Official agent skill

Windbg Kernel Verifier Triage

by microsoft in microsoft/win-dev-skills

A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

OfficialMITAuto-check passed

Install Windbg Kernel Verifier Triage

skills CLI
$ npx skills add microsoft/win-dev-skills --skill windbg-kernel-verifier-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/win-dev-skills windbg-kernel-verifier-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/win-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/windbg/skills/windbg-kernel-verifier-triage .claude/skills/windbg-kernel-verifier-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windbg-kernel-verifier-triage
GitHub stars
462
Token cost
~1.1k tokens
SKILL.md length
470 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

  • Works in 4 steps: Preserve code, subcode, and active… → Decode available I/O history → Recover context or follow dependencies → …
  • A kernel dump contains Driver Verifier violations
  • SKILL.md covers Scope, Workflow, Controlled repro and Validation, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windbg Kernel Verifier Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state. Not for Application Verifier user-mode stops or inferring a violation from enabled flags alone.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Agent plugins for building Windows apps with GitHub Copilot, Claude Code, OpenAI Codex, and more. The licence is MIT.

When your agent uses it

  • A kernel dump contains Driver Verifier violations
  • Bugcheck subcodes
  • Available I/O shadow state

Example prompts

  • “/windbg-kernel-verifier-triage”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Preserve code, subcode, and active configuration
  2. Decode available I/O history
  3. Recover context or follow dependencies
  4. Investigate uncovered violations

What it can do on your machine

Read from SKILL.md and the folder at commit 5ce74fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windbg Kernel Verifier Triage loads about 1.1k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 470 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/win-dev-skills at commit 5ce74fa, republished under its MIT licence (© microsoft). 470 words, ~1,115 tokens.

Download SKILL.mdSave it as .claude/skills/windbg-kernel-verifier-triage/SKILL.md (or your agent's skills folder).
name
windbg-kernel-verifier-triage
description
Use when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state. Not for Application Verifier user-mode stops or inferring a violation from enabled flags alone.

Driver Verifier Triage

Load windbg-diagnostic-method first if it is not already loaded in this conversation, and apply it throughout for evidence ranking, hypothesis testing, confidence calibration, independent review, and report validation. This skill adds the bug-family-specific commands and evidence requirements.

Scope

Driver Verifier checks kernel driver contracts. Application Verifier is a different user-mode facility; use windbg-user-heap-corruption-investigation for its heap stops. Enabled Driver Verifier flags alone do not prove a contract violation.

Use this skill when a verifier-class bugcheck or analysis identifies an actual violation. Examples include 0xC4, 0xC9, and 0xE6; inspect the exact code and parameters rather than treating every stop as the same family.

Workflow

1. Preserve code, subcode, and active configuration
text
!analyze -v
.bugcheck
!verifier
k

Record the bugcheck, subtype/subcode, offending operation and driver when reported, enabled checks, target build, and evidence availability. Decode each subcode against its documented contract. Existing output may be incomplete in a small dump; do not discard captured evidence merely because live configuration is now different.

2. Decode available I/O history

When the violation supplies an appropriate IRP address and I/O verification state is available:

text
!iovirp <irp-address>
!irp <irp-address>

Shadow state may preserve information lost from the live request. Correlate it with the decoded contract and use windbg-kernel-irp-lifecycle-triage for completion, cancellation, pending state, and ownership.

3. Recover context or follow dependencies
  • Saved exception/trap context: windbg-kernel-bugcheck-triage.
  • Lock-order evidence: windbg-kernel-lock-deadlock-triage.
  • Outstanding or power request: windbg-kernel-irp-lifecycle-triage.

Avoid cyclic dispatch. Carry the evidence already collected to the next skill; re-enter only when a distinct evidence requirement exists.

4. Investigate uncovered violations

For a generic DDI violation, identify the exact precondition (IRQL, lifetime, parameters, or ownership) and the driver call that broke it. For a DMA violation, inspect supported adapter/map/unmap and buffer-lifetime evidence for that subcode. This package does not provide a specialized decoder for every DDI or DMA case; state the gap and continue from documentation and driver source.

Show full SKILL.md (167 more words)Show less

Controlled repro

Do not enable Driver Verifier without approval. It can deliberately crash the system and expose boot-critical defects. Use a recoverable test machine, save the current configuration, select relevant vendor drivers/checks, and agree on rollback before restarting. Do not verify every installed driver by default.

Read-only configuration inspection on a test machine:

text
verifier /querysettings

verifier /reset clears settings and normally requires a restart to stop verification; it is a configuration change, not a harmless query. Restore previous intentional settings rather than unconditionally clearing them.

Validation

Name the exact violated contract, link the recorded operation to driver source, and test that the remedy satisfies it under the same checks and workload. Record dump/verification limitations and unverified assumptions. Passing a single repro is not proof that every driver path is safe.

References

Feedback

Follow FEEDBACK.md and submit reviewed, sanitized feedback to WinDbg-Feedback. Include windbg-kernel-verifier-triage and the package version from plugin.json; do not automatically upload dumps or proprietary driver source.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/windbg/skills/windbg-kernel-verifier-triage of microsoft/win-dev-skills.

Open the folder on GitHubat commit 5ce74fa

Compare with similar skills

Windbg Kernel Verifier Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windbg Kernel Verifier Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windbg Kernel Verifier Triage this skillmicrosoft/win-dev-skills462—~1.1kAutomated safety check: PassMIT
Verifyasgeirtj/system_prompts_leaks69k—~3kAutomated safety check: PassCC0-1.0
Triaging Issuespytorch/pytorch104k—~4.2kAutomated safety check: PassCustom licence
Issue Triagepaperclipai/paperclip99k—~1kAutomated safety check: PassMIT
Triagepnpm/pnpm37k—~2.9kAutomated safety check: PassMIT
Herdr Issue Triageherdrdev/herdr43k—~517Automated safety check: PassApache-2.0

Similar skills

  • Verify

    asgeirtj/system_prompts_leaks

    Verify that a code change actually does what it's supposed to by exercising it end-to-end and observing behavior — drive the affected flow, not just tests or typecheck.

    69k GitHub stars~3k tokensUpdated today
    Testing & QAAuto-check passed
  • Triaging Issues

    pytorch/pytorch

    Triages GitHub issues by routing to oncall teams, applying labels, and closing questions.

    104k GitHub stars~4.2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Issue Triage

    paperclipai/paperclip

    Triage Paperclip inbox issues that are stale, blocked, in-review, or assigned-but-not-progressing, and decide a single next action per issue (resume, reassign, unblock, escalate, or close).

    99k GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Triage

    pnpm/pnpm

    Triage an incoming GitHub issue against the pnpm codebase and related open issues, then apply exactly one implementation-readiness label using pnpm's state: taxonomy.

    37k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Herdr Issue Triage

    herdrdev/herdr

    Triages open herdr GitHub issues into a short decision-first Markdown table with a priority light, recommendation, age, reactions and a reason for each.

    43k GitHub stars~517 tokensUpdated today
    DevelopmentAuto-check passed
  • Runs issue triage and PR triage in parallel, then cross-analyzes the results to flag duplicate coverage, security gaps, P0 issues with no PR, and PR conflicts.

    83k GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check: notes

More from microsoft/win-dev-skills

All 11 skills in this repo
  • Windbg Diagnostic Method

    microsoft/win-dev-skills

    Official

    Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

    462 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Windbg Kernel Bugcheck Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

    462 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Windbg Kernel Irp Lifecycle Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

    462 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Windbg Kernel Lock Deadlock Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

    462 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Windbg User Exception Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

    462 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds.

    462 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Questions about Windbg Kernel Verifier Triage

What does Windbg Kernel Verifier Triage do?

A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state. Windbg Kernel Verifier Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

When should I use Windbg Kernel Verifier Triage?

Windbg Kernel Verifier Triage fits situations like: A kernel dump contains Driver Verifier violations; bugcheck subcodes; available I/O shadow state.

How do I install Windbg Kernel Verifier Triage in Claude Code?

Run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-verifier-triage -a claude-code`. Or copy the skill folder (plugins/windbg/skills/windbg-kernel-verifier-triage in microsoft/win-dev-skills) into .claude/skills/windbg-kernel-verifier-triage in your project. Claude Code loads it when a task matches its description.

How do I install Windbg Kernel Verifier Triage in Codex?

Run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-verifier-triage -a codex`. Or copy the skill folder (plugins/windbg/skills/windbg-kernel-verifier-triage in microsoft/win-dev-skills) into .agents/skills/windbg-kernel-verifier-triage in your project. Codex loads it when a task matches its description.

Can I use Windbg Kernel Verifier Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/win-dev-skills --skill windbg-kernel-verifier-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windbg-kernel-verifier-triage, .gemini/skills/windbg-kernel-verifier-triage, .github/skills/windbg-kernel-verifier-triage and .opencode/skills/windbg-kernel-verifier-triage in your project.

What does Windbg Kernel Verifier Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Windbg Kernel Verifier Triage is instructions for the agent only.

Does Windbg Kernel Verifier Triage access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Windbg Kernel Verifier Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windbg Kernel Verifier Triage use?

Windbg Kernel Verifier Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windbg Kernel Verifier Triage use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windbg Kernel Verifier Triage?

Skills that share tags, products or a category with Windbg Kernel Verifier Triage: Verify (asgeirtj/system_prompts_leaks, 69k stars), Triaging Issues (pytorch/pytorch, 104k stars), Issue Triage (paperclipai/paperclip, 99k stars) and Triage (pnpm/pnpm, 37k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windbg Kernel Verifier Triage?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/win-dev-skills, which has 462 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/win-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.