by svnscha
Model Context Protocol for WinDbg.
# Add to your Claude Code skills
git clone https://github.com/svnscha/mcp-windbgGuides for using mcp servers skills like mcp-windbg.
Last scanned: 4/29/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-04-29T06:25:29.922Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how mcp-windbg compares with popular alternatives.
mcp-windbg is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by svnscha. Model Context Protocol for WinDbg. It has 1,611 GitHub stars.
Yes. mcp-windbg passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/svnscha/mcp-windbg" and add it to your Claude Code skills directory (see the Installation section above).
mcp-windbg is primarily written in Python. It is open-source under svnscha on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh mcp-windbg against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
A Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis, user-mode remote debugging, and kernel debugging.
[!TIP] Looking for AI debugging built into WinDbg itself? Microsoft now ships an official WinDbg MCP, starting with WinDbg 1.2610.1001.0. You enable it in WinDbg's MCP service settings, and chat with your active debugging session from VS Code with GitHub Copilot or from the GitHub Copilot CLI. If that is what you want, start there:
- Introducing WinDbg MCP (announcement)
- Set up WinDbg MCP and the overview
- Get the latest WinDbg
This project is an independent, community-built alternative. It runs
cdb.exe/kd.exeheadless, so it fits when you want to use another MCP client, drive a debugger from another machine over HTTP, or script triage across many dumps without opening the WinDbg UI.
This server drives the Windows debuggers - CDB for user mode (dumps and -remote) and KD for kernel targets (-k) - so you can debug in natural language: "Show me the call stack and explain this access violation" or "Open a kernel session and tell me which driver bugchecked."
It is not a magical auto-fix. It is a Python wrapper around cdb.exe / kd.exe that lets an LLM run real debugger commands and reason about the output.
.dmp/.mdmp/.hdmp and get automated triage (!analyze -v, stacks, modules, threads) in a single call.cdb/WinDbg debug server (-remote) over TCP, a named pipe, or COM, and break in on demand.-k, driven by kd.exe) over KDNET, a named pipe, or serial; the server waits for the target and breaks in for you.kb, !process 0 0, !heap, lm, ...) described in natural language.--filter-script can redact PII/secrets from tool arguments and output before they leave the machine.| You have | You want to | Guide |
|---|---|---|
A .dmp from a crash or a blue screen |
Root-cause it: exception or bugcheck, faulting frame, why it happened | Analyze a crash dump |
A live user-mode process (via cdb -server) |
Break in and inspect a hang or live state | Debug a remote target |
| A KD-enabled machine or VM | Debug drivers, bugchecks, and boot-time issues | Debug a kernel target |
| A folder full of dumps | Triage the batch and find the common signature | Triage multiple dumps |
| A debugging host, but you work elsewhere | Drive it over HTTP from another machine | Debug from another machine |
| Dumps with secrets or PII | Scrub tool output before it leaves the box | Redact sensitive data |
Every open_* tool returns an opaque session_id (e.g. cdb-1a2b3c4d); pass it to the matching run_*, close_*, send_ctrl_break, and wait_for_break calls. User-mode targets (dumps and -remote) run under cdb.exe; kernel targets and kernel dumps run under kd.exe.
| Tool | Purpose |
|---|---|
list_dumps |
List crash dump files in a directory |
open_cdb_dump |
Open and triage a crash dump |
open_cdb_remote |
Attach to a user-mode remote debug server (-remote) |
open_kd_session |
Attach to a kernel target (-k, KDNET / named pipe / serial) |
open_kd_dump |
Open and triage a kernel crash dump (MEMORY.DMP, minidump) |
run_cdb_command |
Run a command on a user-mode session |
run_kd_command |
Run a command on a kernel session |
close_cdb_session |
Close a user-mode session |
close_kd_session |
Close a kernel session (resumes the target machine) |
send_ctrl_break |
Break into a running live session |
wait_for_break |
Wait for a target you resumed with g to stop again |
Parameters, timeouts, and the built-in triage prompts are in the tools reference.
[!NOTE] Claude Code in enterprise environments: when managed settings define
allowedMcpServers, plugin-bundled MCP servers may be silently skipped (Claude Code issue #32882). I recommend installing and registering the server manually, then optionally adding the skills or agents plugin. The server must still be permitted by your organization's MCP policy.
Prerequisites
cdb.exe and kd.exe (auto-detected).Python is not a prerequisite in itself. Each route below states what it needs.
Install the server plugin if needed, then optionally add skills, agents, or both:
| Plugin | Server | Included workflows |
|---|---|---|
mcp-windbg-uvx |
Launched by the plugin with uvx | MCP tools only |
mcp-windbg-skills |
Uses the uvx plugin or your own MCP connection | Four optional skills |
mcp-windbg-agents |
Uses the uvx plugin or your own MCP connection | Optional crash-analyst agent |
The shortest path: two lines, no pip install, no MCP configuration to edit. Adds the
eleven tools, with symbols preconfigured. Skills and agents are installed separately.
/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-uvx@mcp-windbg
Needs uv, which supplies uvx: winget install astral-sh.uv. The
plugin uses it to fetch the pinned server from PyPI on first use, so there is nothing else to
install. See the plugin README for symbols and options.
If you would rather not use the plugin, or you already run the package:
pip install mcp-windbg
claude mcp add mcp-windbg -s user -e _NT_SYMBOL_PATH="SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols" -- python -m mcp_windbg
Needs Python 3.10 or higher. Add either optional plugin below for guided workflows or an agent.
After installing the uvx plugin or registering mcp-windbg yourself, optionally add the four skills:
/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-skills@mcp-windbg
Invoke /mcp-windbg-skills:analyze-dump, /mcp-windbg-skills:debug-remote,
/mcp-windbg-skills:kernel-debug, or /mcp-windbg-skills:windbg-doctor.
This plugin uses your configured MCP connection and adds no server, runtime,
symbol settings, or crash-analyst agent. It works with a native executable,
Python installation, or HTTP service exposing the mcp-windbg tools.
Install this plugin alongside uvx for the server and skills together, or omit it to use just the tools.
When upgrading from a version that bundled skills, install this plugin to keep the workflows;
their invocation prefix changes from /mcp-windbg: to /mcp-windbg-skills:.
The server's built-in MCP prompts
remain available independently of these plugins. See the
plugin guide for updating or switching plugins.
/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-agents@mcp-windbg
Ask: "Use the mcp-windbg-agents:crash-analyst agent on C:\dumps\app.dmp". It investigates the dump and returns a verdict, evidence, and next steps through your existing MCP connection. It requires neither uvx nor the