Official agent skill

Windbg User Ttd Reverse Debugging Triage

by microsoft in microsoft/win-dev-skills

A skill your agent uses when an app, service, or user-mode driver host TTD recording is available and earlier calls, writes, or lifetimes matter.

OfficialMITAuto-check passedDevelopment

Install Windbg User Ttd Reverse Debugging Triage

skills CLI
$ npx skills add microsoft/win-dev-skills --skill windbg-user-ttd-reverse-debugging-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/win-dev-skills windbg-user-ttd-reverse-debugging-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/win-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/windbg/skills/windbg-user-ttd-reverse-debugging-triage .claude/skills/windbg-user-ttd-reverse-debugging-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windbg-user-ttd-reverse-debugging-triage
GitHub stars
462
Token cost
~1.1k tokens
SKILL.md length
458 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when an app, service, or user-mode driver host TTD recording is available and earlier calls, writes, or lifetimes matter.

  • Works in 4 steps: Open and index the recording → Ask a bounded history question → Seek and inspect state → …
  • User-mode driver host TTD recording is available and earlier calls
  • SKILL.md covers Requirements and scope, Workflow, Validation and References, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windbg User Ttd Reverse Debugging Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when an app, service, or user-mode driver host TTD recording is available and earlier calls, writes, or lifetimes matter. Not for kernel replay or history from a normal dump.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Debugging. The repository describes itself as: Agent plugins for building Windows apps with GitHub Copilot, Claude Code, OpenAI Codex, and more. The licence is MIT.

When your agent uses it

  • User-mode driver host TTD recording is available and earlier calls
  • Lifetimes matter

Example prompts

  • “/windbg-user-ttd-reverse-debugging-triage”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Open and index the recording
  2. Ask a bounded history question
  3. Seek and inspect state
  4. Continue with a shipped investigation

What it can do on your machine

Read from SKILL.md and the folder at commit 5ce74fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windbg User Ttd Reverse Debugging Triage loads about 1.1k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 458 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/win-dev-skills at commit 5ce74fa, republished under its MIT licence (© microsoft). 458 words, ~1,118 tokens.

Download SKILL.mdSave it as .claude/skills/windbg-user-ttd-reverse-debugging-triage/SKILL.md (or your agent's skills folder).
name
windbg-user-ttd-reverse-debugging-triage
description
Use when an app, service, or user-mode driver host TTD recording is available and earlier calls, writes, or lifetimes matter. Not for kernel replay or history from a normal dump.

TTD Reverse Debugging Triage

Load windbg-diagnostic-method first if it is not already loaded in this conversation, and apply it throughout for evidence ranking, hypothesis testing, confidence calibration, independent review, and report validation. This skill adds the bug-family-specific commands and evidence requirements.

Requirements and scope

Time Travel Debugging records a user-mode process for replay, including an authorized application, service, or user-mode driver host process. A dump alone contains no execution timeline. Confirm a valid recording and matching module symbols before attempting timeline queries. It does not record kernel execution or automatically include another process's server-side activity.

Recording can change timing, require substantial storage, and capture sensitive memory. Obtain authorization before capture. Check the installed recorder's help for supported target, architecture, and options. WinDbg's Launch executable (advanced) / Record with Time Travel Debugging flow can record a named test application without guessing a recorder command.

Workflow

1. Open and index the recording

Open the recorded .run file in WinDbg and load public Windows symbols and matching PDBs for your own binaries.

text
!tt.index
dx @$cursession.TTD

Confirm the timeline range. Indexing and data-model availability depend on WinDbg/TTD versions; consult the installed help if the command is unavailable.

2. Ask a bounded history question
text
dx @$cursession.TTD.Calls("MyModule!MyFunction")
dx @$cursession.TTD.Memory(<start-address>, <end-address>, "w")

Query the known function or exact memory range, then inspect relevant results and their timeline positions. An empty result can mean unmatched symbols, uninstrumented execution, or an out-of-range query, not proof of absence.

Use the call query to find allocation/free or module lifetime transitions and the memory query to locate candidate writes. Account for allocator reuse: the same virtual address may represent different objects over the recording.

Show full SKILL.md (196 more words)Show less
3. Seek and inspect state
text
!tt <position>
k
r
g-

Seek to an actual position returned by the query. g- continues backward; use the installed reverse-step controls to refine the search. Capture the last-good and first-bad states, writer/caller stack, and ownership transition.

Do not equate the last write with the bug until you establish the object's identity, valid lifetime, intended invariant, and relevant cross-thread order.

4. Continue with a shipped investigation
EvidenceSkill
Bad free/write or allocation-boundary violationwindbg-user-heap-corruption-investigation
Growing allocation/reservation usagewindbg-user-virtual-memory-exhaustion
Lock survives coroutine suspensionwindbg-user-mutex-held-across-co-await
Blocker or cross-process dependency at the selected momentwindbg-user-wait-chain-analysis

For other user-mode families continue reasoning from the timeline rather than dispatching to absent skills. For a kernel crash use windbg-kernel-bugcheck-triage; TTD is not a kernel-history substitute.

Validation

Record the question, trace identity, timeline positions, relevant object lifetime, and source/stack evidence. Test alternatives and state recording boundaries. A reproducible timeline proves what occurred in that recording; it does not establish that instrumentation preserved all production timing.

References

Feedback

Follow FEEDBACK.md and report a reviewed summary to WinDbg-Feedback. Include windbg-user-ttd-reverse-debugging-triage and the package version from plugin.json; never automatically upload a recording or its memory/query contents.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/windbg/skills/windbg-user-ttd-reverse-debugging-triage of microsoft/win-dev-skills.

Open the folder on GitHubat commit 5ce74fa

Compare with similar skills

Windbg User Ttd Reverse Debugging Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windbg User Ttd Reverse Debugging Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windbg User Ttd Reverse Debugging Triage this skillmicrosoft/win-dev-skills462—~1.1kAutomated safety check: PassMIT
Trellis Session Insightmindfold-ai/Trellis15k4 repos~1.7kAutomated safety check: PassAGPL-3.0
Native Data FetchingCherryHQ/cherry-studio-app4k6 repos~2.9kAutomated safety check: NotesMIT
Debugging Executionsn8n-io/n8n207k—~2.6kAutomated safety check: PassCustom licence
Aoti Debugpytorch/pytorch104k1 repos~1.7kAutomated safety check: PassCustom licence
Herdr Throwaway Reproductionherdrdev/herdr43k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Trellis Session Insight

    mindfold-ai/Trellis

    Reach into past AI conversation history through the trellis mem CLI.

    15k GitHub starsUsed in 4 repos~1.7k tokens
    DevelopmentAuto-check passed
  • Native Data Fetching

    CherryHQ/cherry-studio-app

    A skill your agent uses when implementing or debugging ANY network request, API call, or data fetching.

    4k GitHub starsUsed in 6 repos~2.9k tokens
    DevelopmentAuto-check: notes
  • Official

    Debug failed or wrong-output workflow executions using executions tools.

    207k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Aoti Debug

    pytorch/pytorch

    Debug AOTInductor (AOTI) errors and crashes. An agent skill from pytorch/pytorch.

    104k GitHub starsUsed in 1 repo~1.7k tokens
    DevelopmentAuto-check passed
  • Runs a disposable, uniquely named Herdr session inside an existing one so runtime, pane, terminal or API bugs can be reproduced without touching the main session.

    43k GitHub stars~2.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Systematic Debugging

    ultralisp/ultralisp

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior, before proposing fixes

    258 GitHub starsUsed in 51 repos~2.4k tokens
    DevelopmentAuto-check passed

More from microsoft/win-dev-skills

All 11 skills in this repo
  • Windbg Diagnostic Method

    microsoft/win-dev-skills

    Official

    Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

    462 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Bugcheck Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Irp Lifecycle Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Lock Deadlock Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Verifier Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

    462 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg User Exception Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

    462 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Windbg User Ttd Reverse Debugging Triage

What does Windbg User Ttd Reverse Debugging Triage do?

A skill your agent uses when an app, service, or user-mode driver host TTD recording is available and earlier calls, writes, or lifetimes matter. Windbg User Ttd Reverse Debugging Triage is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when an app, service, or user-mode driver host TTD recording is available and earlier calls, writes, or lifetimes matter.

When should I use Windbg User Ttd Reverse Debugging Triage?

Windbg User Ttd Reverse Debugging Triage fits situations like: user-mode driver host TTD recording is available and earlier calls; lifetimes matter.

How do I install Windbg User Ttd Reverse Debugging Triage in Claude Code?

Run `npx skills add microsoft/win-dev-skills --skill windbg-user-ttd-reverse-debugging-triage -a claude-code`. Or copy the skill folder (plugins/windbg/skills/windbg-user-ttd-reverse-debugging-triage in microsoft/win-dev-skills) into .claude/skills/windbg-user-ttd-reverse-debugging-triage in your project. Claude Code loads it when a task matches its description.

How do I install Windbg User Ttd Reverse Debugging Triage in Codex?

Run `npx skills add microsoft/win-dev-skills --skill windbg-user-ttd-reverse-debugging-triage -a codex`. Or copy the skill folder (plugins/windbg/skills/windbg-user-ttd-reverse-debugging-triage in microsoft/win-dev-skills) into .agents/skills/windbg-user-ttd-reverse-debugging-triage in your project. Codex loads it when a task matches its description.

Can I use Windbg User Ttd Reverse Debugging Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/win-dev-skills --skill windbg-user-ttd-reverse-debugging-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windbg-user-ttd-reverse-debugging-triage, .gemini/skills/windbg-user-ttd-reverse-debugging-triage, .github/skills/windbg-user-ttd-reverse-debugging-triage and .opencode/skills/windbg-user-ttd-reverse-debugging-triage in your project.

What does Windbg User Ttd Reverse Debugging Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Windbg User Ttd Reverse Debugging Triage is instructions for the agent only.

Does Windbg User Ttd Reverse Debugging Triage access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Windbg User Ttd Reverse Debugging Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windbg User Ttd Reverse Debugging Triage use?

Windbg User Ttd Reverse Debugging Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windbg User Ttd Reverse Debugging Triage use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windbg User Ttd Reverse Debugging Triage?

Skills that share tags, products or a category with Windbg User Ttd Reverse Debugging Triage: Trellis Session Insight (mindfold-ai/Trellis, 15k stars), Native Data Fetching (CherryHQ/cherry-studio-app, 4k stars), Debugging Executions (n8n-io/n8n, 207k stars) and Aoti Debug (pytorch/pytorch, 104k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windbg User Ttd Reverse Debugging Triage?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/win-dev-skills, which has 462 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/win-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.