Official agent skill

Windbg Diagnostic Method

by microsoft in microsoft/win-dev-skills

Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

OfficialMITAuto-check passedBusiness, Finance & HR

Install Windbg Diagnostic Method

skills CLI
$ npx skills add microsoft/win-dev-skills --skill windbg-diagnostic-method -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/win-dev-skills windbg-diagnostic-method --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/win-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/windbg/skills/windbg-diagnostic-method .claude/skills/windbg-diagnostic-method && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windbg-diagnostic-method
GitHub stars
462
Token cost
~1.9k tokens
SKILL.md length
894 words
Files
2 (incl. scripts)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

  • Works in 5 steps: Faulting instruction/context, bugcheck… → Matching symbols and the user's… → Allocation/free, Verifier, IRP, lock,… → …
  • Tasks that involve Performance reviews
  • SKILL.md covers Evidence ladder, First-pass normalization, Five-phase investigation and Routing index, plus 8 more sections
  • Runs PowerShell scripts from its folder; calls pwsh

What it does

Windbg Diagnostic Method is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation. Not a bug-family-specific triage skill.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.

It sits in Business, Finance & HR, covering Performance reviews. The repository describes itself as: Agent plugins for building Windows apps with GitHub Copilot, Claude Code, OpenAI Codex, and more. The licence is MIT.

When your agent uses it

  • Tasks that involve Performance reviews

Example prompts

  • “/windbg-diagnostic-method”

Requirements

  • PowerShell

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Faulting instruction/context, bugcheck or exception parameters, and resource
  2. Matching symbols and the user's authorized source for the involved build.
  3. Allocation/free, Verifier, IRP, lock, ETW, WCT, or TTD history captured for
  4. Controlled reproduction and instrumentation.
  5. Pattern guidance as a hypothesis only.

What it can do on your machine

Read from SKILL.md and the folder at commit 5ce74fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (PowerShell), which the agent can run.

    Shell commands in SKILL.md call:

    • pwsh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windbg Diagnostic Method loads about 1.9k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 894 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from microsoft/win-dev-skills at commit 5ce74fa, republished under its MIT licence (© microsoft). 894 words, ~1,944 tokens.

Download SKILL.mdSave it as .claude/skills/windbg-diagnostic-method/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
windbg-diagnostic-method
description
Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation. Not a bug-family-specific triage skill.
user-invocable
false

WinDbg Diagnostic Method

Apply this method alongside the bug-family-specific skill selected for an investigation. Pattern matches route the investigation; they do not prove the root cause.

Evidence ladder

Prefer direct evidence in this order:

  1. Faulting instruction/context, bugcheck or exception parameters, and resource owners/waiters from the actual dump or trace.
  2. Matching symbols and the user's authorized source for the involved build.
  3. Allocation/free, Verifier, IRP, lock, ETW, WCT, or TTD history captured for the same failure.
  4. Controlled reproduction and instrumentation.
  5. Pattern guidance as a hypothesis only.

Never claim commands, source access, or artifacts that are unavailable in the session.

First-pass normalization

  • Confirm process dump versus kernel dump and target architecture/build.
  • Load public Windows symbols and matching symbols for user/vendor modules.
  • Record missing pages, symbols, related-process dumps, trace scope, and tool availability.
  • User-mode exception: .exr -1, .ecxr, stack, and registers.
  • Kernel bugcheck: .bugcheck, !analyze -v, then documented context/trap recovery for that code.
  • Hang: identify the affected operation, wait type, owner/server, and deepest supported blocker.
  • Memory: distinguish corruption, address-space pressure, and commit/limit failures before choosing a fix.

Five-phase investigation

  1. OBSERVE: establish dump/trace type, architecture, symbols, code, stack, registers, thread/resource state, and missing evidence.
  2. HYPOTHESIZE: form a specific primary mechanism and at least two plausible alternatives when the evidence permits.
  3. TEST: identify direct debugger, source, trace, or reproduction evidence that distinguishes the hypotheses. Absence of evidence is not evidence of absence.
  4. EVALUATE: record supporting, contradictory, and missing evidence.
  5. CONCLUDE or PIVOT: name the violated invariant and verification plan, or remain candidate-pending-verification.

Routing index

EvidenceSkill
Native user-mode exception in an app, service, or UMDF/user-mode driver hostwindbg-user-exception-triage
User-mode heap corruption or allocation/free historywindbg-user-heap-corruption-investigation
Cross-thread/process, COM/RPC, or service waitwindbg-user-wait-chain-analysis
User-mode TTD history questionwindbg-user-ttd-reverse-debugging-triage
User-mode VA fragmentation, allocation failure, or commit pressurewindbg-user-virtual-memory-exhaustion
Thread-affine lock across coroutine suspensionwindbg-user-mutex-held-across-co-await
Kernel bugcheck, trap frame, or saved contextwindbg-kernel-bugcheck-triage
Driver Verifier violationwindbg-kernel-verifier-triage
Outstanding/power IRP, completion, or cancellationwindbg-kernel-irp-lifecycle-triage
Kernel lock owner/waiter chainwindbg-kernel-lock-deadlock-triage

These are the complete bug-family routes. Continue evidence-led reasoning for unsupported families; never dispatch to an absent skill.

Routing depth

  • Fast (indicative diagnosis confidence >=0.80): validate the apparent pattern, its required evidence, and plausible alternatives.
  • Validate (0.40-0.79): test the leading pattern and at least one plausible alternative through the full cycle.
  • Full reasoning (<0.40 or no match): reason from observations and preserve explicit uncertainty.

Confidence is explanatory judgment, not measured probability.

Trigger and fix gates

  • Verify the trigger in the dump, disassembly, source, trace, or controlled reproduction before declaring a final fix.
  • Name the violated invariant and the parties or path that violate it.
  • Separate the detector or victim from the original writer, freeing actor, or resource holder.
  • A fix must restore the violated invariant, not merely suppress the reproducer.
  • If the trigger is unverified, use candidate-pending-verification, set the fix to null or a verification plan, and name the evidence/fix matrix needed.
  • Do not blame a module solely from a bucket or MODULE_NAME.
Show full SKILL.md (403 more words)Show less

Fix-confidence calibration

Diagnosis confidence and fix confidence are separate. Every proposed fix must declare fix_confidence and one fix_code_path_coverage value:

Fix confidenceRequired coverage
>=0.90read-this-session: the actual fix path was read in this investigation.
0.70-0.89read-prior-session or symbol-or-disassembly: direct coverage exists, but the complete source path was not read in this investigation.
0.50-0.69pattern-only, or incomplete symbol/disassembly evidence. Treat the fix as a candidate.
<0.50not-read: no direct fix-path coverage. Keep the diagnosis candidate-pending-verification and set the fix to null or a verification plan.

Lower confidence is always allowed when evidence quality, path coverage, or alternatives warrant it. Never raise confidence to fit the table.

Independent review

Before finalizing a full diagnosis:

  1. When the host supports the bundled Copilot agents, invoke the contrarian agent once with the complete proposed diagnosis.
  2. When the host cannot run that agent, state that the independent review did not run; do not silently substitute inline self-review.
  3. If the verdict is CHALLENGED, test the counter-hypothesis with direct evidence, then downgrade confidence or remain pending verification.
  4. Stop after one loopback. A second challenge remains pending verification.

Record contrarian_loopback as the Boolean true or false.

Report contract

A full report contains these H2 sections in order:

  1. Analysis
  2. Root Cause
  3. Fix
  4. Reasoning Chain
  5. Alternatives Considered
  6. Trigger Verification
  7. Mermaid
  8. Contrarian Verdict
  9. JSON Output Contract Summary

The Trigger Verification section must distinguish observed, contradictory, and missing evidence plus fix validation. Mermaid must reflect verified evidence. The JSON summary must include:

  • diagnosis_status
  • routing_path
  • root_cause
  • confidence
  • fix_confidence
  • fix_code_path_coverage
  • contrarian_review
  • contrarian_loopback

Deterministic report validation

After writing the report, run the bundled validator with PowerShell 7:

powershell
pwsh -NoProfile -File <skill-directory>\scripts\validate-diagnosis-output.ps1 `
  -Path <diagnosis-markdown-path>

Use the installed windbg-diagnostic-method directory for <skill-directory>. The script checks each section body independently, requires at least two alternatives, accepts explicit or implicit Mermaid participants, parses the JSON summary, and exits nonzero on failure.

Correct failed checks and rerun the script before presenting the report as structurally complete. Structural validation does not replace technical review.

Safety and privacy

Dumps, traces, ETLs, CABs, source, paths, tokens, and memory contents can be sensitive. Obtain authorization before capture, configuration changes, or sharing. Verifier and Page Heap can disrupt workloads and require a recoverable test plan plus restoration steps. Public feedback follows FEEDBACK.md and defaults to a minimal reviewed summary with no automatic attachments.

Feedback

For feedback about this method or validator, follow the package FEEDBACK.md. Do not attach private diagnosis files automatically.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in plugins/windbg/skills/windbg-diagnostic-method of microsoft/win-dev-skills.

  • SKILL.md
  • scripts/validate-diagnosis-output.ps1

Open the folder on GitHubat commit 5ce74fa

Compare with similar skills

Windbg Diagnostic Method next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windbg Diagnostic Method compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windbg Diagnostic Method this skillmicrosoft/win-dev-skills462—~1.9kAutomated safety check: PassMIT
Wp Performance Reviewelvismdev/claude-wordpress-skills2351 repos~4.5kAutomated safety check: PassMIT
Align Humanagentscope-ai/OpenJudge868—~3.1kAutomated safety check: PassApache-2.0
Performance ReportAffitor/affiliate-skills6991 repos~2.5kAutomated safety check: PassMIT
Run Mv Hoi Reconstructionnvidia-isaac/video_to_data850—~1.5kAutomated safety check: PassCustom licence
Company Analysiszhu1090093659/dsh-trading231—~4.2kAutomated safety check: PassCustom licence

Similar skills

  • Wp Performance Review

    elvismdev/claude-wordpress-skills

    WordPress performance code review and optimization analysis.

    235 GitHub starsUsed in 1 repo~4.5k tokens
    Business, Finance & HRAuto-check passed
  • Align Human

    agentscope-ai/OpenJudge

    A skill your agent uses when the user has a judge/grader and human-labeled data, and wants to measure how well the judge agrees with humans, detect systematic biases, determine whether automatic…

    868 GitHub stars~3.1k tokensUpdated 27 days ago
    Business, Finance & HRAuto-check passed
  • Performance Report

    Affitor/affiliate-skills

    Generate affiliate performance reports with KPIs and recommendations.

    699 GitHub starsUsed in 1 repo~2.5k tokens
    Business, Finance & HRAuto-check passed
  • Run Mv Hoi Reconstruction

    nvidia-isaac/video_to_data

    Run and validate the repository-local multi-view camera calibration and human-object reconstruction pipelines.

    850 GitHub stars~1.5k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Company Analysis

    zhu1090093659/dsh-trading

    A skill your agent uses when the user wants to analyze a listed company, stock, business, or investment target; challenge or revise an existing company report; compare A/H or primary-listing/ADR…

    231 GitHub stars~4.2k tokensUpdated 5 days ago
    Business, Finance & HRAuto-check passed
  • AI Index

    mizchi/skills

    Method and tooling for measuring how AI-generated a piece of prose reads, in Japanese or English.

    356 GitHub stars~3.6k tokensUpdated 6 days ago
    Business, Finance & HRAuto-check passed

More from microsoft/win-dev-skills

All 11 skills in this repo
  • Windbg Kernel Bugcheck Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

    462 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Windbg Kernel Irp Lifecycle Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

    462 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Windbg Kernel Lock Deadlock Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

    462 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Windbg Kernel Verifier Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

    462 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Windbg User Exception Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

    462 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds.

    462 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Questions about Windbg Diagnostic Method

What does Windbg Diagnostic Method do?

Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation. Windbg Diagnostic Method is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

When should I use Windbg Diagnostic Method?

Windbg Diagnostic Method fits situations like: tasks that involve Performance reviews.

How do I install Windbg Diagnostic Method in Claude Code?

Run `npx skills add microsoft/win-dev-skills --skill windbg-diagnostic-method -a claude-code`. Or copy the skill folder (plugins/windbg/skills/windbg-diagnostic-method in microsoft/win-dev-skills) into .claude/skills/windbg-diagnostic-method in your project. Claude Code loads it when a task matches its description.

How do I install Windbg Diagnostic Method in Codex?

Run `npx skills add microsoft/win-dev-skills --skill windbg-diagnostic-method -a codex`. Or copy the skill folder (plugins/windbg/skills/windbg-diagnostic-method in microsoft/win-dev-skills) into .agents/skills/windbg-diagnostic-method in your project. Codex loads it when a task matches its description.

Can I use Windbg Diagnostic Method in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/win-dev-skills --skill windbg-diagnostic-method -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windbg-diagnostic-method, .gemini/skills/windbg-diagnostic-method, .github/skills/windbg-diagnostic-method and .opencode/skills/windbg-diagnostic-method in your project.

What does Windbg Diagnostic Method need to run?

Going by SKILL.md and its folder, Windbg Diagnostic Method needs PowerShell for the scripts in its folder and the command-line tools its instructions call (pwsh). Our summary lists: PowerShell.

Does Windbg Diagnostic Method access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Windbg Diagnostic Method safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Windbg Diagnostic Method use?

Windbg Diagnostic Method is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windbg Diagnostic Method use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windbg Diagnostic Method?

Skills that share tags, products or a category with Windbg Diagnostic Method: Wp Performance Review (elvismdev/claude-wordpress-skills, 235 stars), Align Human (agentscope-ai/OpenJudge, 868 stars), Performance Report (Affitor/affiliate-skills, 699 stars) and Run Mv Hoi Reconstruction (nvidia-isaac/video_to_data, 850 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windbg Diagnostic Method?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/win-dev-skills, which has 462 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/win-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.