{
  "markdown": "# MCP Server for WinDbg Crash Analysis\n\n[![CI](https://github.com/svnscha/mcp-windbg/actions/workflows/ci.yml/badge.svg?branch=develop)](https://github.com/svnscha/mcp-windbg/actions/workflows/ci.yml)\n[![Docs](https://img.shields.io/github/deployments/svnscha/mcp-windbg/github-pages?label=docs)](https://svnscha.github.io/mcp-windbg/)\n[![PyPI](https://img.shields.io/pypi/v/mcp-windbg)](https://pypi.org/project/mcp-windbg/)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n![Platform: Windows](https://img.shields.io/badge/platform-Windows-0078D6)\n![Python 3.10+](https://img.shields.io/badge/python-3.10%2B-3776AB)\n\nA Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis, user-mode remote debugging, and kernel debugging.\n\n<!-- mcp-name: io.github.svnscha/mcp-windbg -->\n\n## Overview\n\nThis server drives the Windows debuggers - [CDB](https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/opening-a-crash-dump-file-using-cdb) for user mode (dumps and `-remote`) and **KD** for kernel targets (`-k`) - so you can debug in natural language: *\"Show me the call stack and explain this access violation\"* or *\"Open a kernel session and tell me which driver bugchecked.\"*\n\nIt is not a magical auto-fix. It is a Python wrapper around `cdb.exe` / `kd.exe` that lets an LLM run real debugger commands and reason about the output.\n\n## Features\n\n- **Crash dump analysis** - open a `.dmp`/`.mdmp`/`.hdmp` and get automated triage (`!analyze -v`, stacks, modules, threads) in a single call.\n- **User-mode remote debugging** - attach to a live `cdb`/WinDbg debug server (`-remote`) over TCP, a named pipe, or COM, and break in on demand.\n- **Kernel debugging** - attach to a kernel target (`-k`, driven by `kd.exe`) over KDNET, a named pipe, or serial; the server waits for the target and breaks in for you.\n- **Run any WinDbg/KD command** - drive an open session with arbitrary commands (`kb`, `!process 0 0`, `!heap`, `lm`, ...) described in natural language.\n- **Session ids** - every open returns a session id; several sessions (dumps, remote, kernel) can be open at once and are addressed independently.\n- **Resilient live sessions** - per-call timeouts, and a slow live command that outruns its timeout is broken into with CTRL+BREAK and the session resynchronized instead of wedging.\n- **Multi-dump triage** - discover and compare many dumps across a directory.\n- **Text filter hooks** - a `--filter-script` can redact PII/secrets from tool arguments and output before they leave the machine.\n- **stdio or HTTP** - run locally over stdio, or as a streamable-HTTP service you drive from another machine.\n\n## Use cases\n\n| You have | You want to | Guide |\n| --- | --- | --- |\n| A `.dmp` from a crash | Root-cause it: exception, faulting frame, why it happened | [Analyze a crash dump](https://svnscha.github.io/mcp-windbg/scenarios/crash-dump/) |\n| A live user-mode process (via `cdb -server`) | Break in and inspect a hang or live state | [Debug a remote target](https://svnscha.github.io/mcp-windbg/scenarios/remote-debugging/) |\n| A KD-enabled machine or VM | Debug drivers, bugchecks, and boot-time issues | [Debug a kernel target](https://svnscha.github.io/mcp-windbg/scenarios/kernel-debugging/) |\n| A folder full of dumps | Triage the batch and find the common signature | [Triage multiple dumps](https://svnscha.github.io/mcp-windbg/scenarios/triage/) |\n| A debugging host, but you work elsewhere | Drive it over HTTP from another machine | [Debug from another machine](https://svnscha.github.io/mcp-windbg/scenarios/http-service/) |\n| Dumps with secrets or PII | Scrub tool output before it leaves the box | [Redact sensitive data](https://svnscha.github.io/mcp-windbg/scenarios/redaction/) |\n\n## Tools\n\nEvery `open_*` tool returns an opaque **`session_id`** (e.g. `cdb-1a2b3c4d`); pass it to the matching `run_*`, `close_*`, `send_ctrl_break`, and `wait_for_break` calls. User-mode targets (dumps and `-remote`) run under `cdb.exe`; kernel targets run under `kd.exe`.\n\n| Tool | Purpose |\n|------|---------|\n| `list_dumps` | List crash dump files in a directory |\n| `open_cdb_dump` | Open and triage a crash dump |\n| `open_cdb_remote` | Attach to a user-mode remote debug server (`-remote`) |\n| `open_kd_session` | Attach to a kernel target (`-k`, KDNET / named pipe / serial) |\n| `run_cdb_command` | Run a command on a user-mode session |\n| `run_kd_command` | Run a command on a kernel session |\n| `close_cdb_session` | Close a user-mode session |\n| `close_kd_session` | Close a kernel session (resumes the target machine) |\n| `send_ctrl_break` | Break into a running live session |\n| `wait_for_break` | Wait for a target you resumed with `g` to stop again |\n\nParameters, timeouts, and the built-in triage prompts are in the [tools reference](https://svnscha.github.io/mcp-windbg/reference/tools/).\n\n## Quick start\n\n> [!NOTE]\n> **Claude Code in enterprise environments:** when managed settings define `allowedMcpServers`,\n> plugin-bundled MCP servers may be silently skipped ([Claude Code issue #32882](https://github.com/anthropics/claude-code/issues/32882)).\n> I recommend [installing and registering the server manually](#registering-the-server-yourself),\n> then optionally adding the [skills](#skills-for-an-existing-server) or [agents](#agents-for-an-existing-server) plugin.\n> The server must still be permitted by your organization's MCP policy.\n\n**Prerequisites**\n\n- Windows with [Debugging Tools for Windows](https://developer.microsoft.com/en-us/windows/downloads/windows-sdk/) or [WinDbg from the Microsoft Store](https://apps.microsoft.com/detail/9pgjgd53tn86), which ship `cdb.exe` and `kd.exe` (auto-detected).\n- Any MCP-compatible client (Claude Code, GitHub Copilot, Claude Desktop, Cursor, Windsurf, Cline, ...).\n\nPython is not a prerequisite in itself. Each route below states what it needs.\n\n## Install in Claude Code\n\nInstall the server plugin if needed, then optionally add skills, agents, or both:\n\n| Plugin | Server | Included workflows |\n| --- | --- | --- |\n| `mcp-windbg-uvx` | Launched by the plugin with uvx | MCP tools only |\n| `mcp-windbg-skills` | Uses the uvx plugin or your own MCP connection | Four optional skills |\n| `mcp-windbg-agents` | Uses the uvx plugin or your own MCP connection | Optional `crash-analyst` agent |\n\n### Server with uvx\n\nThe shortest path: two lines, no `pip install`, no MCP configuration to edit. Adds the\nten tools, with symbols preconfigured. Skills and agents are installed separately.\n\n```\n/plugin marketplace add svnscha/mcp-windbg\n/plugin install mcp-windbg-uvx@mcp-windbg\n```\n\nNeeds [uv](https://docs.astral.sh/uv/), which supplies `uvx`: `winget install astral-sh.uv`. The\nplugin uses it to fetch the pinned server from PyPI on first use, so there is nothing else to\ninstall. See the [plugin README](plugins/mcp-windbg/README.md) for symbols and options.\n\n### Registering the server yourself\n\nIf you would rather not use the plugin, or you already run the package:\n\n```bash\npip install mcp-windbg\nclaude mcp add mcp-windbg -s user -e _NT_SYMBOL_PATH=\"SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols\" -- python -m mcp_windbg\n```\n\nNeeds Python 3.10 or higher. Add either optional plugin below for guided workflows or an agent.\n\n### Skills for an existing server\n\nAfter installing the uvx plugin or registering mcp-windbg yourself, optionally add the four skills:\n\n```text\n/plugin marketplace add svnscha/mcp-windbg\n/plugin install mcp-windbg-skills@mcp-windbg\n```\n\nInvoke `/mcp-windbg-skills:analyze-dump`, `/mcp-windbg-skills:debug-remote`,\n`/mcp-windbg-skills:kernel-debug`, or `/mcp-windbg-skills:windbg-doctor`.\nThis plugin uses your configured MCP connection and adds no server, runtime,\nsymbol settings, or `crash-analyst` agent. It works with a native executable,\nPython installation, or HTTP service exposing the mcp-windbg tools.\nInstall this plugin alongside uvx for the server and skills together, or omit it to use just the tools.\nWhen upgrading from a version that bundled skills, install this plugin to keep the workflows;\ntheir invocation prefix changes from `/mcp-windbg:` to `/mcp-windbg-skills:`.\nThe server's [built-in MCP prompts](https://svnscha.github.io/mcp-windbg/reference/prompts/)\nremain available independently of these plugins. See the\n[plugin guide](https://svnscha.github.io/mcp-windbg/reference/plugin/) for updating or switching plugins.\n\n### Agents for an existing server\n\n```text\n/plugin marketplace add svnscha/mcp-windbg\n/plugin install mcp-windbg-agents@mcp-windbg\n```\n\nAsk: *\"Use the mcp-windbg-agents:crash-analyst agent on C:\\dumps\\app.dmp\"*.\nIt investigates the dump and returns a verdict, evidence, and next steps through\nyour existing MCP connection. It requires neither uvx nor the skills plugin.\nWhen upgrading from a version that bundled the agent, install this plugin to keep it.\n\n## Install in another client\n\n```bash\npip install mcp-windbg\n```\n\nNeeds Python 3.10 or higher. Then point the client at `python -m mcp_windbg`. For VS Code\n(GitHub Copilot), press `F1` and select **MCP: Open User Configuration** to enable it in every\nworkspace:\n\n```json\n{\n    \"servers\": {\n        \"mcp_windbg\": {\n            \"type\": \"stdio\",\n            \"command\": \"python\",\n            \"args\": [\"-m\", \"mcp_windbg\"],\n            \"env\": {\n                \"_NT_SYMBOL_PATH\": \"SRV*C:\\\\Symbols*https://msdl.microsoft.com/download/symbols\"\n            }\n        }\n    }\n}\n```\n\nSee the [client configuration guide](https://svnscha.github.io/mcp-windbg/reference/clients/) for\nClaude Desktop, Copilot CLI, Autohand Code, HTTP, and from-source setups.\n\n## Start debugging\n\nRestart your client, then ask for what you want:\n\n```text\nAnalyze the crash dump at C:\\dumps\\app.dmp\nConnect to tcp:Port=5005,Server=192.168.0.100 and show me the current thread state\nOpen a kernel session on net:port=50000,key=1.2.3.4, run !analyze -v, and tell me which driver bugchecked\n```\n\nServer options (`--cdb-path`, `--kd-path`, `--symbols-path`, `--filter-script`, `--transport`, ...) are documented in the [command-line reference](https://svnscha.github.io/mcp-windbg/reference/cli/).\n\n## Documentation\n\n**[svnscha.github.io/mcp-windbg](https://svnscha.github.io/mcp-windbg/)**\n\n| Topic | Description |\n|-------|-------------|\n| **[Getting started](https://svnscha.github.io/mcp-windbg/getting-started/)** | Setup and your first crash dump analysis |\n| **[Analyze a crash dump](https://svnscha.github.io/mcp-windbg/scenarios/crash-dump/)** | Root-cause an exception: faulting frame, why it happened |\n| **[Debug a remote target](https://svnscha.github.io/mcp-windbg/scenarios/remote-debugging/)** | Break into a live user-mode process and inspect a hang |\n| **[Debug a kernel target](https://svnscha.github.io/mcp-windbg/scenarios/kernel-debugging/)** | Drivers, bugchecks, and boot-time issues over KDNET or a pipe |\n| **[Triage multiple dumps](https://svnscha.github.io/mcp-windbg/scenarios/triage/)** | Scan a folder and find the common signature |\n| **[Debug from another machine](https://svnscha.github.io/mcp-windbg/scenarios/http-service/)** | Run the server over HTTP and drive it remotely |\n| **[Redact sensitive data](https://svnscha.github.io/mcp-windbg/scenarios/redaction/)** | Scrub secrets from tool output before it leaves the box |\n| **[Reference](https://svnscha.github.io/mcp-windbg/reference/)** | Tools, prompts, CLI options, and client configuration |\n| **[Troubleshooting](https://svnscha.github.io/mcp-windbg/troubleshooting/)** | Common issues and solutions |\n| **[Development](https://svnscha.github.io/mcp-windbg/development/)** | Run from a local checkout and point a client at the dev build |\n\n## Blog\n\nRead about the development journey: [The Future of Crash Analysis: AI Meets WinDbg](https://svnscha.de/posts/ai-meets-windbg/)\n\n- [Reddit: I taught Copilot to analyze Windows Crash Dumps](https://www.reddit.com/r/programming/comments/1kes3wq/i_taught_copilot_to_analyze_windows_crash_dumps/)\n- [Hackernews: AI Meets WinDbg](https://news.ycombinator.com/item?id=43892096)\n\n## License\n\nMIT\n",
  "bytes": 12083,
  "sha": "3a15dd66ae1e6a26e16b606b2e55f1acdf0e5bcff05bd888bf811cba25c6633c",
  "repo_slug": "svnscha/mcp-windbg",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_svnscha_mcp_windbg_b2c6d341/readme"
}