Agent skill

Kernel Debugging

by mohitmishra786 in mohitmishra786/low-level-dev-skills

Linux kernel debugging skill for kgdb, kdb, ftrace, kprobes, and crash analysis.

MITAuto-check: notesDevelopment

Install Kernel Debugging

skills CLI
$ npx skills add mohitmishra786/low-level-dev-skills --skill kernel-debugging -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitmishra786/low-level-dev-skills kernel-debugging --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kernel/kernel-debugging .claude/skills/kernel-debugging && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kernel-debugging
GitHub stars
253
Token cost
~1.6k tokens
SKILL.md length
275 words
Files
1
Skills in repo
138
Repo updated
First seen
Licence
MIT

At a glance

Linux kernel debugging skill for kgdb, kdb, ftrace, kprobes, and crash analysis.

  • Works in 9 steps: dmesg and log levels → kgdb over serial → kdb commands → …
  • Setting up kgdb over serial
  • SKILL.md covers Purpose, When to Use, Workflow and Common Problems, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Kernel Debugging is an agent skill from mohitmishra786/low-level-dev-skills. Linux kernel debugging skill for kgdb, kdb, ftrace, kprobes, and crash analysis. Use when setting up kgdb over serial, using ftrace and trace-cmd, inserting kprobes, enabling dynamic debug, or analyzing kdump with crash. Activates on queries about kgdb, kdb, ftrace, kprobes, dyndbg, kdump, or kernel dmesg levels.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Debugging and Mobile performance. It works with Linux. The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.

When your agent uses it

  • Setting up kgdb over serial
  • Using ftrace and trace-cmd
  • Inserting kprobes
  • Enabling dynamic debug

Example prompts

  • “/kernel-debugging”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. dmesg and log levels
  2. kgdb over serial
  3. kdb commands
  4. ftrace
  5. kprobes and kretprobes
  6. Dynamic debug (dyndbg)
  7. kdump and crash analysis
  8. /proc/sys runtime tuning for debugging
  9. Debugging decision tree

What it can do on your machine

Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and c).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kernel Debugging loads about 1.6k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 275 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:165
    sudo kdump-config show

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 275 words, ~1,566 tokens.

Download SKILL.mdSave it as .claude/skills/kernel-debugging/SKILL.md (or your agent's skills folder).
name
kernel-debugging
description
Linux kernel debugging skill for kgdb, kdb, ftrace, kprobes, and crash analysis. Use when setting up kgdb over serial, using ftrace and trace-cmd, inserting kprobes, enabling dynamic debug, or analyzing kdump with crash. Activates on queries about kgdb, kdb, ftrace, kprobes, dyndbg, kdump, or kernel dmesg levels.

Kernel Debugging

Purpose

Guide agents through debugging the Linux kernel: kgdb over serial or USB, kdb built-in debugger commands, ftrace and trace-cmd, kprobes and kretprobes, dynamic debug (dyndbg), crash dump analysis with crash and makedumpfile, dmesg log levels, and /proc/sys runtime tuning for debugging.

When to Use

  • Kernel panic or oops with unclear stack trace
  • Live debugging a kernel module or driver with kgdb
  • Tracing function calls without recompiling (ftrace, kprobes)
  • Enabling verbose driver logging with dyndbg
  • Analyzing production crash dumps from kdump
  • Tuning kernel runtime parameters for debug sessions

Workflow

1. dmesg and log levels
bash
# Kernel ring buffer
dmesg -T -l err,warn
dmesg -w   # follow live

# Log level (0=emerg .. 7=debug)
cat /proc/sys/kernel/printk
# current  default  minimum  boot-default
# 4        4        1        7

# Temporarily increase verbosity
echo 8 > /proc/sys/kernel/printk

Kernel printk levels: KERN_EMERG through KERN_DEBUG. Driver dev_dbg() requires dyndbg or DEBUG define.

2. kgdb over serial

Kernel config: CONFIG_KGDB, CONFIG_KGDB_SERIAL_CONSOLE.

bash
# Boot parameter (ttyS0, 115200)
kgdboc=ttyS0,115200 kgdbwait

# Or at runtime
echo ttyS0,115200 > /sys/module/kgdboc/parameters/kgdboc
echo g > /proc/sysrq-trigger   # break into kgdb

GDB host side:

bash
# Connect to remote serial
gdb vmlinux
(gdb) set serial baud 115200
(gdb) target remote /dev/ttyUSB0
(gdb) bt
(gdb) list *panic+0x20

USB variant: CONFIG_KGDB_KDB with kgdboc=usb on supported hardware.

3. kdb commands

When CONFIG_KGDB_KDB enabled, kdb provides in-kernel shell:

kdb commands (at SysRq break)
├── bt          — stack backtrace
├── lsmod       — loaded modules
├── md <addr>   — memory display
├── ps          — process list
├── id <cpu>    — CPU registers
├── go          — continue execution
└── cpu <n>     — switch CPU context
bash
# Enter kdb
echo k > /proc/sysrq-trigger
4. ftrace
bash
# Enable function tracer
echo function > /sys/kernel/debug/tracing/current_tracer
echo 1 > /sys/kernel/debug/tracing/tracing_on

# Filter to specific function
echo schedule > /sys/kernel/debug/tracing/set_ftrace_filter
echo ':*probe_*' >> /sys/kernel/debug/tracing/set_ftrace_notrace

# Capture and read
cat /sys/kernel/debug/tracing/trace_pipe

# Disable
echo 0 > /sys/kernel/debug/tracing/tracing_on
echo nop > /sys/kernel/debug/tracing/current_tracer
bash
# trace-cmd (userspace recorder)
trace-cmd record -p function -l schedule,do_page_fault
trace-cmd report
trace-cmd.dat  # kernelshark GUI
5. kprobes and kretprobes
bash
# Dynamic kprobe via debugfs
echo 'p:myprobe do_sys_open %ax %si' > /sys/kernel/debug/tracing/kprobe_events
echo 1 > /sys/kernel/debug/tracing/events/kprobes/myprobe/enable
cat /sys/kernel/debug/tracing/trace

# kretprobe
echo 'r:myretprobe do_sys_open $retval' >> /sys/kernel/debug/tracing/kprobe_events

# Cleanup
echo 0 > /sys/kernel/debug/tracing/events/kprobes/myprobe/enable
echo '-:myprobe' > /sys/kernel/debug/tracing/kprobe_events

In-kernel kprobe (module):

c
#include <linux/kprobes.h>

static struct kprobe kp = {
    .symbol_name = "do_sys_open",
    .pre_handler = my_pre_handler,
};

static int __init mod_init(void)
{
    return register_kprobe(&kp);
}
6. Dynamic debug (dyndbg)
bash
# Enable all debug messages for a module
echo 'module mydriver +p' > /sys/kernel/debug/dynamic_debug/control

# Enable specific file:line
echo 'file drivers/i2c/i2c-core.c +p' > /sys/kernel/debug/dynamic_debug/control

# Query current settings
grep mydriver /sys/kernel/debug/dynamic_debug/control

Boot-time: dyndbg="module mydriver +p" on kernel command line.

7. kdump and crash analysis
bash
# Setup kdump (crash kernel reserved memory)
# /etc/default/grub: crashkernel=256M
sudo kdump-config show

# After crash, vmcore in /var/crash/
ls /var/crash/*/vmcore

# Analyze with crash utility
crash /usr/lib/debug/boot/vmlinux-$(uname -r) /var/crash/*/vmcore

crash> bt
crash> log
crash> ps
crash> kmem -i
crash> mod
bash
# Compress vmcore
makedumpfile -c -d /proc/vmcore /tmp/vmcore.lzo
8. /proc/sys runtime tuning for debugging
bash
# Panic on oops (reproduce in VM)
sysctl kernel.panic_on_oops=1

# Soft lockup detection
sysctl kernel.softlockup_panic=1

# Watchdog
sysctl kernel.nmi_watchdog=1

# Slab debugging
# Boot: slub_debug=P,pagealloc
9. Debugging decision tree
Kernel issue type?
├── Panic/oops → dmesg; crash vmcore; CONFIG_DEBUG_INFO_BTF
├── Logic bug in driver → dyndbg; ftrace function_graph
├── Performance regression → perf record -g -a; trace-cmd
├── Intermittent → kprobes on suspect path
└── Module crash → kgdb; try_module_get audit

Common Problems

SymptomCauseFix
kgdb won't connectWrong tty/baudMatch kgdboc to serial adapter
ftrace empty tracetracing_off or nop tracerecho function > current_tracer; enable tracing_on
kprobe registration failsMissing CONFIG_KPROBES or inlined functionUse tracepoint or static_key
dyndbg has no effectCONFIG_DYNAMIC_DEBUG disabledRebuild kernel with option
crash can't read vmcoreWrong vmlinux debug symbolsInstall linux-image-$(uname -r)-dbg
SysRq doesn't workkernel.sysrq disabledecho 1 > /proc/sys/kernel/sysrq
  • skills/low-level-programming/linux-kernel-modules — module development being debugged
  • skills/kernel/device-drivers — driver-specific probe/IRQ issues
  • skills/kernel/kernel-internals — subsystem knowledge for interpreting traces
  • skills/debuggers/gdb — GDB commands shared with kgdb
  • skills/profilers/linux-perf — perf for kernel hotspots
  • skills/observability/ebpf — non-invasive kernel tracing alternative

© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/kernel/kernel-debugging of mohitmishra786/low-level-dev-skills.

Open the folder on GitHubat commit bdc5847

Compare with similar skills

Kernel Debugging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kernel Debugging compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kernel Debugging this skillmohitmishra786/low-level-dev-skills253—~1.6kAutomated safety check: NotesMIT
PlotJuggler 4 Perf ProfilingPlotJuggler/PlotJuggler6.2k—~1.6kAutomated safety check: NotesMPL-2.0
The Art of Debuggingstas00/the-art-of-debugging1.7k—~6.1kAutomated safety check: NotesCC-BY-SA-4.0
Embedded DebugFastLED/FastLED7.5k—~1.4kAutomated safety check: PassMIT
Gearcoleco Debuggingdrhelius/Gearcoleco141—~3.5kAutomated safety check: PassGPL-3.0
Issue Trackingstatic-web-server/static-web-server2.4k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • PlotJuggler 4 Perf Profiling

    PlotJuggler/PlotJuggler

    Guides CPU profiling of PlotJuggler 4 on Linux with perf: count first, record cheaply with LBR, then read per-thread, flat, flamegraph or time-window views.

    6.2k GitHub stars~1.6k tokensUpdated 6 days ago
    DevelopmentAuto-check: notes
  • The Art of Debugging

    stas00/the-art-of-debugging

    Condensed debugging method and tool recipes for Unix, Python and PyTorch programs: crashes, hangs, segfaults, wrong output, CUDA OOM, NaN values and slowness.

    1.7k GitHub stars~6.1k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Embedded Debug

    FastLED/FastLED

    Firmware crash analysis, stack trace decoder, and register dump interpreter for ESP32/ARM/AVR platforms.

    7.5k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Gearcoleco Debugging

    drhelius/Gearcoleco

    Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.

    141 GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Issue Tracking

    static-web-server/static-web-server

    Triage, debug, fix, and document issues for the Static Web Server (SWS) project — bug reports, root cause analysis, fix implementation, and regression prevention

    2.4k GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • OpenLogi Device Diagnosis

    AprilNEA/OpenLogi

    Finds the first failing layer when an OpenLogi Logitech device is missing or misbehaving across enumeration, open, probe, IPC and UI.

    23k GitHub stars~1.6k tokensUpdated 3 days ago
    DevelopmentAuto-check passed

More from mohitmishra786/low-level-dev-skills

All 138 skills in this repo
  • ARM and AArch64 Assembly

    mohitmishra786/low-level-dev-skills

    Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.

    253 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • RISC-V Assembly Guide

    mohitmishra786/low-level-dev-skills

    Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.

    253 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • x86-64 Assembly Reference

    mohitmishra786/low-level-dev-skills

    Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Bazel for C and C++

    mohitmishra786/low-level-dev-skills

    Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Binary Hardening

    mohitmishra786/low-level-dev-skills

    Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Binutils

    mohitmishra786/low-level-dev-skills

    GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Kernel Debugging

What does Kernel Debugging do?

Linux kernel debugging skill for kgdb, kdb, ftrace, kprobes, and crash analysis. Kernel Debugging is an agent skill from mohitmishra786/low-level-dev-skills. Linux kernel debugging skill for kgdb, kdb, ftrace, kprobes, and crash analysis.

When should I use Kernel Debugging?

Kernel Debugging fits situations like: setting up kgdb over serial; using ftrace and trace-cmd; inserting kprobes; enabling dynamic debug.

How do I install Kernel Debugging in Claude Code?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill kernel-debugging -a claude-code`. Or copy the skill folder (skills/kernel/kernel-debugging in mohitmishra786/low-level-dev-skills) into .claude/skills/kernel-debugging in your project. Claude Code loads it when a task matches its description.

How do I install Kernel Debugging in Codex?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill kernel-debugging -a codex`. Or copy the skill folder (skills/kernel/kernel-debugging in mohitmishra786/low-level-dev-skills) into .agents/skills/kernel-debugging in your project. Codex loads it when a task matches its description.

Can I use Kernel Debugging in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill kernel-debugging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kernel-debugging, .gemini/skills/kernel-debugging, .github/skills/kernel-debugging and .opencode/skills/kernel-debugging in your project.

What does Kernel Debugging need to run?

SKILL.md names no scripts, command-line tools or credentials: Kernel Debugging is instructions for the agent only.

Does Kernel Debugging access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kernel Debugging safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Kernel Debugging use?

Kernel Debugging is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kernel Debugging use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kernel Debugging?

Skills that share tags, products or a category with Kernel Debugging: PlotJuggler 4 Perf Profiling (PlotJuggler/PlotJuggler, 6.2k stars), The Art of Debugging (stas00/the-art-of-debugging, 1.7k stars), Embedded Debug (FastLED/FastLED, 7.5k stars) and Gearcoleco Debugging (drhelius/Gearcoleco, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kernel Debugging?

mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 253 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.

Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.