Official agent skill

Windbg User Heap Corruption Investigation

by microsoft in microsoft/win-dev-skills

A skill your agent uses when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds.

OfficialMITAuto-check passed

Install Windbg User Heap Corruption Investigation

skills CLI
$ npx skills add microsoft/win-dev-skills --skill windbg-user-heap-corruption-investigation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/win-dev-skills windbg-user-heap-corruption-investigation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/win-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/windbg/skills/windbg-user-heap-corruption-investigation .claude/skills/windbg-user-heap-corruption-investigation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windbg-user-heap-corruption-investigation
GitHub stars
466
Token cost
~1.3k tokens
SKILL.md length
596 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds.

  • Works in 4 steps: Decode the stop → Recover available block history → Test competing explanations → …
  • User-mode driver host heap fails
  • SKILL.md covers Detection and limits, Workflow, Fix patterns and Validation, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windbg User Heap Corruption Investigation is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds. Not for kernel pool corruption or ordinary OOM.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Agent plugins for building Windows apps with GitHub Copilot, Claude Code, OpenAI Codex, and more. The licence is MIT.

When your agent uses it

  • User-mode driver host heap fails
  • Application Verifier detects corruption
  • Inspect history and bounds

Example prompts

  • “/windbg-user-heap-corruption-investigation”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Decode the stop
  2. Recover available block history
  3. Test competing explanations
  4. Obtain stronger evidence if necessary

What it can do on your machine

Read from SKILL.md and the folder at commit 5ce74fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windbg User Heap Corruption Investigation loads about 1.3k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 596 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/win-dev-skills at commit 5ce74fa, republished under its MIT licence (© microsoft). 596 words, ~1,330 tokens.

Download SKILL.mdSave it as .claude/skills/windbg-user-heap-corruption-investigation/SKILL.md (or your agent's skills folder).
name
windbg-user-heap-corruption-investigation
description
Use when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds. Not for kernel pool corruption or ordinary OOM.

Heap Corruption Investigation

Load windbg-diagnostic-method first if it is not already loaded in this conversation, and apply it throughout for evidence ranking, hypothesis testing, confidence calibration, independent review, and report validation. This skill adds the bug-family-specific commands and evidence requirements.

Detection and limits

Look for STATUS_HEAP_CORRUPTION (0xC0000374), Application Verifier stops, or failures in heap allocate/free/reallocate paths in an application, service, or user-mode driver host such as an UMDF host process. A crash inside the allocator may be the first detection of an earlier bad write, not the faulty operation. Distinguish corruption from allocation failure; for the latter use windbg-user-virtual-memory-exhaustion.

Allocation/free history depends on how the process was instrumented and which pages were captured. A missing history is a limitation, not proof of a leak or use-after-free.

Workflow

1. Decode the stop
text
.exr -1
.ecxr
!analyze -v
k

Record the stop reason, corrupted block, corruption address, and the operation that detected the damage. If a verifier stop frame has parameter/local symbols, select it with .frame /r <frame> and inspect dv; otherwise use the captured stop output and the documented stop definition. Do not assume one fixed parameter layout or a stop code shared by all verifier versions.

2. Recover available block history
text
!heap -p -a <address>
!avrf -hp -a <address>

The first command inspects a Page Heap allocation; the second searches available Application Verifier heap-operation history. Use !heap -? and !avrf -? to confirm support in the installed extension. On an uninstrumented dump these commands may not recover the history needed to identify the writer.

Capture allocation and free stacks when present. Check the address is inside the user allocation rather than a header or neighboring block.

3. Test competing explanations
HypothesisEvidence to seek
Use-after-freeConfirmed free before a later access through a retained reference
Double-freeTwo ownership/completion paths freeing the same allocation
Overrun/underrunA write outside the allocated user bounds
Wild writeCorrupted header or payload and a writer with an invalid target
Allocation/free contract mismatchDifferent allocator/deallocator or incorrect owning heap

Inspect bytes with db <address> L<size> and disassembly around the access. Fill patterns and plausible pointers are clues, not causal proof. Correlate with source, history, or a repro and trace the ownership transition.

Show full SKILL.md (246 more words)Show less
4. Obtain stronger evidence if necessary

With user approval, enable full Page Heap for a named test executable:

text
gflags /p /enable target.exe /full

Restart that process and reproduce under the debugger. Application Verifier heap checks can also be configured for that test executable. Explain memory overhead, timing changes, and potential deliberate stops before doing this. Record the previous settings and restore them when finished; if Page Heap was newly enabled for this test, disable it with:

text
gflags /p /disable target.exe

Do not change an existing application's verification policy without approval. If a user-mode TTD trace is available, use windbg-user-ttd-reverse-debugging-triage to find the relevant mutation or free.

Fix patterns

  • Enforce the actual lifetime contract with ownership types or explicit acquire/release rules. Shared ownership is appropriate only when the design genuinely has multiple owners.
  • Synchronize shared state separately: shared_ptr ownership does not make a concurrently modified cache or pointed-to object thread-safe.
  • Size buffers and check arithmetic, lengths, and terminators; use bounds-aware containers where appropriate.
  • Keep allocation and deallocation compatible across DLL/API boundaries.

Validation

Establish the affected block and supported corruption class, name the path that violated bounds or ownership, and distinguish the detector from the writer. Exercise the fix with the same instrumentation and relevant concurrency/load. Report unresolved writer history rather than presenting a guessed fix as proven.

References

Feedback

Follow FEEDBACK.md and report reviewed, sanitized feedback to WinDbg-Feedback. Include windbg-user-heap-corruption-investigation and the package version from plugin.json; no automatic dump, source, or transcript upload.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/windbg/skills/windbg-user-heap-corruption-investigation of microsoft/win-dev-skills.

Open the folder on GitHubat commit 5ce74fa

Compare with similar skills

Windbg User Heap Corruption Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windbg User Heap Corruption Investigation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windbg User Heap Corruption Investigation this skillmicrosoft/win-dev-skills466—~1.3kAutomated safety check: PassMIT
Openclaw Test Heap Leaksopenclaw/openclaw392k—~1.9kAutomated safety check: PassMIT
Root Cause Investigationgarrytan/gstack136k—~13kAutomated safety check: NotesMIT
Osint Investigationaffaan-m/ECC276k—~5.7kAutomated safety check: PassCC-BY-SA-4.0
Driver Incident Investigationmohitagw15856/pm-claude-skills1.4k—~1.7kAutomated safety check: PassMIT
Investigate CIClickHouse/ClickHouse50k—~11kAutomated safety check: NotesApache-2.0

Similar skills

  • Openclaw Test Heap Leaks

    openclaw/openclaw

    Investigate OpenClaw pnpm test memory growth, Vitest OOMs, RSS spikes, and heap snapshot deltas.

    392k GitHub stars~1.9k tokensUpdated today
    Testing & QAAuto-check passed
  • Debugs in four phases (investigate, analyze, hypothesize, implement) under one rule: no fix is made until the root cause is found.

    136k GitHub stars~13k tokensUpdated today
    DevelopmentAuto-check: notes
  • Sparse-clue OSINT investigation methodology for extracting overlooked leads, connecting fragmented evidence, and testing explanations across sources.

    276k GitHub stars~5.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Driver Incident Investigation

    mohitagw15856/pm-claude-skills

    Investigate a commercial vehicle incident so the record is defensible and the cause is actually found — evidence secured in the first hours, the preventability decision made on stated criteria, and…

    1.4k GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Investigate CI

    ClickHouse/ClickHouse

    Investigate a ClickHouse CI failure end-to-end from a PR or S3 report URL.

    50k GitHub stars~11k tokensUpdated today
    DatabasesAuto-check: notes
  • Investigate Issue

    videojs/video.js

    Investigate GitHub issues without changing code. An agent skill from videojs/video.js.

    40k GitHub stars~318 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from microsoft/win-dev-skills

All 11 skills in this repo
  • Windbg Diagnostic Method

    microsoft/win-dev-skills

    Official

    Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

    466 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Windbg Kernel Bugcheck Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

    466 GitHub stars~1.3k tokensUpdated 3 days ago
    Auto-check passed
  • Windbg Kernel Irp Lifecycle Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

    466 GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed
  • Windbg Kernel Lock Deadlock Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

    466 GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed
  • Windbg Kernel Verifier Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

    466 GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed
  • Windbg User Exception Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

    466 GitHub stars~1.3k tokensUpdated 3 days ago
    Auto-check passed

Questions about Windbg User Heap Corruption Investigation

What does Windbg User Heap Corruption Investigation do?

A skill your agent uses when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds. Windbg User Heap Corruption Investigation is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds.

When should I use Windbg User Heap Corruption Investigation?

Windbg User Heap Corruption Investigation fits situations like: user-mode driver host heap fails; application Verifier detects corruption; inspect history and bounds.

How do I install Windbg User Heap Corruption Investigation in Claude Code?

Run `npx skills add microsoft/win-dev-skills --skill windbg-user-heap-corruption-investigation -a claude-code`. Or copy the skill folder (plugins/windbg/skills/windbg-user-heap-corruption-investigation in microsoft/win-dev-skills) into .claude/skills/windbg-user-heap-corruption-investigation in your project. Claude Code loads it when a task matches its description.

How do I install Windbg User Heap Corruption Investigation in Codex?

Run `npx skills add microsoft/win-dev-skills --skill windbg-user-heap-corruption-investigation -a codex`. Or copy the skill folder (plugins/windbg/skills/windbg-user-heap-corruption-investigation in microsoft/win-dev-skills) into .agents/skills/windbg-user-heap-corruption-investigation in your project. Codex loads it when a task matches its description.

Can I use Windbg User Heap Corruption Investigation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/win-dev-skills --skill windbg-user-heap-corruption-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windbg-user-heap-corruption-investigation, .gemini/skills/windbg-user-heap-corruption-investigation, .github/skills/windbg-user-heap-corruption-investigation and .opencode/skills/windbg-user-heap-corruption-investigation in your project.

What does Windbg User Heap Corruption Investigation need to run?

SKILL.md names no scripts, command-line tools or credentials: Windbg User Heap Corruption Investigation is instructions for the agent only.

Does Windbg User Heap Corruption Investigation access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Windbg User Heap Corruption Investigation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windbg User Heap Corruption Investigation use?

Windbg User Heap Corruption Investigation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windbg User Heap Corruption Investigation use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windbg User Heap Corruption Investigation?

Skills that share tags, products or a category with Windbg User Heap Corruption Investigation: Openclaw Test Heap Leaks (openclaw/openclaw, 392k stars), Root Cause Investigation (garrytan/gstack, 136k stars), Osint Investigation (affaan-m/ECC, 276k stars) and Driver Incident Investigation (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windbg User Heap Corruption Investigation?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/win-dev-skills, which has 466 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/win-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.