Official agent skill

Windbg Kernel Lock Deadlock Triage

by microsoft in microsoft/win-dev-skills

A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

OfficialMITAuto-check passed

Install Windbg Kernel Lock Deadlock Triage

skills CLI
$ npx skills add microsoft/win-dev-skills --skill windbg-kernel-lock-deadlock-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/win-dev-skills windbg-kernel-lock-deadlock-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/win-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/windbg/skills/windbg-kernel-lock-deadlock-triage .claude/skills/windbg-kernel-lock-deadlock-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windbg-kernel-lock-deadlock-triage
GitHub stars
462
Token cost
~1.1k tokens
SKILL.md length
433 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

  • Works in 4 steps: Gather owners and waiters → Inspect recorded lock-order evidence → Build and test the graph → …
  • Kernel threads block on driver synchronization
  • SKILL.md covers Detection, Workflow, Fix patterns and Validation, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windbg Kernel Lock Deadlock Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph. Not for treating every watchdog stop as a deadlock or listing every lock type with !locks.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Agent plugins for building Windows apps with GitHub Copilot, Claude Code, OpenAI Codex, and more. The licence is MIT.

When your agent uses it

  • Kernel threads block on driver synchronization
  • Verifier reports a lock-order violation
  • Build an owner/waiter graph

Example prompts

  • “/windbg-kernel-lock-deadlock-triage”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gather owners and waiters
  2. Inspect recorded lock-order evidence
  3. Build and test the graph
  4. Localize the driver path

What it can do on your machine

Read from SKILL.md and the folder at commit 5ce74fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windbg Kernel Lock Deadlock Triage loads about 1.1k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 433 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/win-dev-skills at commit 5ce74fa, republished under its MIT licence (© microsoft). 433 words, ~1,075 tokens.

Download SKILL.mdSave it as .claude/skills/windbg-kernel-lock-deadlock-triage/SKILL.md (or your agent's skills folder).
name
windbg-kernel-lock-deadlock-triage
description
Use when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph. Not for treating every watchdog stop as a deadlock or listing every lock type with !locks.

Kernel Lock and Deadlock Triage

Load windbg-diagnostic-method first if it is not already loaded in this conversation, and apply it throughout for evidence ranking, hypothesis testing, confidence calibration, independent review, and report validation. This skill adds the bug-family-specific commands and evidence requirements.

Detection

Use kernel thread stacks, synchronization-object evidence, and Driver Verifier deadlock records. A watchdog bugcheck can indicate CPU/DPC progress failures, not necessarily a lock cycle. Establish the actual waits before choosing this workflow.

Workflow

1. Gather owners and waiters
text
!locks
!thread <ethread-address>
!process 0 7

!locks enumerates ERESOURCE information. It is not an inventory of all pushlocks, fast mutexes, and spinlocks. For other primitives use documented primitive-specific inspection when available, matching symbols for your driver, its source, and recorded acquisition evidence. State missing owners explicitly.

2. Inspect recorded lock-order evidence

If Driver Verifier deadlock detection was enabled and the dump contains its records:

text
!deadlock 1

Inspect the reported resources, acquisition sequence, and threads. Verifier can detect an unsafe ordering before a persistent deadlock actually forms. An empty result without the required verification/history is not proof that the lock order is safe. For Verifier setup/safety use windbg-kernel-verifier-triage.

3. Build and test the graph
text
thread A holds resource X -> waits for Y owned by B
thread B holds resource Y -> waits for X owned by A

Show evidence for every edge. Check recursive acquisition, callbacks under locks, I/O completion dependencies, and destruction/rundown paths.

Distinguish:

  • A demonstrated cycle or Verifier-reported order inversion.
  • Contention where a runnable owner can progress.
  • Starvation or an owner blocked on a separate request.
  • Spin/IRQL problems, which are not necessarily blocking-lock deadlocks.

If blocked on an IRP use windbg-kernel-irp-lifecycle-triage; if a chain crosses into a user-mode COM/RPC operation use windbg-user-wait-chain-analysis. Carry the proven graph edges into the next skill rather than starting the same investigation again.

Show full SKILL.md (164 more words)Show less
4. Localize the driver path

Identify which call path held one resource while acquiring/waiting for another. Check the required IRQL, permitted waits, lock hierarchy, and object lifetime. Private Windows implementation layouts are not prerequisites; if public symbols and captured state cannot recover an edge, request appropriate authorized evidence and keep the conclusion provisional.

Fix patterns

Use a consistent acquisition hierarchy, reduce lock scope, avoid unbounded waits/cross-component callbacks while holding resources, and move potentially blocking destruction outside locks where the ownership design permits. Do not replace a lock or add a timeout without preserving invariants and completion/cancellation semantics.

Validation

Record the graph, supported cycle/inversion, and offending driver path. Test concurrency, callbacks, teardown, and the same applicable Verifier checks. Separate a demonstrated fix from an unproven contention hypothesis.

References

Feedback

Follow FEEDBACK.md and report reviewed, sanitized feedback to WinDbg-Feedback. Include windbg-kernel-lock-deadlock-triage and the package version from plugin.json; no automatic dump, lock-history transcript, or driver-source upload.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/windbg/skills/windbg-kernel-lock-deadlock-triage of microsoft/win-dev-skills.

Open the folder on GitHubat commit 5ce74fa

Compare with similar skills

Windbg Kernel Lock Deadlock Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windbg Kernel Lock Deadlock Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windbg Kernel Lock Deadlock Triage this skillmicrosoft/win-dev-skills462—~1.1kAutomated safety check: PassMIT
Verifyasgeirtj/system_prompts_leaks69k—~3kAutomated safety check: PassCC0-1.0
Verify Thiscursor/plugins10k2 repos~693Automated safety check: PassNone
Verify Releaseopenclaw/openclaw392k—~2.4kAutomated safety check: PassMIT
Verifycodewhale-hq/Codewhale41k—~156Automated safety check: PassMIT
Verify Before CompletionYeachan-Heo/oh-my-claudecode40k—~277Automated safety check: PassMIT

Similar skills

  • Verify

    asgeirtj/system_prompts_leaks

    Verify that a code change actually does what it's supposed to by exercising it end-to-end and observing behavior — drive the affected flow, not just tests or typecheck.

    69k GitHub stars~3k tokensUpdated today
    Testing & QAAuto-check passed
  • Verify This

    cursor/plugins

    Official

    Verify a claim with fresh local evidence: restate it falsifiably, capture baseline and treatment, compare artifacts, and return VERIFIED, NOT VERIFIED, or INCONCLUSIVE.

    10k GitHub starsUsed in 2 repos~693 tokens
    Auto-check passed
  • Verify Release

    openclaw/openclaw

    Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release…

    392k GitHub stars~2.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Verify

    codewhale-hq/Codewhale

    Exercise the real app/API/CLI and collect observable evidence; tests alone do not count as end-to-end verification.

    41k GitHub stars~156 tokensUpdated today
    Testing & QAAuto-check passed
  • Verify Before Completion

    Yeachan-Heo/oh-my-claudecode

    Has the agent prove that a feature, fix or refactor works, using existing tests first, then narrow commands and manual checks, and report only what was actually verified.

    40k GitHub stars~277 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Kernel Organization

    sgl-project/sglang

    Apply the SGLang kernels RFC when adding, moving, splitting, or reviewing kernel APIs, registry metadata, kernel tests, benchmarks, and model-specific implementations.

    37k GitHub stars~1.3k tokensUpdated today
    AI & LLM EngineeringAuto-check passed

More from microsoft/win-dev-skills

All 11 skills in this repo
  • Windbg Diagnostic Method

    microsoft/win-dev-skills

    Official

    Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

    462 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Bugcheck Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Irp Lifecycle Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Verifier Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg User Exception Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Official

    A skill your agent uses when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds.

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Questions about Windbg Kernel Lock Deadlock Triage

What does Windbg Kernel Lock Deadlock Triage do?

A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph. Windbg Kernel Lock Deadlock Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

When should I use Windbg Kernel Lock Deadlock Triage?

Windbg Kernel Lock Deadlock Triage fits situations like: kernel threads block on driver synchronization; verifier reports a lock-order violation; build an owner/waiter graph.

How do I install Windbg Kernel Lock Deadlock Triage in Claude Code?

Run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-lock-deadlock-triage -a claude-code`. Or copy the skill folder (plugins/windbg/skills/windbg-kernel-lock-deadlock-triage in microsoft/win-dev-skills) into .claude/skills/windbg-kernel-lock-deadlock-triage in your project. Claude Code loads it when a task matches its description.

How do I install Windbg Kernel Lock Deadlock Triage in Codex?

Run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-lock-deadlock-triage -a codex`. Or copy the skill folder (plugins/windbg/skills/windbg-kernel-lock-deadlock-triage in microsoft/win-dev-skills) into .agents/skills/windbg-kernel-lock-deadlock-triage in your project. Codex loads it when a task matches its description.

Can I use Windbg Kernel Lock Deadlock Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-lock-deadlock-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windbg-kernel-lock-deadlock-triage, .gemini/skills/windbg-kernel-lock-deadlock-triage, .github/skills/windbg-kernel-lock-deadlock-triage and .opencode/skills/windbg-kernel-lock-deadlock-triage in your project.

What does Windbg Kernel Lock Deadlock Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Windbg Kernel Lock Deadlock Triage is instructions for the agent only.

Does Windbg Kernel Lock Deadlock Triage access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Windbg Kernel Lock Deadlock Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windbg Kernel Lock Deadlock Triage use?

Windbg Kernel Lock Deadlock Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windbg Kernel Lock Deadlock Triage use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windbg Kernel Lock Deadlock Triage?

Skills that share tags, products or a category with Windbg Kernel Lock Deadlock Triage: Verify (asgeirtj/system_prompts_leaks, 69k stars), Verify This (cursor/plugins, 10k stars), Verify Release (openclaw/openclaw, 392k stars) and Verify (codewhale-hq/Codewhale, 41k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windbg Kernel Lock Deadlock Triage?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/win-dev-skills, which has 462 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/win-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.