---
title: "windbg"
description: "WinDbg diagnosis workflows and report validation for applications, services, UMDF/user-mode drivers, and kernel-mode drivers."
canonical: https://agentpluginsdirectory.com/plugins/windbg--microsoft
last-updated: 2026-10-08
---

# windbg
WinDbg diagnosis workflows and report validation for applications, services, UMDF/user-mode drivers, and kernel-mode drivers.
- Slug: windbg--microsoft
- Publisher: Microsoft
- Repository: https://github.com/microsoft/win-dev-skills
- Manifest: plugins/windbg/plugin.json
- Version: 1.0.0
- Category (editorial): other
- Skills: 11 (windbg-diagnostic-method, windbg-kernel-bugcheck-triage, windbg-kernel-irp-lifecycle-triage, windbg-kernel-lock-deadlock-triage, windbg-kernel-verifier-triage, windbg-user-exception-triage, windbg-user-heap-corruption-investigation, windbg-user-mutex-held-across-co-await, windbg-user-ttd-reverse-debugging-triage, windbg-user-virtual-memory-exhaustion, windbg-user-wait-chain-analysis)
- MCP servers: 0
- Stars: 463
- Repository created: 2026-03-03
- Repository last pushed: 2026-10-07
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/windbg--microsoft
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What windbg does, in the publisher's words

A WinDbg-centric crash, hang, memory, and driver diagnosis playbook for developers who build software for Windows: native applications, services, third-party user-mode drivers (including UMDF), and kernel-mode drivers.

This public edition combines focused user-mode and kernel-mode debugging skills, a shared windbg-diagnostic-method skill with deterministic report validation, and a contrarian reviewer. It does not require private Windows source, symbols, portals, or feedback services. The goal is to shorten the path from a dump, trace, or stack to a supported root cause and candidate fix without forcing a pattern match.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/microsoft/win-dev-skills/HEAD/plugins/windbg/README.md

## Skills

- windbg-diagnostic-method: Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation. Not a bug-family-specific triage skill.
- windbg-kernel-bugcheck-triage: Use when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver. Not for user-mode process crashes or blaming a module from its name alone.
- windbg-kernel-irp-lifecycle-triage: Use when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership. Not for interpreting an empty IRP search in a limited dump as proof of healthy I/O.
- windbg-kernel-lock-deadlock-triage: Use when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph. Not for treating every watchdog stop as a deadlock or listing every lock type with!locks.
- windbg-kernel-verifier-triage: Use when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state. Not for Application Verifier user-mode stops or inferring a violation from enabled flags alone.
- windbg-user-exception-triage: Use when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside managed processes. Not for managed.NET exceptions, WinUI/XAML app errors, or kernel bugchecks.
- windbg-user-heap-corruption-investigation: Use when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds. Not for kernel pool corruption or ordinary OOM.
- windbg-user-mutex-held-across-co-await: Use when app, service, or user-mode driver C++ coroutine code holds a thread-affine lock across suspension and later hangs or fails. Not for all coroutine crashes or choosing lock performance.
- windbg-user-ttd-reverse-debugging-triage: Use when an app, service, or user-mode driver host TTD recording is available and earlier calls, writes, or lifetimes matter. Not for kernel replay or history from a normal dump.
- windbg-user-virtual-memory-exhaustion: Use when a native app, service, or user-mode driver host allocation fails; distinguish VA exhaustion, fragmentation, and commit pressure. Not for managed.NET heap growth, proving a leak from one snapshot, or corruption.
- windbg-user-wait-chain-analysis: Use when an app, service, or user-mode driver host is unresponsive on locks, COM/RPC, I/O, or another process; follow the blocker chain. Not for a crash solely from an exception stack.

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
