Official agent skill

Apple Crash Log .NET Symbolication

by dotnet in dotnet/skills

Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.

OfficialMITAuto-check passedMobile

Install Apple Crash Log .NET Symbolication

skills CLI
$ npx skills add dotnet/skills --skill apple-crash-symbolication -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dotnet/skills apple-crash-symbolication --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dotnet-diag/skills/apple-crash-symbolication .claude/skills/apple-crash-symbolication && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
apple-crash-symbolication
GitHub stars
5.6k
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
949 words
Files
3 (incl. scripts, references)
Skills in repo
93
Repo updated
First seen
Licence
MIT

At a glance

Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.

  • Works in 5 steps: Parse the .ips Crash Log → Identify .NET Runtime Libraries → Interpret the Crash → …
  • Triaging a MAUI or Mono app crash from an .ips file
  • SKILL.md covers Workflow, Retrieving Crash Logs, Validation and Stop Signals, plus 1 more section
  • Runs PowerShell scripts from its folder; calls pwsh; reaches msdl.microsoft.com

What it does

The skill targets crashes of .NET MAUI and Mono apps on iOS, tvOS, Mac Catalyst and macOS. It checks that the file is the two-part JSON .ips format, with a metadata header line followed by the crash body, then reads the loaded images, thread frames, exception details, application-specific information and the faulting thread. Frames in .NET runtime libraries such as `libcoreclr` and `libmonosgen-2.0` are picked out and their addresses computed from each image's base and offset.

It then looks for dSYM debug symbols, downloads `.dwarf` symbols from the Microsoft symbol server by Mach-O UUID when needed, and runs `atos` through the `Symbolicate-Crash.ps1` script to get function names with file and line information. `idevicecrashreport` can pull logs from a connected iOS device. A reference describes the .ips format, including duplicate keys that differ only by case. Pure Swift or Objective-C crashes and Android tombstones are out of scope.

When your agent uses it

  • Triaging a MAUI or Mono app crash from an .ips file
  • Resolving native frames in libcoreclr or libmonosgen to runtime source
  • Investigating an EXC_BAD_ACCESS or SIGABRT that starts in the .NET runtime
  • Pulling crash logs from a connected iPhone for analysis

Example prompts

  • “Symbolicate this .ips crash log from our MAUI app and tell me where it crashed.”
  • “Pull the latest crash report from my connected iPhone and resolve the runtime frames.”
  • “This SIGABRT points at libcoreclr. Find the matching function names and source lines.”

Requirements

  • `atos` from Xcode
  • PowerShell to run `Symbolicate-Crash.ps1`
  • dSYM symbols or access to the Microsoft symbol server

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Parse the .ips Crash Log
  2. Identify .NET Runtime Libraries
  3. Interpret the Crash
  4. Locate dSYMs
  5. Symbolicate with atos

What it can do on your machine

Read from SKILL.md and the folder at commit 3d38ac3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (PowerShell), which the agent can run.

    Shell commands in SKILL.md call:

    • pwsh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • msdl.microsoft.com

    Also links to:

    • github.com
    • libimobiledevice.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Apple Crash Log .NET Symbolication loads about 2.4k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 225 tokens; SKILL.md has 949 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~225
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from dotnet/skills at commit 3d38ac3, republished under its MIT licence (© dotnet). 949 words, ~2,421 tokens.

Download SKILL.mdSave it as .claude/skills/apple-crash-symbolication/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
apple-crash-symbolication
description
Symbolicate .NET runtime frames in Apple platform .ips crash logs (iOS, tvOS, Mac Catalyst, macOS). Extracts UUIDs and addresses from the native backtrace, locates dSYM debug symbols, and runs atos to produce function names with source file and line numbers. Automatically downloads .dwarf symbols from the Microsoft symbol server using Mach-O UUIDs. USE FOR triaging a .NET MAUI or Mono app crash from an .ips file on any Apple platform, resolving native backtrace frames in libcoreclr or libmonosgen-2.0 to .NET runtime source code, retrieving .ips crash logs from a connected iOS device or iPhone, or investigating EXC_CRASH, EXC_BAD_ACCESS, SIGABRT, or SIGSEGV originating from the .NET runtime. DO NOT USE FOR pure Swift/Objective-C crashes with no .NET components, or Android tombstone files. INVOKES Symbolicate-Crash.ps1 script, atos, dwarfdump, idevicecrashreport.
license
MIT

Apple Platform Crash Log .NET Symbolication

Resolves native backtrace frames from .NET MAUI and Mono app crashes on Apple platforms (iOS, tvOS, Mac Catalyst, macOS) to function names, source files, and line numbers using Mach-O UUIDs and dSYM debug symbol bundles.

Inputs: Crash log file (.ips JSON format, iOS 15+ / macOS 12+), atos (from Xcode), optionally a connected iOS device to pull crash logs from.

Do not use when: The crashing library is not a .NET component (e.g., pure Swift/UIKit), or the crash log is an Android tombstone.


Workflow

Step 1: Parse the .ips Crash Log

Format check: Before proceeding, verify the file is .ips JSON format. The first line must be valid JSON. If the file is plain text (e.g., Android tombstone with #NN pc frame lines, or legacy Apple .crash text format), stop immediately — this workflow does not apply. Report the format mismatch to the user and do not attempt any symbolication.

The .ips file is two-part JSON: line 1 is a metadata header; the remaining lines are a separate JSON crash body. Parse them separately:

python
lines = open('crash.ips').readlines()
metadata = json.loads(lines[0])           # app_name, bundleID, os_version, slice_uuid
crash    = json.loads(''.join(lines[1:])) # Full crash report

Key fields in the crash body:

  • usedImages[N] has name, base (load address), uuid, arch for each loaded binary
  • threads[N].frames[M] has imageOffset, imageIndex; frame address = usedImages[imageIndex].base + imageOffset
  • exception.type, exception.signal (e.g., EXC_CRASH / SIGABRT)
  • asi (Application Specific Information) often contains the managed exception message
  • lastExceptionBacktrace has frames from the exception that triggered the crash
  • faultingThread is the index into the threads array

Parsing gotcha: Some .ips files have case-conflicting duplicate keys (vmRegionInfo / vmregioninfo). Pre-process the raw JSON to rename the lowercase duplicate before parsing. The asi field may be absent.

Step 2: Identify .NET Runtime Libraries

Filter usedImages to .NET runtime libraries:

LibraryRuntime
libcoreclrCoreCLR runtime
libmonosgen-2.0Mono runtime
libSystem.Native.NET BCL native component
libSystem.Globalization.Native.NET BCL globalization
libSystem.Security.Cryptography.Native.Apple.NET BCL crypto
libSystem.IO.Compression.Native.NET BCL compression
libSystem.Net.Security.Native.NET BCL net security

On Apple platforms these ship as .framework bundles, so image names may omit .dylib. Match using substring (e.g., libcoreclr not libcoreclr.dylib). The app binary may appear twice in usedImages with different UUIDs.

Key bridge functions in the app binary: xamarin_process_managed_exception (managed exception bridged to ObjC NSException), xamarin_main, mono_jit_exec, coreclr_execute_assembly.

NativeAOT: Runtime is statically linked into the app binary. libSystem.* BCL libraries remain separate. The app binary needs its own dSYM from the build output.

Skip libsystem_kernel.dylib, UIKitCore, and other Apple system frameworks unless specifically asked.

Step 3: Interpret the Crash

Start with asi (Application Specific Information) — for .NET crashes, it often contains the managed exception type and message (e.g., XamlParseException, NullReferenceException). The root cause may already be visible here.

Then examine the faulting thread (threads[faultingThread]). Explain what frames #0 and #1 mean before examining other threads. Cross-thread context (GC state, thread pool) is useful for validation but not evidence of causation.

Also check lastExceptionBacktrace for the managed exception path through bridge functions like xamarin_process_managed_exception.

Sometimes the .NET runtime version is visible in image paths in usedImages, particularly on macOS when using shared-framework installs or NuGet-pack-style layouts (e.g., .../Microsoft.NETCore.App/10.0.4/libcoreclr.dylib). On iOS, however, image paths are typically inside the app bundle (for example, .../Frameworks/libcoreclr.framework/libcoreclr) and do not embed the runtime version, so you usually need to infer it via the Mach-O UUID by matching against SDK packs or symbol-server downloads rather than relying on the path alone.

Show full SKILL.md (414 more words)Show less
Step 4: Locate dSYMs

For each .NET library needing symbolication, locate a UUID-matched dSYM:

  1. Microsoft symbol server (automatic): Download .dwarf via https://msdl.microsoft.com/download/symbols/_.dwarf/mach-uuid-sym-{UUID}/_.dwarf (UUID lowercase, no dashes). Convert to .dSYM bundle (use the image name from usedImages[].name, e.g., libcoreclr):
    bash
    mkdir -p libcoreclr.dSYM/Contents/Resources/DWARF
    cp _.dwarf libcoreclr.dSYM/Contents/Resources/DWARF/libcoreclr
  2. Build output: bin/Debug/net*-ios/ios-arm64/<App>.app.dSYM/
  3. SDK packs: $DOTNET_ROOT/packs/Microsoft.NETCore.App.Runtime.<rid>/<version>/runtimes/<rid>/native/
  4. NuGet cache: ~/.nuget/packages/microsoft.netcore.app.runtime.<rid>/<version>/runtimes/<rid>/native/
  5. dotnet-symbol: dotnet-symbol --symbols -o symbols-out <path-to-binary.dylib>

Always verify: dwarfdump --uuid <dsym> must match the UUID from the crash log exactly.

Step 5: Symbolicate with atos
bash
atos -arch arm64 -o <path.dSYM/Contents/Resources/DWARF/binary_name> -l <load_address> <frame_addresses...>
  • -o points to the DWARF binary inside the .dSYM bundle (Contents/Resources/DWARF/), not the bundle itself
  • -l is the load address from usedImages[N].base
  • Use the arch from usedImages[N].arch (usually arm64, may be arm64e)
  • Pass multiple addresses per invocation for batch symbolication
bash
# Example: symbolicate libcoreclr frames
atos -arch arm64 -o libcoreclr.dSYM/Contents/Resources/DWARF/libcoreclr -l 0x104000000 0x104522098 0x1043c0014

Strip the /__w/1/s/ CI workspace prefix from output — meaningful paths start at src/runtime/, mapping to the dotnet/dotnet VMR.

Automation Script

scripts/Symbolicate-Crash.ps1 automates the full workflow (parsing, dSYM lookup, symbol download, and symbolication). Resolve the path relative to this SKILL.md file.

powershell
# $SKILL_DIR is the directory containing this SKILL.md
pwsh "$SKILL_DIR/scripts/Symbolicate-Crash.ps1" -CrashFile MyApp-2026-02-25.ips

Start with -ParseOnly for a fast overview without requiring atos. The script automatically downloads symbols from the Microsoft symbol server when local dSYMs are missing.

Flags: -CrashingThreadOnly, -OutputFile path, -ParseOnly, -SkipVersionLookup, -SkipSymbolDownload, -SymbolCacheDir path, -DsymSearchPaths path1,path2.


Retrieving Crash Logs

Pull crash logs from a connected iOS device using idevicecrashreport (from libimobiledevice):

bash
idevicecrashreport -e /tmp/crashlogs/
find /tmp/crashlogs/ -iname '*MyApp*' -name '*.ips'

Also available in Xcode > Window > Devices and Simulators > View Device Logs, or at ~/Library/Logs/CrashReporter/ (Mac Catalyst), ~/Library/Logs/DiagnosticReports/ (macOS).


Validation

  1. dwarfdump --uuid <dsym> matches UUID from the crash log
  2. At least one .NET frame resolves to a function name (not a raw address)
  3. Resolved paths contain recognizable .NET runtime structure (e.g., src/coreclr/, mono/metadata/, mono/mini/)

Stop Signals

  • Wrong file format: If the file is not .ips JSON (e.g., Android tombstone with #NN pc stack frames, legacy .crash text format), stop immediately — report the format mismatch to the user and do not proceed with any symbolication. Do not attempt to symbolicate using other tools or workflows.
  • No .NET frames found: Report parsed frames and stop.
  • All frames resolved: Present symbolicated backtrace with brief crash analysis (faulting thread, exception type, likely area). If the user asks for deeper investigation, proceed.
  • dSYM not available / UUID mismatch: Report unsymbolicated frames with UUIDs and addresses. Suggest locating the original build artifacts.
  • atos not available: Present the manual atos commands for the user to run. Do not install Xcode. atos ships with Xcode Command Line Tools (xcode-select --install).

References

© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in plugins/dotnet-diag/skills/apple-crash-symbolication of dotnet/skills.

  • SKILL.md
  • references/ips-crash-format.md
  • scripts/Symbolicate-Crash.ps1

Open the folder on GitHubat commit 3d38ac3

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Apple Crash Log .NET Symbolication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Apple Crash Log .NET Symbolication compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Apple Crash Log .NET Symbolication this skilldotnet/skills5.6k1 repos~2.4kAutomated safety check: PassMIT
Mobile App Debuggingsecondsky/claude-skills227—~513Automated safety check: PassMIT
Orca iOS Simulator Controlstablyai/orca88k1 repos~584Automated safety check: PassApache-2.0
Macios Xcode Beta Updatedotnet/macios2.9k—~1.8kAutomated safety check: PassCustom licence
Maui AI DebuggingRedth/Maui.Gtk101—~4.1kAutomated safety check: PassMIT
Macios Binding Creatordotnet/macios2.9k—~7.3kAutomated safety check: PassCustom licence

Similar skills

  • Mobile App Debugging

    secondsky/claude-skills

    Mobile app debugging for iOS, Android, cross-platform frameworks.

    227 GitHub stars~513 tokensUpdated 11 days ago
    MobileAuto-check passed
  • iOS Simulator control from inside Orca, with the live device view in Orca's emulator pane. Use when driving a booted Apple Simulator on macOS: taps, gestures…

    88k GitHub starsUsed in 1 repo~584 tokens
    MobileAuto-check passed
  • Official

    Update dotnet/macios to a new Xcode beta and validate it end-to-end.

    2.9k GitHub stars~1.8k tokensUpdated today
    MobileAuto-check passed
  • Maui AI Debugging

    Redth/Maui.Gtk

    End-to-end workflow for building, deploying, inspecting, and debugging .NET MAUI and MAUI Blazor Hybrid apps as an AI agent.

    101 GitHub stars~4.1k tokensUpdated 5 mo ago
    MobileAuto-check passed
  • Official

    Create C bindings for Apple frameworks in dotnet/macios. An agent skill from dotnet/macios.

    2.9k GitHub stars~7.3k tokensUpdated today
    MobileAuto-check passed
  • Flowdeck

    SwiftedMind/Tessera

    FlowDeck is REQUIRED for all Apple platform build/run/test/launch/debug/simulator/device/log/automation tasks.

    116 GitHub stars~11k tokensUpdated 5 mo ago
    MobileAuto-check passed

More from dotnet/skills

All 93 skills in this repo
  • Official

    Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.

    5.6k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Official

    Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.

    5.6k GitHub starsUsed in 3 repos~3.1k tokens
    Auto-check passed
  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Microbenchmarking

    dotnet/skills

    Official

    Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.

    5.6k GitHub starsUsed in 3 repos~3.3k tokens
    Auto-check passed
  • Official

    Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.

    5.6k GitHub starsUsed in 2 repos~4.2k tokens
    Auto-check passed
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    Auto-check passed

Questions about Apple Crash Log .NET Symbolication

What does Apple Crash Log .NET Symbolication do?

Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server. NET MAUI and Mono apps on iOS, tvOS, Mac Catalyst and macOS.ips format, with a metadata header line followed by the crash body, then reads the loaded images, thread frames, exception details, application-specific information and the faulting thread.

When should I use Apple Crash Log .NET Symbolication?

Apple Crash Log .NET Symbolication fits situations like: triaging a MAUI or Mono app crash from an .ips file; resolving native frames in libcoreclr or libmonosgen to runtime source; investigating an EXC_BAD_ACCESS or SIGABRT that starts in the .NET runtime; pulling crash logs from a connected iPhone for analysis.

How do I install Apple Crash Log .NET Symbolication in Claude Code?

Run `npx skills add dotnet/skills --skill apple-crash-symbolication -a claude-code`. Or copy the skill folder (plugins/dotnet-diag/skills/apple-crash-symbolication in dotnet/skills) into .claude/skills/apple-crash-symbolication in your project. Claude Code loads it when a task matches its description.

How do I install Apple Crash Log .NET Symbolication in Codex?

Run `npx skills add dotnet/skills --skill apple-crash-symbolication -a codex`. Or copy the skill folder (plugins/dotnet-diag/skills/apple-crash-symbolication in dotnet/skills) into .agents/skills/apple-crash-symbolication in your project. Codex loads it when a task matches its description.

Can I use Apple Crash Log .NET Symbolication in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill apple-crash-symbolication -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/apple-crash-symbolication, .gemini/skills/apple-crash-symbolication, .github/skills/apple-crash-symbolication and .opencode/skills/apple-crash-symbolication in your project.

What does Apple Crash Log .NET Symbolication need to run?

Going by SKILL.md and its folder, Apple Crash Log .NET Symbolication needs PowerShell for the scripts in its folder and the command-line tools its instructions call (pwsh). Our summary lists: `atos` from Xcode; PowerShell to run `Symbolicate-Crash.ps1`; dSYM symbols or access to the Microsoft symbol server.

Does Apple Crash Log .NET Symbolication access the network?

SKILL.md names 3 domains. In commands or code: msdl.microsoft.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com and libimobiledevice.org. This is read from the text; nothing was executed.

Is Apple Crash Log .NET Symbolication safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Apple Crash Log .NET Symbolication use?

Apple Crash Log .NET Symbolication is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Apple Crash Log .NET Symbolication use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 426 tokens, read only when the agent opens those files.

What are the alternatives to Apple Crash Log .NET Symbolication?

Skills that share tags, products or a category with Apple Crash Log .NET Symbolication: Mobile App Debugging (secondsky/claude-skills, 227 stars), Orca iOS Simulator Control (stablyai/orca, 88k stars), Macios Xcode Beta Update (dotnet/macios, 2.9k stars) and Maui AI Debugging (Redth/Maui.Gtk, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Apple Crash Log .NET Symbolication?

dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,585 GitHub stars. The repository holds 93 skills in this directory. The repository was last updated on October 9, 2026.

Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.