Listing branches retrieves repository metadata without modifying, deleting, or executing any code. The operation has no side effects and poses minimal risk if misused by an AI agent. Even with an empty description, the verb 'list' and naming convention clearly indicate a read-only query operation.

From the tool's own definition: "Tool name 'list_branches' indicates a listing/retrieval operation. Server context confirms it enables interaction with Azure DevOps repositories for querying purposes."

## Use case

AI agents call list_branches to retrieve information from Azure DevOps MCP Server without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Azure DevOps MCP Server:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "list_branches": {}
  }
}
```

## Other tools on Azure DevOps MCP Server (15)

- `get_pull_request` — Read — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/get-pull-request.md
- `get_pull_request_full_diff` — Read — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/get-pull-request-full-diff.md
- `list_area_paths` — Read — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/list-area-paths.md
- `list_iteration_paths` — Read — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/list-iteration-paths.md
- `list_projects` — Read — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/list-projects.md
- `list_pull_requests` — Read — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/list-pull-requests.md
- `list_work_item_types` — Read — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/list-work-item-types.md
- `resolve_repo_id` — Read — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/resolve-repo-id.md
- `add_pull_request_comment` — Write — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/add-pull-request-comment.md
- `create_bug` — Write — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/create-bug.md
- `create_product_backlog_item` — Write — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/create-product-backlog-item.md
- `create_pull_request` — Write — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/create-pull-request.md
- `create_work_item` — Write — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/create-work-item.md
- `link_pr_to_work_item` — Write — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/link-pr-to-work-item.md
- `set_pr_description` — Write — https://policylayer.com/tools/abdelrhmansror-azuredevopsmcp/set-pr-description.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=abdelrhmansror-azuredevopsmcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/abdelrhmansror-azuredevopsmcp
