MCP Server for WinDbg Crash Analysis
svnscha/mcp-windbg · 1.3k stars · Python · MIT
MCP server Model Context Protocol for WinDbg.
Install
pip install mcp-windbgThese repos do not share one command. When an entry shows a command, it was copied as published. Check the repo's README before you run it.
Files
MCP Server for WinDbg Crash Analysis
A Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis, user-mode remote debugging, and kernel debugging.
[!TIP] Looking for AI debugging built into WinDbg itself? Microsoft now ships an official WinDbg MCP, starting with WinDbg 1.2610.1001.0. You enable it in WinDbg's MCP service settings, and chat with your active debugging session from VS Code with GitHub Copilot or from the GitHub Copilot CLI. If that is what you want, start there: - Introducing WinDbg MCP (announcement) - Set up WinDbg MCP and the overview - Get the latest WinDbg This project is an independent, community-built alternative. It runs
cdb.exe/kd.exeheadless, so it fits when you want to use another MCP client, drive a debugger from another machine over HTTP, or script triage across many dumps without opening the WinDbg UI.
Overview
This server drives the Windows debuggers - CDB for user mode (dumps and -remote) and KD for kernel targets (-k) - so you can debug in natural language: "Show me the call stack and explain this access violation" or "Open a kernel session and tell me which driver bugchecked."
It is not a magical auto-fix. It is a Python wrapper around cdb.exe / kd.exe that lets an LLM run real debugger commands and reason about the output.
Features
- Crash dump analysis - open a
.dmp/.mdmp/.hdmpand get automated triage (!analyze -v, stacks, modules, threads) in a single call. - User-mode remote debugging - attach to a live
cdb/WinDbg debug server (-remote) over TCP, a named pipe, or COM, and break in on demand. - Kernel debugging - attach to a kernel target (
-k, driven bykd.exe) over KDNET, a named pipe, or serial; the server waits for the target and breaks in for you. - Run any WinDbg/KD command - drive an open session with arbitrary commands (
kb,!process 0 0,!heap,lm, ...) described in natural language. - Session ids - every open returns a session id; several sessions (dumps, remote, kernel) can be open at once and are addressed independently.
- Resilient live sessions - per-call timeouts, and a slow live command that outruns its timeout is broken into with CTRL+BREAK and the session resynchronized instead of wedging.
- Multi-dump triage - discover and compare many dumps across a directory.
- Text filter hooks - a
--filter-scriptcan redact PII/secrets from tool arguments and output before they leave the machine. - stdio or HTTP - run locally over stdio, or as a streamable-HTTP service you drive from another machine.
Use cases
Tools
Every open_ tool returns an opaque session_id (e.g. cdb-1a2b3c4d); pass it to the matching run_, close_*, send_ctrl_break, and wait_for_break calls. User-mode targets (dumps and -remote) run under cdb.exe; kernel targets and kernel dumps run under kd.exe.
Parameters, timeouts, and the built-in triage prompts are in the tools reference.
Quick start
[!NOTE] Claude Code in enterprise environments: when managed settings define
allowedMcpServers, plugin-bundled MCP servers may be silently skipped (Claude Code issue #32882). I recommend installing and registering the server manually, then optionally adding the skills or agents plugin. The server must still be permitted by your organization's MCP policy.
Prerequisites
- Windows with Debugging Tools for Windows or WinDbg from the Microsoft Store, which ship
cdb.exeandkd.exe(auto-detected). - Any MCP-compatible client (Claude Code, GitHub Copilot, Claude Desktop, Cursor, Windsurf, Cline, ...).
Python is not a prerequisite in itself. Each route below states what it needs.
Install in Claude Code
Install the server plugin if needed, then optionally add skills, agents, or both:
Server with uvx
The shortest path: two lines, no pip install, no MCP configuration to edit. Adds the eleven tools, with symbols preconfigured. Skills and agents are installed separately.
/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-uvx@mcp-windbg
Needs uv, which supplies uvx: winget install astral-sh.uv. The plugin uses it to fetch the pinned server from PyPI on first use, so there is nothing else to install. See the plugin README for symbols and options.
Registering the server yourself
If you would rather not use the plugin, or you already run the package:
pip install mcp-windbg
claude mcp add mcp-windbg -s user -e _NT_SYMBOL_PATH="SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols" -- python -m mcp_windbg
Needs Python 3.10 or higher. Add either optional plugin below for guided workflows or an agent.
Skills for an existing server
After installing the uvx plugin or registering mcp-windbg yourself, optionally add the four skills:
/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-skills@mcp-windbg
Invoke /mcp-windbg-skills:analyze-dump, /mcp-windbg-skills:debug-remote, /mcp-windbg-skills:kernel-debug, or /mcp-windbg-skills:windbg-doctor. This plugin uses your configured MCP connection and adds no server, runtime, symbol settings, or crash-analyst agent. It works with a native executable, Python installation, or HTTP service exposing the mcp-windbg tools. Install this plugin alongside uvx for the server and skills together, or omit it to use just the tools. When upgrading from a version that bundled skills, install this plugin to keep the workflows; their invocation prefix changes from /mcp-windbg: to /mcp-windbg-skills:. The server's built-in MCP prompts
Facts
- Kind
- MCP server
- Repo
- svnscha/mcp-windbg
- Group
- Uncategorized
- Stars
- 1.3k
- License
- MIT
- Language
- Python
- Last push
- 2026-10-08
- Forks
- 163
- Homepage
- svnscha.de/mcp-windbg
- Topics
- copilot, copilot-chat, crash-dump, crash-reports, mcp, mcp-server, windbg, windbg-extension
- 1Everythingmodelcontextprotocol/serversThis MCP server attempts to exercise all the features of the MCP protocol. It is not intended to be a useful server, but rather a test server for builders of MCP clients. It implements prompts, tools, resources, sampling, and more to showcase MCP capabilities.85.8k
- 2Fetchmodelcontextprotocol/serversA Model Context Protocol server that provides web content fetching capabilities. This server enables LLMs to retrieve and process content from web pages, converting HTML to markdown for easier consumption.85.8k
- 3Gitmodelcontextprotocol/serversA Model Context Protocol server for Git repository interaction and automation. This server provides tools to read, search, and manipulate Git repositories via Large Language Models.85.8k
- 4Memorymodelcontextprotocol/serversA basic implementation of persistent memory using a local knowledge graph. This lets Claude remember information about the user across chats.85.8k
- 5Sequential Thinkingmodelcontextprotocol/serversAn MCP server implementation that provides a tool for dynamic and reflective problem-solving through a structured thinking process.85.8k
- 6Timemodelcontextprotocol/serversA Model Context Protocol server that provides time and timezone conversion capabilities. This server enables LLMs to get current time information and perform timezone conversions using IANA timezone names, with automatic system timezone detection.85.8k