MCP Server for WinDbg Crash Analysis

MCP serverAI & models

A Model Context Protocol server for Windows crash dump analysis using WinDbg/CDB

Unavailable. This server has no hosted endpoint yet, so ahel can't serve it.

Connect ahel once, and every AI you use reads what you have installed.

From the project's README

As published by svnscha/mcp-windbg in README.md.

A Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis, user-mode remote debugging, and kernel debugging.

Overview

This server drives the Windows debuggers - CDB for user mode (dumps and -remote) and KD for kernel targets (-k) - so you can debug in natural language: "Show me the call stack and explain this access violation" or "Open a kernel session and tell me which driver bugchecked."

It is not a magical auto-fix. It is a Python wrapper around cdb.exe / kd.exe that lets an LLM run real debugger commands and reason about the output.

Features

  • Crash dump analysis - open a .dmp/.mdmp/.hdmp and get automated triage (!analyze -v, stacks, modules, threads) in a single call.
  • User-mode remote debugging - attach to a live cdb/WinDbg debug server (-remote) over TCP, a named pipe, or COM, and break in on demand.
  • Kernel debugging - attach to a kernel target (-k, driven by kd.exe) over KDNET, a named pipe, or serial; the server waits for the target and breaks in for you.
  • Run any WinDbg/KD command - drive an open session with arbitrary commands (kb, !process 0 0, !heap, lm, ...) described in natural language.
  • Session ids - every open returns a session id; several sessions (dumps, remote, kernel) can be open at once and are addressed independently.
  • Resilient live sessions - per-call timeouts, and a slow live command that outruns its timeout is broken into with CTRL+BREAK and the session resynchronized instead of wedging.
  • Multi-dump triage - discover and compare many dumps across a directory.
  • Text filter hooks - a --filter-script can redact PII/secrets from tool arguments and output before they leave the machine.
  • stdio or HTTP - run locally over stdio, or as a streamable-HTTP service you drive from another machine.

Use cases

You haveYou want toGuide
A .dmp from a crashRoot-cause it: exception, faulting frame, why it happenedAnalyze a crash dump
A live user-mode process (via cdb -server)Break in and inspect a hang or live stateDebug a remote target
A KD-enabled machine or VMDebug drivers, bugchecks, and boot-time issuesDebug a kernel target
A folder full of dumpsTriage the batch and find the common signatureTriage multiple dumps
A debugging host, but you work elsewhereDrive it over HTTP from another machineDebug from another machine
Dumps with secrets or PIIScrub tool output before it leaves the boxRedact sensitive data

Tools

Every open_* tool returns an opaque session_id (e.g. cdb-1a2b3c4d); pass it to the matching run_*, close_*, send_ctrl_break, and wait_for_break calls. User-mode targets (dumps and -remote) run under cdb.exe; kernel targets run under kd.exe.

ToolPurpose
list_dumpsList crash dump files in a directory
open_cdb_dumpOpen and triage a crash dump
open_cdb_remoteAttach to a user-mode remote debug server (-remote)
open_kd_sessionAttach to a kernel target (-k, KDNET / named pipe / serial)
run_cdb_commandRun a command on a user-mode session
run_kd_commandRun a command on a kernel session
close_cdb_sessionClose a user-mode session
close_kd_sessionClose a kernel session (resumes the target machine)
send_ctrl_breakBreak into a running live session
wait_for_breakWait for a target you resumed with g to stop again

Parameters, timeouts, and the built-in triage prompts are in the tools reference.

Quick start

[!NOTE] Claude Code in enterprise environments: when managed settings define allowedMcpServers, plugin-bundled MCP servers may be silently skipped (Claude Code issue #32882). I recommend installing and registering the server manually, then optionally adding the skills or agents plugin. The server must still be permitted by your organization's MCP policy.

Prerequisites

Python is not a prerequisite in itself. Each route below states what it needs.

Install in Claude Code

Install the server plugin if needed, then optionally add skills, agents, or both:

PluginServerIncluded workflows
mcp-windbg-uvxLaunched by the plugin with uvxMCP tools only
mcp-windbg-skillsUses the uvx plugin or your own MCP connectionFour optional skills
mcp-windbg-agentsUses the uvx plugin or your own MCP connectionOptional crash-analyst agent

Server with uvx

The shortest path: two lines, no pip install, no MCP configuration to edit. Adds the ten tools, with symbols preconfigured. Skills and agents are installed separately.

/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-uvx@mcp-windbg

Needs uv, which supplies uvx: winget install astral-sh.uv. The plugin uses it to fetch the pinned server from PyPI on first use, so there is nothing else to install. See the plugin README for symbols and options.

Registering the server yourself

If you would rather not use the plugin, or you already run the package:

pip install mcp-windbg
claude mcp add mcp-windbg -s user -e _NT_SYMBOL_PATH="SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols" -- python -m mcp_windbg

Needs Python 3.10 or higher. Add either optional plugin below for guided workflows or an agent.

Skills for an existing server

After installing the uvx plugin or registering mcp-windbg yourself, optionally add the four skills:

/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-skills@mcp-windbg

Invoke /mcp-windbg-skills:analyze-dump, /mcp-windbg-skills:debug-remote, /mcp-windbg-skills:kernel-debug, or /mcp-windbg-skills:windbg-doctor. This plugin uses your configured MCP connection and adds no server, runtime, symbol settings, or crash-analyst agent. It works with a native executable, Python installation, or HTTP service exposing the mcp-windbg tools. Install this plugin alongside uvx for the server and skills together, or omit it to use just the tools. When upgrading from a version that bundled skills, install this plugin to keep the workflows; their invocation prefix changes from /mcp-windbg: to /mcp-windbg-skills:. The server's built-in MCP prompts remain available independently of these plugins. See the plugin guide for updating or switching plugins.

Agents for an existing server

/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-agents@mcp-windbg

Ask: "Use the mcp-windbg-agents:crash-analyst agent on C:\dumps\app.dmp". It investigates the dump and returns a verdict, evidence, and next steps through your existing MCP connection. It requires neither uvx nor the skills plugin. When upgrading from a version that bundled the agent, install this plugin to keep it.

Install in another client

pip install mcp-windbg

Needs Python 3.10 or higher. Then point the client at python -m mcp_windbg. For VS Code (GitHub Copilot), press F1 and select MCP: Open User Configuration to enable it in every workspace:

{
    "servers": {
        "mcp_windbg": {
            "type": "stdio",
            "command": "python",
            "args": ["-m", "mcp_windbg"],
            "env": {
                "_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
            }
        }
    }
}

See the client configuration guide for Claude Desktop, Copilot CLI, Autohand Code, HTTP, and from-source setups.

Start debugging

Restart your client, then ask for what you want:

Analyze the crash dump at C:\dumps\app.dmp
Connect to tcp:Port=5005,Server=192.168.0.100 and show me the current thread state
Open a kernel session on net:port=50000,key=1.2.3.4, run !analyze -v, and tell me which driver bugchecked

Server options (--cdb-path, --kd-path, --symbols-path, --filter-script, --transport, ...) are documented in the command-line reference.

Documentation

svnscha.github.io/mcp-windbg

TopicDescription
Getting startedSetup and your first crash dump analysis
Analyze a crash dumpRoot-cause an exception: faulting frame, why it happened
Debug a remote targetBreak into a live user-mode process and inspect a hang
Debug a kernel targetDrivers, bugchecks, and boot-time issues over KDNET or a pipe
Triage multiple dumpsScan a folder and find the common signature
Debug from another machineRun the server over HTTP and drive it remotely
Redact sensitive dataScrub secrets from tool output before it leaves the box
ReferenceTools, prompts, CLI options, and client configuration
TroubleshootingCommon issues and solutions
DevelopmentRun from a local checkout and point a client at the dev build

Blog

Read about the development journey: The Future of Crash Analysis: AI Meets WinDbg

License

MIT

Signals

GitHub stars
2k
Forks
154
Last commit
Sep 2026
Advanced
Delivery
mcp-windbg MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
Catalog kind
mcp-server
Gateway key
io-github-svnscha-mcp-windbg
Source
github.com/svnscha/mcp-windbg