Official agent skill

Windbg Kernel Bugcheck Triage

by microsoft in microsoft/win-dev-skills

A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

OfficialMITAuto-check passed

Install Windbg Kernel Bugcheck Triage

skills CLI
$ npx skills add microsoft/win-dev-skills --skill windbg-kernel-bugcheck-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/win-dev-skills windbg-kernel-bugcheck-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/win-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/windbg/skills/windbg-kernel-bugcheck-triage .claude/skills/windbg-kernel-bugcheck-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windbg-kernel-bugcheck-triage
GitHub stars
462
Token cost
~1.3k tokens
SKILL.md length
528 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

  • Works in 4 steps: Establish symbols and bugcheck evidence → Decode parameters for the specific code → Recover the original faulting context → …
  • A kernel dump reports a Windows bugcheck
  • SKILL.md covers Scope, Workflow, Validation and References, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windbg Kernel Bugcheck Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver. Not for user-mode process crashes or blaming a module from its name alone.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Agent plugins for building Windows apps with GitHub Copilot, Claude Code, OpenAI Codex, and more. The licence is MIT.

When your agent uses it

  • A kernel dump reports a Windows bugcheck
  • Decode parameters and recover exception
  • Trap context before investigating your driver

Example prompts

  • “/windbg-kernel-bugcheck-triage”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Establish symbols and bugcheck evidence
  2. Decode parameters for the specific code
  3. Recover the original faulting context
  4. Investigate the driver, not just the detector

What it can do on your machine

Read from SKILL.md and the folder at commit 5ce74fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windbg Kernel Bugcheck Triage loads about 1.3k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 528 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/win-dev-skills at commit 5ce74fa, republished under its MIT licence (© microsoft). 528 words, ~1,317 tokens.

Download SKILL.mdSave it as .claude/skills/windbg-kernel-bugcheck-triage/SKILL.md (or your agent's skills folder).
name
windbg-kernel-bugcheck-triage
description
Use when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver. Not for user-mode process crashes or blaming a module from its name alone.

Kernel Bugcheck Triage

Load windbg-diagnostic-method first if it is not already loaded in this conversation, and apply it throughout for evidence ranking, hypothesis testing, confidence calibration, independent review, and report validation. This skill adds the bug-family-specific commands and evidence requirements.

Scope

Use a kernel crash dump or authorized live kernel session. A process dump captured after a reboot does not contain the earlier kernel fault. Confirm the dump type with the debugger, not a filename or the user's visible symptom. This skill includes exception-context and trap-frame recovery.

Workflow

1. Establish symbols and bugcheck evidence
text
.symfix
.sympath+ <your-vendor-symbol-directory>
.reload
!analyze -v
.bugcheck
k

Replace the placeholder with the approved symbol location for your own binaries. Record dump type, target architecture/build, bugcheck code and parameters, faulting instruction, and available memory. Public Windows symbols suffice for many investigations; do not require private Windows source or PDBs.

2. Decode parameters for the specific code
CodeParameter meaning / next step
0x1EP1 exception code; P2 exception address; P3/P4 exception-specific information. These are not generically a CONTEXT pair.
0x7EP1 exception code; P2 exception address; P3 EXCEPTION_RECORD; P4 CONTEXT.
0x3BP1 exception code; P2 instruction address; P3 CONTEXT; P4 unused.
0x0A / 0xD1Referenced address, IRQL, access information, instruction address. Decode the access field for that code; these parameters are not generally a trap-frame pointer.
0x50Invalid memory reference; parameter interpretation varies with target version. Consult the code reference.
0x9FP1 selects the power-failure subtype; use its specific parameter table and windbg-kernel-irp-lifecycle-triage where applicable.
Verifier-class stopUse windbg-kernel-verifier-triage and the exact code/subcode definition.

Do not reuse a parameter layout across different bugchecks.

3. Recover the original faulting context

For 0x7E:

text
.exr <P3>
.cxr <P4>
kb
r

For 0x3B:

text
.cxr <P3>
kb
r

For other exception-style bugchecks, locate a valid saved exception/context using the documented code procedure and available analysis output. Do not guess .cxr arguments from arbitrary P1..P4 values.

When !analyze -v or verified stack evidence identifies a TRAP_FRAME:

text
.trap <trap-frame-address>
kb
r

Trap frames can be partial: some registers may be missing or reconstructed incorrectly. Note the debugger's warnings and do not treat unsaved registers as reliable evidence. If a frame is missing, malformed, or absent from the dump, report the limitation rather than scanning arbitrary pointers and claiming a recovered context.

Show full SKILL.md (174 more words)Show less
4. Investigate the driver, not just the detector
text
!thread
lmvm <driver-module>
.frame /r <frame-number>

Inspect the recovered instruction, register/object used, IRQL, ownership, and nearby driver frames. A crash in an operating-system routine may result from prior driver corruption. Conversely, a third-party name in MODULE_NAME does not establish that the named driver caused the failure. Verify vendor build identity against the matching binary/PDB.

For concurrency or blocked requests use windbg-kernel-lock-deadlock-triage or windbg-kernel-irp-lifecycle-triage. Kernel ~ commands select processors, not the application thread list; use documented thread/process inspection such as !thread and !process 0 7.

Validation

Record the decoded parameters, recovered context and its limitations, and the evidence connecting the driver's operation to the violated invariant. Test competing lifetime, bounds, IRQL, and synchronization explanations. Recommend an instrumented test/repro only with approval; route Verifier evidence to windbg-kernel-verifier-triage. Do not call a guessed module assignment a proven cause.

References

Feedback

Follow FEEDBACK.md and submit only reviewed, sanitized feedback to WinDbg-Feedback. Include windbg-kernel-bugcheck-triage and the package version from plugin.json; no automatic kernel dump, private-symbol, or source upload.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/windbg/skills/windbg-kernel-bugcheck-triage of microsoft/win-dev-skills.

Open the folder on GitHubat commit 5ce74fa

Compare with similar skills

Windbg Kernel Bugcheck Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windbg Kernel Bugcheck Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windbg Kernel Bugcheck Triage this skillmicrosoft/win-dev-skills462—~1.3kAutomated safety check: PassMIT
Triaging Windows With Kapemukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Windows Kernel Securitygmh5225/awesome-game-security3.6k—~317Automated safety check: PassMIT
Triaging Issuespytorch/pytorch104k—~4.2kAutomated safety check: PassCustom licence
Issue Triagepaperclipai/paperclip99k—~1kAutomated safety check: PassMIT
Triagepnpm/pnpm37k—~2.9kAutomated safety check: PassMIT

Similar skills

  • Triaging Windows With Kape

    mukul975/Anthropic-Cybersecurity-Skills

    Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted forensic artifacts (registry hives, $MFT, event logs, prefetch, browser data) via Targets and parse them with Modules wrapping…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Windows Kernel Security

    gmh5225/awesome-game-security

    Analyze Windows driver trust, callbacks, IRQL, kernel memory, DSE, PatchGuard, VBS/HVCI, ETW, crash evidence, and build-specific internals for authorized game-security research.

    3.6k GitHub stars~317 tokensUpdated today
    Auto-check passed
  • Triaging Issues

    pytorch/pytorch

    Triages GitHub issues by routing to oncall teams, applying labels, and closing questions.

    104k GitHub stars~4.2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Issue Triage

    paperclipai/paperclip

    Triage Paperclip inbox issues that are stale, blocked, in-review, or assigned-but-not-progressing, and decide a single next action per issue (resume, reassign, unblock, escalate, or close).

    99k GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Triage

    pnpm/pnpm

    Triage an incoming GitHub issue against the pnpm codebase and related open issues, then apply exactly one implementation-readiness label using pnpm's state: taxonomy.

    37k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Herdr Issue Triage

    herdrdev/herdr

    Triages open herdr GitHub issues into a short decision-first Markdown table with a priority light, recommendation, age, reactions and a reason for each.

    43k GitHub stars~517 tokensUpdated today
    DevelopmentAuto-check passed

More from microsoft/win-dev-skills

All 11 skills in this repo
  • Windbg Diagnostic Method

    microsoft/win-dev-skills

    Official

    Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

    462 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Irp Lifecycle Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Lock Deadlock Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Verifier Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg User Exception Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Official

    A skill your agent uses when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds.

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Questions about Windbg Kernel Bugcheck Triage

What does Windbg Kernel Bugcheck Triage do?

A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver. Windbg Kernel Bugcheck Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

When should I use Windbg Kernel Bugcheck Triage?

Windbg Kernel Bugcheck Triage fits situations like: A kernel dump reports a Windows bugcheck; decode parameters and recover exception; trap context before investigating your driver.

How do I install Windbg Kernel Bugcheck Triage in Claude Code?

Run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-bugcheck-triage -a claude-code`. Or copy the skill folder (plugins/windbg/skills/windbg-kernel-bugcheck-triage in microsoft/win-dev-skills) into .claude/skills/windbg-kernel-bugcheck-triage in your project. Claude Code loads it when a task matches its description.

How do I install Windbg Kernel Bugcheck Triage in Codex?

Run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-bugcheck-triage -a codex`. Or copy the skill folder (plugins/windbg/skills/windbg-kernel-bugcheck-triage in microsoft/win-dev-skills) into .agents/skills/windbg-kernel-bugcheck-triage in your project. Codex loads it when a task matches its description.

Can I use Windbg Kernel Bugcheck Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-bugcheck-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windbg-kernel-bugcheck-triage, .gemini/skills/windbg-kernel-bugcheck-triage, .github/skills/windbg-kernel-bugcheck-triage and .opencode/skills/windbg-kernel-bugcheck-triage in your project.

What does Windbg Kernel Bugcheck Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Windbg Kernel Bugcheck Triage is instructions for the agent only.

Does Windbg Kernel Bugcheck Triage access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Windbg Kernel Bugcheck Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windbg Kernel Bugcheck Triage use?

Windbg Kernel Bugcheck Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windbg Kernel Bugcheck Triage use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windbg Kernel Bugcheck Triage?

Skills that share tags, products or a category with Windbg Kernel Bugcheck Triage: Triaging Windows With Kape (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Windows Kernel Security (gmh5225/awesome-game-security, 3.6k stars), Triaging Issues (pytorch/pytorch, 104k stars) and Issue Triage (paperclipai/paperclip, 99k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windbg Kernel Bugcheck Triage?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/win-dev-skills, which has 462 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/win-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.