Official agent skill

Windbg Kernel Irp Lifecycle Triage

by microsoft in microsoft/win-dev-skills

A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

OfficialMITAuto-check passed

Install Windbg Kernel Irp Lifecycle Triage

skills CLI
$ npx skills add microsoft/win-dev-skills --skill windbg-kernel-irp-lifecycle-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/win-dev-skills windbg-kernel-irp-lifecycle-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/win-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/windbg/skills/windbg-kernel-irp-lifecycle-triage .claude/skills/windbg-kernel-irp-lifecycle-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windbg-kernel-irp-lifecycle-triage
GitHub stars
462
Token cost
~1.1k tokens
SKILL.md length
469 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

  • Works in 4 steps: Decode the known request → Follow the stack and ownership → Correlate dependencies → …
  • Kernel evidence shows stalled I/O
  • SKILL.md covers Scope, Workflow, Validation and References, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windbg Kernel Irp Lifecycle Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership. Not for interpreting an empty IRP search in a limited dump as proof of healthy I/O.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Agent plugins for building Windows apps with GitHub Copilot, Claude Code, OpenAI Codex, and more. The licence is MIT.

When your agent uses it

  • Kernel evidence shows stalled I/O
  • Completion/cancellation misuse
  • Inspect request state and driver ownership

Example prompts

  • “/windbg-kernel-irp-lifecycle-triage”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Decode the known request
  2. Follow the stack and ownership
  3. Correlate dependencies
  4. Test the request protocol

What it can do on your machine

Read from SKILL.md and the folder at commit 5ce74fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windbg Kernel Irp Lifecycle Triage loads about 1.1k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 469 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/win-dev-skills at commit 5ce74fa, republished under its MIT licence (© microsoft). 469 words, ~1,081 tokens.

Download SKILL.mdSave it as .claude/skills/windbg-kernel-irp-lifecycle-triage/SKILL.md (or your agent's skills folder).
name
windbg-kernel-irp-lifecycle-triage
description
Use when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership. Not for interpreting an empty IRP search in a limited dump as proof of healthy I/O.

IRP Lifecycle Triage

Load windbg-diagnostic-method first if it is not already loaded in this conversation, and apply it throughout for evidence ranking, hypothesis testing, confidence calibration, independent review, and report validation. This skill adds the bug-family-specific commands and evidence requirements.

Scope

Investigate I/O Request Packets in a kernel dump or authorized live kernel session. Examples include 0x9F power failures and hangs where progress depends on a driver request. Apply the parameter table for the specific bugcheck subtype rather than assuming every 0x9F identifies the same object.

For 0x9F with P1 equal to 3, P4 is the blocked IRP. Inspect that directly before running a system-wide search.

Workflow

1. Decode the known request
text
!analyze -v
!irp <irp-address>

When no request address is known and the dump has the required pool data:

text
!irpfind

!irpfind can be expensive in a live session and incomplete in a limited dump. Use supported filters where appropriate. No result does not prove there are no outstanding requests.

2. Follow the stack and ownership

Record the major/minor operation, current stack location, device/driver stack, completion routine, pending flags, cancellation state, and any relevant thread. Use the available device stack and driver source to establish which component is expected to advance or complete the request.

Do not identify an offending driver solely by the last name printed in the IRP stack. A completion routine, downstream dependency, or framework-owned request may change the responsible path.

3. Correlate dependencies
EvidenceNext investigation
I/O verifier violation or available shadow historywindbg-kernel-verifier-triage
Owner/waiter kernel lock chainwindbg-kernel-lock-deadlock-triage
Exception or trap during request handlingwindbg-kernel-bugcheck-triage

Preserve evidence between skills; avoid repeatedly handing the same unchanged IRP back and forth.

Show full SKILL.md (200 more words)Show less
4. Test the request protocol
  • Power request: inspect the subtype's objects and power/PnP state, current stack location, and completion dependency.
  • Cancellation race: establish which routine owns completion, how cancellation synchronizes with normal completion, and whether the request can be completed twice or retained after cancellation.
  • Double completion: trace competing terminal paths; a single live IRP snapshot may not contain enough history.
  • Pending request: verify API/framework-specific pending and completion rules, remove/shutdown paths, and who promises eventual progress.

WDM and WDF have different ownership APIs. Do not transplant a raw WDM completion/cancel pattern into a framework-owned request without checking its contract. This skill establishes evidence; it is not a complete I/O protocol reference or a decoder for every power subtype.

Validation

Name the operation, current owner/dependency, and supported protocol violation or stalled path. Test normal completion, concurrent cancellation, removal, power transitions, and shutdown where relevant. If history is missing, propose an approved instrumented test using the verifier skill rather than inventing which driver lost the completion.

References

Feedback

Follow FEEDBACK.md and report only reviewed, sanitized feedback to WinDbg-Feedback. Include windbg-kernel-irp-lifecycle-triage and the package version from plugin.json; no automatic kernel dump or request-content upload.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/windbg/skills/windbg-kernel-irp-lifecycle-triage of microsoft/win-dev-skills.

Open the folder on GitHubat commit 5ce74fa

Compare with similar skills

Windbg Kernel Irp Lifecycle Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windbg Kernel Irp Lifecycle Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windbg Kernel Irp Lifecycle Triage this skillmicrosoft/win-dev-skills462—~1.1kAutomated safety check: PassMIT
Triaging Issuespytorch/pytorch104k—~4.2kAutomated safety check: PassCustom licence
Issue Triagepaperclipai/paperclip99k—~1kAutomated safety check: PassMIT
Triagepnpm/pnpm37k—~2.9kAutomated safety check: PassMIT
Herdr Issue Triageherdrdev/herdr43k—~517Automated safety check: PassApache-2.0
RTK Combined Issue and PR Triagertk-ai/rtk83k—~1.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Triaging Issues

    pytorch/pytorch

    Triages GitHub issues by routing to oncall teams, applying labels, and closing questions.

    104k GitHub stars~4.2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Issue Triage

    paperclipai/paperclip

    Triage Paperclip inbox issues that are stale, blocked, in-review, or assigned-but-not-progressing, and decide a single next action per issue (resume, reassign, unblock, escalate, or close).

    99k GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Triage

    pnpm/pnpm

    Triage an incoming GitHub issue against the pnpm codebase and related open issues, then apply exactly one implementation-readiness label using pnpm's state: taxonomy.

    37k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Herdr Issue Triage

    herdrdev/herdr

    Triages open herdr GitHub issues into a short decision-first Markdown table with a priority light, recommendation, age, reactions and a reason for each.

    43k GitHub stars~517 tokensUpdated today
    DevelopmentAuto-check passed
  • Runs issue triage and PR triage in parallel, then cross-analyzes the results to flag duplicate coverage, security gaps, P0 issues with no PR, and PR conflicts.

    83k GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Triage

    TalAter/annyang

    Triage and close GitHub issues on TalAter/annyang. An agent skill from TalAter/annyang.

    6.8k GitHub starsUsed in 1 repo~810 tokens
    AI & LLM EngineeringAuto-check: notes

More from microsoft/win-dev-skills

All 11 skills in this repo
  • Windbg Diagnostic Method

    microsoft/win-dev-skills

    Official

    Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

    462 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Bugcheck Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Lock Deadlock Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Verifier Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg User Exception Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Official

    A skill your agent uses when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds.

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Questions about Windbg Kernel Irp Lifecycle Triage

What does Windbg Kernel Irp Lifecycle Triage do?

A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership. Windbg Kernel Irp Lifecycle Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

When should I use Windbg Kernel Irp Lifecycle Triage?

Windbg Kernel Irp Lifecycle Triage fits situations like: kernel evidence shows stalled I/O; completion/cancellation misuse; inspect request state and driver ownership.

How do I install Windbg Kernel Irp Lifecycle Triage in Claude Code?

Run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-irp-lifecycle-triage -a claude-code`. Or copy the skill folder (plugins/windbg/skills/windbg-kernel-irp-lifecycle-triage in microsoft/win-dev-skills) into .claude/skills/windbg-kernel-irp-lifecycle-triage in your project. Claude Code loads it when a task matches its description.

How do I install Windbg Kernel Irp Lifecycle Triage in Codex?

Run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-irp-lifecycle-triage -a codex`. Or copy the skill folder (plugins/windbg/skills/windbg-kernel-irp-lifecycle-triage in microsoft/win-dev-skills) into .agents/skills/windbg-kernel-irp-lifecycle-triage in your project. Codex loads it when a task matches its description.

Can I use Windbg Kernel Irp Lifecycle Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-irp-lifecycle-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windbg-kernel-irp-lifecycle-triage, .gemini/skills/windbg-kernel-irp-lifecycle-triage, .github/skills/windbg-kernel-irp-lifecycle-triage and .opencode/skills/windbg-kernel-irp-lifecycle-triage in your project.

What does Windbg Kernel Irp Lifecycle Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Windbg Kernel Irp Lifecycle Triage is instructions for the agent only.

Does Windbg Kernel Irp Lifecycle Triage access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Windbg Kernel Irp Lifecycle Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windbg Kernel Irp Lifecycle Triage use?

Windbg Kernel Irp Lifecycle Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windbg Kernel Irp Lifecycle Triage use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windbg Kernel Irp Lifecycle Triage?

Skills that share tags, products or a category with Windbg Kernel Irp Lifecycle Triage: Triaging Issues (pytorch/pytorch, 104k stars), Issue Triage (paperclipai/paperclip, 99k stars), Triage (pnpm/pnpm, 37k stars) and Herdr Issue Triage (herdrdev/herdr, 43k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windbg Kernel Irp Lifecycle Triage?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/win-dev-skills, which has 462 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/win-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.