Official agent skill

Windbg User Wait Chain Analysis

by microsoft in microsoft/win-dev-skills

A skill your agent uses when an app, service, or user-mode driver host is unresponsive on locks, COM/RPC, I/O, or another process; follow the blocker chain.

OfficialMITAuto-check passed

Install Windbg User Wait Chain Analysis

skills CLI
$ npx skills add microsoft/win-dev-skills --skill windbg-user-wait-chain-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/win-dev-skills windbg-user-wait-chain-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/win-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/windbg/skills/windbg-user-wait-chain-analysis .claude/skills/windbg-user-wait-chain-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windbg-user-wait-chain-analysis
GitHub stars
465
Token cost
~1.2k tokens
SKILL.md length
584 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when an app, service, or user-mode driver host is unresponsive on locks, COM/RPC, I/O, or another process; follow the blocker chain.

  • Works in 4 steps: Identify the affected operation and its… → Identify each wait and its owner → Gather corresponding server evidence → …
  • User-mode driver host is unresponsive on locks
  • SKILL.md covers Detection, Workflow, Fix patterns and COM boundaries and Validation, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windbg User Wait Chain Analysis is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when an app, service, or user-mode driver host is unresponsive on locks, COM/RPC, I/O, or another process; follow the blocker chain. Not for a crash solely from an exception stack.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Agent plugins for building Windows apps with GitHub Copilot, Claude Code, OpenAI Codex, and more. The licence is MIT.

When your agent uses it

  • User-mode driver host is unresponsive on locks
  • Another process
  • Follow the blocker chain

Example prompts

  • “/windbg-user-wait-chain-analysis”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify the affected operation and its thread
  2. Identify each wait and its owner
  3. Gather corresponding server evidence
  4. Distinguish a cycle from a slow or missing responder

What it can do on your machine

Read from SKILL.md and the folder at commit 5ce74fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windbg User Wait Chain Analysis loads about 1.2k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 584 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/win-dev-skills at commit 5ce74fa, republished under its MIT licence (© microsoft). 584 words, ~1,244 tokens.

Download SKILL.mdSave it as .claude/skills/windbg-user-wait-chain-analysis/SKILL.md (or your agent's skills folder).
name
windbg-user-wait-chain-analysis
description
Use when an app, service, or user-mode driver host is unresponsive on locks, COM/RPC, I/O, or another process; follow the blocker chain. Not for a crash solely from an exception stack.

Cross-Process Wait Chain Analysis

Load windbg-diagnostic-method first if it is not already loaded in this conversation, and apply it throughout for evidence ranking, hypothesis testing, confidence calibration, independent review, and report validation. This skill adds the bug-family-specific commands and evidence requirements.

Detection

Look for blocked work in an application, service, or user-mode driver host (including UMDF), and threads in wait, COM, RPC, or I/O paths. The process displaying the symptom may not own the underlying defect. Idle worker threads waiting normally are not evidence of a hang.

Workflow

1. Identify the affected operation and its thread
text
.lastevent
~*kb
!runaway

Confirm why the dump was collected. A dump is a snapshot; .lastevent does not by itself certify "hang" or "no crash." Identify the UI/serving thread from application evidence instead of assuming thread zero is always the UI thread. If work is spinning rather than blocked, collect appropriate CPU evidence.

2. Identify each wait and its owner

Inspect frames around WaitForSingleObject, WaitForMultipleObjects, COM send/receive, and RPC calls. Use matching symbols/source for your own proxy, interface, and server registration to determine what was requested.

For each edge record:

text
process / thread -> waited resource or request -> owner / serving thread

Do not guess a server PID from undocumented private COM layouts. Use available Wait Chain Traversal, RPC/COM tracing, application correlation IDs, or registration/process information, and explicitly mark unresolved edges.

3. Gather corresponding server evidence

Obtain authorized dumps or live state of the relevant server processes close enough in time to represent the same operation. Inspect their serving threads. For kernel context use documented commands such as:

text
!process 0 7
!thread <ethread>

Available user pages and symbol/context support vary by dump type. If the chain ends in a kernel lock use windbg-kernel-lock-deadlock-triage; if blocked I/O is supported by IRP evidence use windbg-kernel-irp-lifecycle-triage. Do not promise process heaps or user stacks absent from the dump.

4. Distinguish a cycle from a slow or missing responder
  • Cycle: show every required wait/owner edge back to the starting actor.
  • Contention: a runnable owner may eventually release the resource.
  • Starvation: queued work cannot obtain execution capacity.
  • Lost completion: the actor/event expected to unblock the waiter no longer exists or no path signals it.
  • Slow server: the endpoint is doing work, blocked on another dependency, or looping; gather its evidence before blaming the client.

Multiple snapshots or tracing may be needed to distinguish transient waits from persistent blocking.

Show full SKILL.md (206 more words)Show less

Fix patterns and COM boundaries

A synchronous COM call from an STA can pump messages and permit reentrancy. It is not automatically a deadlock. Investigate locks held across calls, callbacks, apartment access, and any non-pumping waits that form an actual dependency cycle.

Possible remedies include asynchronous APIs, shorter lock scopes, moving destruction/cross-process calls outside critical sections, and bounded wait/cancellation protocols where the API supports them. A timeout on the caller does not cancel server work by itself.

If work moves to another apartment, marshal apartment-bound interfaces, keep captured state alive, and dispatch UI updates to the correct thread. Merely capturing a COM pointer and this in a worker lambda is not a safe fix.

Validation

Identify the affected thread, relevant resources and owners, and demonstrated cycle or deepest supported blocker. Test the proposed remedy under concurrency, reentrancy, shutdown, and timeout/cancellation. Do not stop at "waiting in RPC." If the server dump or an owner edge is missing, state the unresolved hypothesis.

References

Feedback

Follow FEEDBACK.md and submit only reviewed, sanitized feedback to WinDbg-Feedback. Include windbg-user-wait-chain-analysis and the package version from plugin.json; no automatic capture or public upload of process dumps or full diagnostic transcripts.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/windbg/skills/windbg-user-wait-chain-analysis of microsoft/win-dev-skills.

Open the folder on GitHubat commit 5ce74fa

Compare with similar skills

Windbg User Wait Chain Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windbg User Wait Chain Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windbg User Wait Chain Analysis this skillmicrosoft/win-dev-skills465—~1.2kAutomated safety check: PassMIT
Sbom Supply Chainsickn33/agentic-awesome-skills47k2 repos~3.4kAutomated safety check: PassMIT
Agent Supply Chaingithub/awesome-copilot40k1 repos~2.7kAutomated safety check: PassMIT
Supply Chain Securityzhaoxuya520/reverse-skill40k4 repos~953Automated safety check: WarnMIT
Canonical Chainthedaviddias/Front-End-Checklist74k—~417Automated safety check: PassMIT
Implementing Supply Chain Security With In Totomukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Sbom Supply Chain

    sickn33/agentic-awesome-skills

    Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain.

    47k GitHub starsUsed in 2 repos~3.4k tokens
    SecurityAuto-check passed
  • Agent Supply Chain

    github/awesome-copilot

    Official

    Verify supply chain integrity for AI agent plugins, tools, and dependencies.

    40k GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Supply Chain Security

    zhaoxuya520/reverse-skill

    A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

    40k GitHub starsUsed in 4 repos~953 tokens
    SecurityAuto-check: warnings
  • Canonical Chain

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing metadata, crawlability, structured data, or indexability related to Avoid redirect chains on canonical URLs.

    74k GitHub stars~417 tokensUpdated 3 days ago
    Marketing & SEOAuto-check passed
  • Implementing Supply Chain Security With In Toto

    mukul975/Anthropic-Cybersecurity-Skills

    Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Supply Chain Guard

    davila7/claude-code-templates

    Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

    32k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from microsoft/win-dev-skills

All 11 skills in this repo
  • Windbg Diagnostic Method

    microsoft/win-dev-skills

    Official

    Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation.

    465 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Bugcheck Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver.

    465 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Irp Lifecycle Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership.

    465 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Lock Deadlock Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph.

    465 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg Kernel Verifier Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state.

    465 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Windbg User Exception Triage

    microsoft/win-dev-skills

    Official

    A skill your agent uses when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside…

    465 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Questions about Windbg User Wait Chain Analysis

What does Windbg User Wait Chain Analysis do?

A skill your agent uses when an app, service, or user-mode driver host is unresponsive on locks, COM/RPC, I/O, or another process; follow the blocker chain. Windbg User Wait Chain Analysis is an agent skill from microsoft/win-dev-skills, published by the product's own GitHub organization. Use when an app, service, or user-mode driver host is unresponsive on locks, COM/RPC, I/O, or another process; follow the blocker chain.

When should I use Windbg User Wait Chain Analysis?

Windbg User Wait Chain Analysis fits situations like: user-mode driver host is unresponsive on locks; another process; follow the blocker chain.

How do I install Windbg User Wait Chain Analysis in Claude Code?

Run `npx skills add microsoft/win-dev-skills --skill windbg-user-wait-chain-analysis -a claude-code`. Or copy the skill folder (plugins/windbg/skills/windbg-user-wait-chain-analysis in microsoft/win-dev-skills) into .claude/skills/windbg-user-wait-chain-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Windbg User Wait Chain Analysis in Codex?

Run `npx skills add microsoft/win-dev-skills --skill windbg-user-wait-chain-analysis -a codex`. Or copy the skill folder (plugins/windbg/skills/windbg-user-wait-chain-analysis in microsoft/win-dev-skills) into .agents/skills/windbg-user-wait-chain-analysis in your project. Codex loads it when a task matches its description.

Can I use Windbg User Wait Chain Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/win-dev-skills --skill windbg-user-wait-chain-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windbg-user-wait-chain-analysis, .gemini/skills/windbg-user-wait-chain-analysis, .github/skills/windbg-user-wait-chain-analysis and .opencode/skills/windbg-user-wait-chain-analysis in your project.

What does Windbg User Wait Chain Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Windbg User Wait Chain Analysis is instructions for the agent only.

Does Windbg User Wait Chain Analysis access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Windbg User Wait Chain Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windbg User Wait Chain Analysis use?

Windbg User Wait Chain Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windbg User Wait Chain Analysis use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windbg User Wait Chain Analysis?

Skills that share tags, products or a category with Windbg User Wait Chain Analysis: Sbom Supply Chain (sickn33/agentic-awesome-skills, 47k stars), Agent Supply Chain (github/awesome-copilot, 40k stars), Supply Chain Security (zhaoxuya520/reverse-skill, 40k stars) and Canonical Chain (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windbg User Wait Chain Analysis?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/win-dev-skills, which has 465 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/win-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.