Official agent skill

Windbg User Exception Triage

by microsoft in microsoft/win-dev-skills

A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

OfficialMITAuto-check passed

Install Windbg User Exception Triage

skills CLI
$ npx skills add microsoft/win-dev-skills --skill windbg-user-exception-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/win-dev-skills windbg-user-exception-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/win-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/windbg/skills/windbg-user-exception-triage .claude/skills/windbg-user-exception-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windbg-user-exception-triage
GitHub stars
465
Token cost
~1.3k tokens
SKILL.md length
534 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

  • Works in 3 steps: Establish the exception context → Classify and choose an available… → Investigate families without a dedicated…
  • A native C/C++ app
  • SKILL.md covers When to use, Workflow, Validation and References, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windbg User Exception Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside managed processes. Not for managed .NET exceptions, WinUI/XAML app errors, or kernel bugchecks.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Windows, C++ and .NET. The repository describes itself as: Agent plugins for building Windows apps with GitHub Copilot, Claude Code, OpenAI Codex, and more. The licence is MIT.

When your agent uses it

  • A native C/C++ app
  • User-mode driver host (including UMDF) crashes with a structured exception in a dump
  • Including native faults inside managed processes

Example prompts

  • “/windbg-user-exception-triage”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Establish the exception context
  2. Classify and choose an available investigation
  3. Investigate families without a dedicated skill

What it can do on your machine

Read from SKILL.md and the folder at commit 5ce74fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windbg User Exception Triage loads about 1.3k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 534 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/win-dev-skills at commit 5ce74fa, republished under its MIT licence (© microsoft). 534 words, ~1,283 tokens.

Download SKILL.mdSave it as .claude/skills/windbg-user-exception-triage/SKILL.md (or your agent's skills folder).
name
windbg-user-exception-triage
description
Use when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside managed processes. Not for managed .NET exceptions, WinUI/XAML app errors, or kernel bugchecks.

User-Mode Exception Triage

Load windbg-diagnostic-method first if it is not already loaded in this conversation, and apply it throughout for evidence ranking, hypothesis testing, confidence calibration, independent review, and report validation. This skill adds the bug-family-specific commands and evidence requirements.

When to use

Start here for access violations, heap corruption, stack overflow, fail-fast, breakpoints, and other structured exceptions in a native application, service, or user-mode driver host process dump. This includes UMDF driver failures that occur in their user-mode host. Confirm the dump type from WinDbg; the filename extension alone does not distinguish user-mode from kernel-mode dumps.

Workflow

1. Establish the exception context
text
.exr -1
.ecxr
k
!analyze -v

Record the exception code, address, parameters, access type, registers, module, and stack. .ecxr selects the saved exception context when available. If no exception context was captured, report that limitation rather than treating the currently selected thread as the faulting thread.

Use matching binaries and PDBs for your modules and public Windows symbols. Investigate mismatches or truncated stacks before naming a failing source line.

2. Classify and choose an available investigation
EvidenceNext step
0xC0000005 with allocation/free or overrun evidencewindbg-user-heap-corruption-investigation
0xC0000374 heap corruptionwindbg-user-heap-corruption-investigation
0xC0000017, 0x8007000E, or an allocation-failure pathwindbg-user-virtual-memory-exhaustion
Lock/unlock failure following coroutine suspensionwindbg-user-mutex-held-across-co-await
A TTD recording is available and earlier mutation is in questionwindbg-user-ttd-reverse-debugging-triage
No crash exception and evidence of blocked workwindbg-user-wait-chain-analysis
A kernel dump reports a bugcheckwindbg-kernel-bugcheck-triage

Do not classify every address in a heap range as a lifetime bug. Check access type, faulting instruction, object layout, and valid allocation boundaries.

Show full SKILL.md (282 more words)Show less
3. Investigate families without a dedicated skill
  • Access violation without a match: identify the read/write/execute target, object/register used, and whether bounds, ownership, or synchronization was violated. Distinguish a null pointer from stale or corrupted state.
  • 0xC0000409 / fail-fast: inspect exception parameters and the documented fast-fail subcode, then the failing condition and call path. The historical status name alone does not prove a buffer overrun or rule one out. Not every fast-fail carries an HRESULT.
  • 0xC00000FD / stack overflow: inspect stack bounds and frame sizes; test recursion, reentrancy, large frames, and inability to commit stack growth. Use the memory-exhaustion skill when commit evidence supports that branch.
  • 0xE06D7363 / MSVC C++ exception: establish whether it was handled, identify the throw/catch path with available symbols, and inspect the exception information supported by the runtime/version. A first-chance throw is not automatically a defect. This package does not decode thrown-object layouts or fully diagnose noexcept/termination behavior.
  • Stowed/WinRT exceptions: preserved error information can precede the final failure. Correlate its originating stack and nested errors with the application; this package does not include a XAML extension workflow.
  • Illegal instruction or breakpoint: distinguish CPU/architecture or code-corruption hypotheses from intentional assertions/debug breaks.

Validation

  • Exception context and code are established, or their absence is stated.
  • Faulting instruction and relevant object/register agree with the hypothesis.
  • Alternatives are tested against evidence, not just stack names.
  • Missing memory, symbols, and specialized exception coverage are explicit.
  • The proposed fix addresses a demonstrated invariant and has a repro/test plan.

References

Feedback

For this skill, follow the plugin's FEEDBACK.md and report a reviewed, sanitized issue to WinDbg-Feedback. Include windbg-user-exception-triage and the package version from plugin.json; do not upload dumps or private source automatically.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/windbg/skills/windbg-user-exception-triage of microsoft/win-dev-skills.

Open the folder on GitHubat commit 5ce74fa

Compare with similar skills

Windbg User Exception Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windbg User Exception Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windbg User Exception Triage this skillmicrosoft/win-dev-skills465—~1.3kAutomated safety check: PassMIT
Bump LibdatadogDataDog/dd-trace-dotnet573—~1.7kAutomated safety check: PassApache-2.0
Build Fluentqt Guicalvinhxx/Fluent-Qt157—~1.6kAutomated safety check: PassMIT
Directxmesh Usagemicrosoft/DirectXMesh859—~1.2kAutomated safety check: PassMIT
Msbuild Antipatternsrunceel/ReactiveProperty944—~3.7kAutomated safety check: PassMIT
Sokol Netelix22/Sokol.NET154—~2.8kAutomated safety check: PassMIT

Similar skills

  • Bump Libdatadog

    DataDog/dd-trace-dotnet

    Official

    Update/bump the libdatadog native library version in dd-trace-dotnet.

    573 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Build Fluentqt Gui

    calvinhxx/Fluent-Qt

    Create, integrate, redesign, or fix C++ and PySide6 GUIs using FluentQt, including component and Gallery work.

    157 GitHub stars~1.6k tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Directxmesh Usage

    microsoft/DirectXMesh

    Official

    Guide for integrating the DirectXMesh geometry processing library into a C++ project.

    859 GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Msbuild Antipatterns

    runceel/ReactiveProperty

    Catalog of MSBuild anti-patterns with detection rules and fix recipes.

    944 GitHub stars~3.7k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Sokol Net

    elix22/Sokol.NET

    Sokol.NET framework development — use for ANY work in this repo: creating or debugging examples, building/running for desktop/Android/iOS/Web, writing or compiling shaders, adding a new C/C++…

    154 GitHub stars~2.8k tokensUpdated today
    Game DevelopmentAuto-check passed
  • Msbuild Modernization

    microsoft/testfx

    Official

    Guide for modernizing and migrating MSBuild project files to SDK-style format.

    1k GitHub starsUsed in 3 repos~4.3k tokens
    DevelopmentAuto-check passed

More from microsoft/win-dev-skills

All 11 skills in this repo
  • Windbg Diagnostic Method

    microsoft/win-dev-skills

    Official

    Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

    465 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Bugcheck Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

    465 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Irp Lifecycle Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

    465 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Lock Deadlock Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

    465 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Verifier Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

    465 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Official

    A skill your agent uses when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds.

    465 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Windbg User Exception Triage

What does Windbg User Exception Triage do?

A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…. Windbg User Exception Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside managed processes.

When should I use Windbg User Exception Triage?

Windbg User Exception Triage fits situations like: A native C/C++ app; user-mode driver host (including UMDF) crashes with a structured exception in a dump; including native faults inside managed processes.

How do I install Windbg User Exception Triage in Claude Code?

Run `npx skills add microsoft/win-dev-skills --skill windbg-user-exception-triage -a claude-code`. Or copy the skill folder (plugins/windbg/skills/windbg-user-exception-triage in microsoft/win-dev-skills) into .claude/skills/windbg-user-exception-triage in your project. Claude Code loads it when a task matches its description.

How do I install Windbg User Exception Triage in Codex?

Run `npx skills add microsoft/win-dev-skills --skill windbg-user-exception-triage -a codex`. Or copy the skill folder (plugins/windbg/skills/windbg-user-exception-triage in microsoft/win-dev-skills) into .agents/skills/windbg-user-exception-triage in your project. Codex loads it when a task matches its description.

Can I use Windbg User Exception Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/win-dev-skills --skill windbg-user-exception-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windbg-user-exception-triage, .gemini/skills/windbg-user-exception-triage, .github/skills/windbg-user-exception-triage and .opencode/skills/windbg-user-exception-triage in your project.

What does Windbg User Exception Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Windbg User Exception Triage is instructions for the agent only.

Does Windbg User Exception Triage access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Windbg User Exception Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windbg User Exception Triage use?

Windbg User Exception Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windbg User Exception Triage use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windbg User Exception Triage?

Skills that share tags, products or a category with Windbg User Exception Triage: Bump Libdatadog (DataDog/dd-trace-dotnet, 573 stars), Build Fluentqt Gui (calvinhxx/Fluent-Qt, 157 stars), Directxmesh Usage (microsoft/DirectXMesh, 859 stars) and Msbuild Antipatterns (runceel/ReactiveProperty, 944 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windbg User Exception Triage?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/win-dev-skills, which has 465 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/win-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.