Official agent skill

DebugView CLI

by microsoft in microsoft/skills

Captures and filters Windows user-mode and kernel debug output from the command line with the Sysinternals DebugView CLI, including bounded runs suited to agents.

OfficialMITAuto-check passedDevelopment

Install DebugView CLI

skills CLI
$ npx skills add microsoft/skills --skill debugview -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills debugview --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/debugview .claude/skills/debugview && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
debugview
GitHub stars
3.1k
Used in
1 other repo
Token cost
~2.7k tokens
SKILL.md length
839 words
Files
7 (incl. scripts, references)
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Captures and filters Windows user-mode and kernel debug output from the command line with the Sysinternals DebugView CLI, including bounded runs suited to agents.

  • Works in 6 steps: Static CRT linking — No DLL… → stdout/stderr separation — Debug output… → Bounded execution — --duration,… → …
  • Capturing OutputDebugString output from a running Windows app
  • SKILL.md covers Installation, Requirements, Core Workflow and Command-Line Parameters, plus 4 more sections
  • Runs PowerShell scripts from its folder

What it does

The skill documents dbgviewcli.exe, a standalone native Windows executable that captures OutputDebugString output from applications and DbgPrint or KdPrint output from kernel drivers. Win32 capture runs as a standard user, while kernel and boot capture need Administrator rights and load the Dbgv.sys driver, which is extracted automatically. It runs on Windows Vista or later, on x64 and ARM64. No dbgviewcli binary may be run before its Authenticode signature is verified as Microsoft Corporation with Get-AuthenticodeSignature, and unsigned or differently signed binaries are rejected.

The core workflow is to check status, start a capture, filter the output and stop. Parameters cover capture control (kernel, Win32, global session 0, passthrough, verbose kernel, process IDs), include and exclude wildcard filters, filtering by PID or process name, and bounded execution such as a duration that stops capture automatically. The folder ships PowerShell scripts for detecting DebugView, wrapping a capture and boot-time logging, plus reference notes on driver IOCTLs, output formats and the remote protocol. It is not for non-Windows systems, application logging frameworks, cloud telemetry or ETW tracing.

When your agent uses it

  • Capturing OutputDebugString output from a running Windows app
  • Collecting kernel DbgPrint or KdPrint output from a driver
  • Setting up boot-time debug logging
  • Running a time-limited debug capture from a script

Example prompts

  • “Capture OutputDebugString output from myapp.exe for a short bounded run.”
  • “Collect kernel debug output while I load the driver, and keep only lines containing ERROR.”
  • “Set up boot-time debug logging with DebugView and tell me what needs Administrator.”

Requirements

  • Windows Vista or later (x64 or ARM64)
  • dbgviewcli.exe, verified as signed by Microsoft Corporation
  • Administrator rights for kernel and boot capture

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Static CRT linking — No DLL dependencies, runs on any Windows system
  2. stdout/stderr separation — Debug output → stdout; errors/status → stderr
  3. Bounded execution — --duration, --max-lines, --wait-for ensure guaranteed exit for automation
  4. Clean output — --no-banner suppresses noise for pipe/agent consumption
  5. Machine-readable status — --status outputs key=value pairs for programmatic checks
  6. Graceful shutdown — SetConsoleCtrlHandler ensures clean driver unload on Ctrl+C

What it can do on your machine

Read from SKILL.md and the folder at commit 354361d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (PowerShell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

DebugView CLI loads about 2.7k tokens when it runs, and up to ~6.6k if it reads all its reference files. Until then it costs about 196 tokens; SKILL.md has 839 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~196
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from microsoft/skills at commit 354361d, republished under its MIT licence (© microsoft). 839 words, ~2,664 tokens.

Download SKILL.mdSave it as .claude/skills/debugview/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
debugview
description
Sysinternals DebugView CLI (DbgViewCli) for capturing and analyzing usermode and kernel-mode Windows debug output from the command line. USE FOR: capturing OutputDebugString output, kernel DbgPrint/KdPrint capture, boot-time debug logging, remote debug monitoring, filtering debug output by PID or process name, crash dump analysis, automated debug capture with bounded execution. DO NOT USE FOR: non-Windows platforms, application-level logging frameworks (log4j, serilog), Azure Monitor or cloud telemetry, ETW tracing (use WPR/xperf instead), user-mode crash dumps (use WinDbg). Triggers: "debug output", "DbgView", "DebugView", "kernel debug", "capture debug logs", "boot logging", "OutputDebugString", "DbgPrint", "KdPrint", "remote debug monitor", "debug capture CLI".

Sysinternals DebugView CLI (DbgViewCli)

Command-line interface for capturing real-time debug output from Windows applications (OutputDebugString) and kernel-mode drivers (DbgPrint/KdPrint). Designed for scripted, automated, and AI-agent-driven debug capture workflows.

Installation

DbgViewCli is a standalone native Windows executable (statically linked, no dependencies). Place dbgviewcli.exe in PATH or reference the full path.

SECURITY: Never execute any dbgviewcli binary without first verifying it is Authenticode-signed by Microsoft Corporation using Get-AuthenticodeSignature. Reject any binary that is unsigned or signed by a different publisher.

bash
# No package manager install — copy binary to a PATH location
copy dbgviewcli.exe C:\Tools\

Requirements

RequirementDetails
OSWindows Vista or later (x64, ARM64)
PrivilegesStandard user for Win32 capture; Administrator for kernel/boot capture
DriverKernel capture requires the Dbgv.sys driver (auto-extracted and loaded)

Core Workflow

1. Detect/status check   →  dbgviewcli --status
2. Start capture          →  dbgviewcli [options]
3. Filter output          →  --filter/--exclude/--pid-filter/--process-filter
4. Bounded execution      →  --duration/--max-lines/--wait-for
5. Output/log results     →  stdout or --log <file>
6. Stop                   →  Ctrl+C or automatic exit on bounds

Command-Line Parameters

Capture Control
ParameterShortDescriptionDefault
--capture-cEnable captureon
--no-captureDisable capture
--kernel-kEnable kernel debug output (requires admin)off
--win32-wEnable Win32 OutputDebugString captureon
--global-gEnable global Win32 capture (session 0)off
--passthroughAllow debug output to pass to debuggerson
--verbose-kernel-vEnable verbose kernel outputoff
--pidsShow process IDs in outputon
Filtering
ParameterShortDescription
--filter <pattern>-iInclude filter (semicolon-separated wildcards)
--exclude <pattern>-eExclude filter (semicolon-separated wildcards)
--pid-filter <pid>Show only output from specific PID
--process-filter <name>Show only output from named process (substring match)
Bounded Execution (AI-Agent Friendly)
ParameterDescription
--duration <seconds>Auto-stop after N seconds
--max-lines <N>Auto-stop after N lines captured
--wait-for <pattern>Capture until pattern matches, then exit
--tail <N>Buffer last N lines, flush on exit
--no-bannerSuppress version banner (clean for piped output)
--statusPrint machine-readable status and exit
Time Display
ParameterDescription
--elapsedElapsed time since start (default)
--clockWall-clock time HH:MM:SS
--clock-msWall-clock with milliseconds HH:MM:SS.mmm
Output Format
ParameterDescription
--format textTab-separated text (default)
--format csvComma-separated values
--format xmlXML elements
Logging
ParameterDescription
--log <file>Log output to file
--log-appendAppend to existing log
--log-limit <MB>Max log file size in MB
--log-wrapWrap log when full
--log-dailyNew log file each day
Boot Logging (Requires Admin)
ParameterDescription
--boot-enableEnable boot-time kernel debug logging
--boot-disableDisable boot-time logging
--boot-statusShow boot logging status and exit
Remote Monitoring
ParameterDescription
--connect <computer>Connect to remote DbgView instance
--disconnectDisconnect from remote
Crash Dump & File Operations
ParameterDescription
--crashdump <file>Analyze crash dump for debug output
--load <file>Load saved log file
--save <file>Save captured output on exit
Runtime Control (Inter-Process)
ParameterDescription
--pausePause a running DbgViewCli instance via named event
--resumeResume a paused DbgViewCli instance
--stopStop a running DbgViewCli instance gracefully
Miscellaneous
ParameterShortDescription
--quit-qTerminate running GUI DbgView instance
--accepteulaAccept the EULA (writes registry key, skips prompt)
--versionShow version and exit
--help-?Show help

Usage Examples

Basic Win32 Capture (bounded)
bash
# Capture for 30 seconds, no banner, output as text
dbgviewcli --no-banner --duration 30

# Capture until a specific error appears
dbgviewcli --no-banner --wait-for "*ERROR*" --max-lines 10000
Kernel Debug Capture (requires admin)
bash
# Run as Administrator
dbgviewcli --kernel --no-banner --duration 60 --format csv --log kernel_debug.csv
Process-Specific Filtering
bash
# Filter by PID
dbgviewcli --no-banner --pid-filter 1234 --duration 10

# Filter by process name
dbgviewcli --no-banner --process-filter "myapp.exe" --max-lines 500
Pattern-Based Filtering
bash
# Include only lines matching pattern
dbgviewcli --no-banner --filter "MyDriver*" --exclude "verbose*"
Tail Mode (recent context)
bash
# Capture but only output last 50 lines on exit
dbgviewcli --no-banner --tail 50 --duration 30
Status Check (machine-readable)
bash
dbgviewcli --status
# Output:
# running=true
# paused=false
# elevated=true
Boot Logging
bash
# Enable (requires admin, persists across reboot)
dbgviewcli --boot-enable

# Check status
dbgviewcli --boot-status

# Disable
dbgviewcli --boot-disable
Remote Monitoring
bash
dbgviewcli --connect SERVER01 --no-banner --duration 60
Runtime Control (Pause/Resume/Stop)
bash
# Pause a running instance from another terminal
dbgviewcli --pause

# Resume the paused instance
dbgviewcli --resume

# Gracefully stop a running instance
dbgviewcli --stop
EULA Acceptance (Unattended)
bash
# Accept EULA non-interactively for automated/scripted deployments
dbgviewcli --accepteula --no-banner --duration 30
Show full SKILL.md (358 more words)Show less

Architecture

ModuleFilePurpose
Maindbgviewcli.cEntry point, arg parsing, capture loop, Ctrl+C handler
Capturecli_capture.cDBWIN shared memory, kernel driver read
Drivercli_driver.cKernel driver load/unload, privilege elevation
Filtercli_filter.cWildcard include/exclude matching
Outputcli_output.cConsole emit, log files, CSV/XML/text formats
Boot Logcli_bootlog.cRegistry config for boot-time driver loading
Remotecli_remote.cTCP socket connect/read for remote monitoring

Key Design Decisions

  1. Static CRT linking — No DLL dependencies, runs on any Windows system
  2. stdout/stderr separation — Debug output → stdout; errors/status → stderr
  3. Bounded execution — --duration, --max-lines, --wait-for ensure guaranteed exit for automation
  4. Clean output — --no-banner suppresses noise for pipe/agent consumption
  5. Machine-readable status — --status outputs key=value pairs for programmatic checks
  6. Graceful shutdown — SetConsoleCtrlHandler ensures clean driver unload on Ctrl+C

Best Practices

  1. Always use --no-banner for scripted/automated use. Banner text pollutes structured output and confuses parsers.
  2. Always bound execution with --duration, --max-lines, or --wait-for. Unbounded capture will run indefinitely.
  3. Check status before capture — Use --status to detect if another instance is already running.
  4. Use --format csv or --format xml when output will be parsed programmatically.
  5. Prefer --pid-filter or --process-filter over broad capture to reduce noise.
  6. Run as Administrator only when needed — kernel and boot logging require elevation; Win32 capture does not.
  7. Combine bounds for safety — Use --duration 60 --max-lines 10000 together so whichever triggers first wins.
  8. Use --tail for "what just happened" queries instead of capturing full history.

Bundled Resources

TypeFilePurpose
Scriptscripts/detect-dbgview.ps1Locate dbgviewcli.exe on PATH or common directories
Scriptscripts/capture-wrapper.ps1Safe bounded capture with parameter validation
Scriptscripts/boot-logging-workflow.ps1End-to-end boot logging lifecycle management
Referencereferences/driver-ioctls.mdKernel driver IOCTL codes and buffer structures
Referencereferences/output-formats.mdText/CSV/XML output format specifications
Referencereferences/remote-protocol.mdTCP remote monitoring wire protocol

Troubleshooting

IssueResolution
"Access denied" on kernel captureRun as Administrator
No output from Win32 captureVerify target app uses OutputDebugString; check no debugger is attached
Another instance runningUse --status to check; use --quit to terminate existing GUI instance
Boot logging not capturingEnsure --boot-enable was run as admin; driver must be in System32\Drivers
Remote connection failsVerify target has DbgView running with remote enabled on ports 2020-2030

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in .github/skills/debugview of microsoft/skills.

  • SKILL.md
  • references/driver-ioctls.md
  • references/output-formats.md
  • references/remote-protocol.md
  • scripts/boot-logging-workflow.ps1
  • scripts/capture-wrapper.ps1
  • scripts/detect-dbgview.ps1

Open the folder on GitHubat commit 354361d

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in microsoft/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

DebugView CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

DebugView CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
DebugView CLI this skillmicrosoft/skills3.1k1 repos~2.7kAutomated safety check: PassMIT
Smt E2E Dataflow DebuggingGoogleCloudPlatform/DataflowTemplates1.3k—~1.8kAutomated safety check: PassApache-2.0
Claude Session Router Debuggerweave-os/router5.6k—~2.9kAutomated safety check: PassApache-2.0
Burla Parallel Dev ClustersBurla-Cloud/burla263—~1.6kAutomated safety check: PassCustom licence
Code Reviewaide-family/moon253—~815Automated safety check: PassNone
Dotnet Debuggingnovotnyllc/dotnet-artisan233—~2.1kAutomated safety check: PassMIT

Similar skills

  • Smt E2E Dataflow Debugging

    GoogleCloudPlatform/DataflowTemplates

    Debugs logical errors and data discrepancies in Dataflow templates by launching jobs via Terraform and comparing source (e.g.

    1.3k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Correlates a Claude Code session's local transcript with a model router's production cloud logs to explain why a specific response rendered the way it did.

    5.6k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Sets up an isolated Burla dev cluster per git worktree so several agents can work in parallel, and explains when to use local-dev or remote-dev.

    263 GitHub stars~1.6k tokensUpdated 15 days ago
    DevelopmentAuto-check passed
  • Code Review

    aide-family/moon

    Reviews code for correctness and potential bugs, pinpoints bug locations by file and line, and suggests concrete fixes.

    253 GitHub stars~815 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Dotnet Debugging

    novotnyllc/dotnet-artisan

    Debugs Windows and Linux/macOS applications (native, .NET/CLR, mixed-mode) with WinDbg MCP (crash dumps, !analyze, !syncblk, !dlk, !runaway, !dumpheap, !gcroot, BSOD), dotnet-dump, lldb with SOS…

    233 GitHub stars~2.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Zizkadb Dev Setup

    ZIZKA-AI-SL/ZizkaDB

    Set up and start the local ZizkaDB development stack. An agent skill from ZIZKA-AI-SL/ZizkaDB.

    123 GitHub stars~535 tokensUpdated yesterday
    DevelopmentAuto-check: notes

More from microsoft/skills

All 150 skills in this repo
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub starsUsed in 6 repos~2.8k tokens
    Auto-check passed
  • Official

    Python guidance for the Azure AI Search SDK covering vector, hybrid and semantic search, index management and indexers, with Entra ID authentication preferred over keys.

    3.1k GitHub starsUsed in 6 repos~4.4k tokens
    Auto-check passed
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 6 repos~496 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed

Works with

Questions about DebugView CLI

What does DebugView CLI do?

Captures and filters Windows user-mode and kernel debug output from the command line with the Sysinternals DebugView CLI, including bounded runs suited to agents. exe, a standalone native Windows executable that captures OutputDebugString output from applications and DbgPrint or KdPrint output from kernel drivers.sys driver, which is extracted automatically.

When should I use DebugView CLI?

DebugView CLI fits situations like: capturing OutputDebugString output from a running Windows app; collecting kernel DbgPrint or KdPrint output from a driver; setting up boot-time debug logging; running a time-limited debug capture from a script.

How do I install DebugView CLI in Claude Code?

Run `npx skills add microsoft/skills --skill debugview -a claude-code`. Or copy the skill folder (.github/skills/debugview in microsoft/skills) into .claude/skills/debugview in your project. Claude Code loads it when a task matches its description.

How do I install DebugView CLI in Codex?

Run `npx skills add microsoft/skills --skill debugview -a codex`. Or copy the skill folder (.github/skills/debugview in microsoft/skills) into .agents/skills/debugview in your project. Codex loads it when a task matches its description.

Can I use DebugView CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill debugview -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/debugview, .gemini/skills/debugview, .github/skills/debugview and .opencode/skills/debugview in your project.

What does DebugView CLI need to run?

Going by SKILL.md and its folder, DebugView CLI needs PowerShell for the scripts in its folder. Our summary lists: Windows Vista or later (x64 or ARM64); dbgviewcli.exe, verified as signed by Microsoft Corporation; Administrator rights for kernel and boot capture.

Does DebugView CLI access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is DebugView CLI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does DebugView CLI use?

DebugView CLI is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does DebugView CLI use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.9k tokens, read only when the agent opens those files.

What are the alternatives to DebugView CLI?

Skills that share tags, products or a category with DebugView CLI: Smt E2E Dataflow Debugging (GoogleCloudPlatform/DataflowTemplates, 1.3k stars), Claude Session Router Debugger (weave-os/router, 5.6k stars), Burla Parallel Dev Clusters (Burla-Cloud/burla, 263 stars) and Code Review (aide-family/moon, 253 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains DebugView CLI?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,091 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.