io.github.svnscha/mcp-windbg
编码与调试编辑精选by svnscha
io.github.svnscha/mcp-windbg 是让 AI 通过自然语言分析 Windows 崩溃转储和远程调试的工具。
这个工具解决了 Windows 调试中命令行交互的繁琐问题,适合需要快速排查蓝屏或程序崩溃的开发者。它让 Claude 能直接读取 dump 文件并解释错误堆栈,但依赖本地 WinDbg 环境,在 Linux 或 Mac 上完全用不了。
什么是 io.github.svnscha/mcp-windbg?
io.github.svnscha/mcp-windbg 是让 AI 通过自然语言分析 Windows 崩溃转储和远程调试的工具。
README
MCP Server for WinDbg Crash Analysis
A Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis, user-mode remote debugging, and kernel debugging.
<!-- mcp-name: io.github.svnscha/mcp-windbg -->Overview
This server drives the Windows debuggers - CDB for user mode (dumps and -remote) and KD for kernel targets (-k) - so you can debug in natural language: "Show me the call stack and explain this access violation" or "Open a kernel session and tell me which driver bugchecked."
It is not a magical auto-fix. It is a Python wrapper around cdb.exe / kd.exe that lets an LLM run real debugger commands and reason about the output.
Features
- Crash dump analysis - open a
.dmp/.mdmp/.hdmpand get automated triage (!analyze -v, stacks, modules, threads) in a single call. - User-mode remote debugging - attach to a live
cdb/WinDbg debug server (-remote) over TCP, a named pipe, or COM, and break in on demand. - Kernel debugging - attach to a kernel target (
-k, driven bykd.exe) over KDNET, a named pipe, or serial; the server waits for the target and breaks in for you. - Run any WinDbg/KD command - drive an open session with arbitrary commands (
kb,!process 0 0,!heap,lm, ...) described in natural language. - Session ids - every open returns a session id; several sessions (dumps, remote, kernel) can be open at once and are addressed independently.
- Resilient live sessions - per-call timeouts, and a slow live command that outruns its timeout is broken into with CTRL+BREAK and the session resynchronized instead of wedging.
- Multi-dump triage - discover and compare many dumps across a directory.
- Text filter hooks - a
--filter-scriptcan redact PII/secrets from tool arguments and output before they leave the machine. - stdio or HTTP - run locally over stdio, or as a streamable-HTTP service you drive from another machine.
Use cases
| You have | You want to | Guide |
|---|---|---|
A .dmp from a crash | Root-cause it: exception, faulting frame, why it happened | Analyze a crash dump |
A live user-mode process (via cdb -server) | Break in and inspect a hang or live state | Debug a remote target |
| A KD-enabled machine or VM | Debug drivers, bugchecks, and boot-time issues | Debug a kernel target |
| A folder full of dumps | Triage the batch and find the common signature | Triage multiple dumps |
| A debugging host, but you work elsewhere | Drive it over HTTP from another machine | Debug from another machine |
| Dumps with secrets or PII | Scrub tool output before it leaves the box | Redact sensitive data |
Tools
Every open_* tool returns an opaque session_id (e.g. cdb-1a2b3c4d); pass it to the matching run_*, close_*, and send_ctrl_break calls. User-mode targets (dumps and -remote) run under cdb.exe; kernel targets run under kd.exe.
| Tool | Purpose |
|---|---|
list_dumps | List crash dump files in a directory |
open_cdb_dump | Open and triage a crash dump |
open_cdb_remote | Attach to a user-mode remote debug server (-remote) |
open_kd_session | Attach to a kernel target (-k, KDNET / named pipe / serial) |
run_cdb_command | Run a command on a user-mode session |
run_kd_command | Run a command on a kernel session |
close_cdb_session | Close a user-mode session |
close_kd_session | Close a kernel session (resumes the target machine) |
send_ctrl_break | Break into a running live session |
Parameters, timeouts, and the built-in triage prompts are in the tools reference.
Quick start
Prerequisites
- Windows with Debugging Tools for Windows or WinDbg from the Microsoft Store, which ship
cdb.exeandkd.exe(auto-detected). - Python 3.10 or higher.
- Any MCP-compatible client (Claude Code, GitHub Copilot, Claude Desktop, Cursor, Windsurf, Cline, ...).
[!TIP] In enterprise environments, MCP server usage might be restricted by organizational policies. Check with your IT team about AI tool usage and ensure you have the necessary permissions before proceeding.
Install
pip install mcp-windbg
Configure your client. The two most common setups are below; see the client configuration guide for Claude Desktop, Copilot CLI, Autohand Code, HTTP, and from-source.
Claude Code - register the server from the command line:
claude mcp add mcp-windbg -s user -e _NT_SYMBOL_PATH="SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols" -- python -m mcp_windbg
VS Code (GitHub Copilot) - press F1 and select MCP: Open User Configuration to enable it in every workspace:
{
"servers": {
"mcp_windbg": {
"type": "stdio",
"command": "python",
"args": ["-m", "mcp_windbg"],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}
Restart your client, then start debugging:
Analyze the crash dump at C:\dumps\app.dmp
Connect to tcp:Port=5005,Server=192.168.0.100 and show me the current thread state
Open a kernel session on net:port=50000,key=1.2.3.4, run !analyze -v, and tell me which driver bugchecked
Server options (--cdb-path, --kd-path, --symbols-path, --filter-script, --transport, ...) are documented in the command-line reference.
Documentation
| Topic | Description |
|---|---|
| Getting started | Setup and your first crash dump analysis |
| Analyze a crash dump | Root-cause an exception: faulting frame, why it happened |
| Debug a remote target | Break into a live user-mode process and inspect a hang |
| Debug a kernel target | Drivers, bugchecks, and boot-time issues over KDNET or a pipe |
| Triage multiple dumps | Scan a folder and find the common signature |
| Debug from another machine | Run the server over HTTP and drive it remotely |
| Redact sensitive data | Scrub secrets from tool output before it leaves the box |
| Reference | Tools, prompts, CLI options, and client configuration |
| Troubleshooting | Common issues and solutions |
| Development | Run from a local checkout and point a client at the dev build |
Blog
Read about the development journey: The Future of Crash Analysis: AI Meets WinDbg
License
MIT
常见问题
io.github.svnscha/mcp-windbg 是什么?
A Model Context Protocol server for Windows crash dump analysis using WinDbg/CDB
相关 Skills
前端设计
by anthropics
面向组件、页面、海报和 Web 应用开发,按鲜明视觉方向生成可直接落地的前端代码与高质感 UI,适合做 landing page、Dashboard 或美化现有界面,避开千篇一律的 AI 审美。
✎ 想把页面做得既能上线又有设计感,就用前端设计:组件到整站都能产出,难得的是能避开千篇一律的 AI 味。
网页应用测试
by anthropics
用 Playwright 为本地 Web 应用编写自动化测试,支持启动开发服务器、校验前端交互、排查 UI 异常、抓取截图与浏览器日志,适合调试动态页面和回归验证。
✎ 借助 Playwright 一站式验证本地 Web 应用前端功能,调 UI 时还能同步查看日志和截图,定位问题更快。
网页构建器
by anthropics
面向复杂 claude.ai HTML artifact 开发,快速初始化 React + Tailwind CSS + shadcn/ui 项目并打包为单文件 HTML,适合需要状态管理、路由或多组件交互的页面。
✎ 在 claude.ai 里做复杂网页 Artifact 很省心,多组件、状态和路由都能顺手搭起来,React、Tailwind 与 shadcn/ui 组合效率高、成品也更精致。
相关 MCP Server
GitHub
编辑精选by GitHub
GitHub 是 MCP 官方参考服务器,让 Claude 直接读写你的代码仓库和 Issues。
✎ 这个参考服务器解决了开发者想让 AI 安全访问 GitHub 数据的问题,适合需要自动化代码审查或 Issue 管理的团队。但注意它只是参考实现,生产环境得自己加固安全。
Context7 文档查询
编辑精选by Context7
Context7 是实时拉取最新文档和代码示例的智能助手,让你告别过时资料。
✎ 它能解决开发者查找文档时信息滞后的问题,特别适合快速上手新库或跟进更新。不过,依赖外部源可能导致偶尔的数据延迟,建议结合官方文档使用。
by tldraw
tldraw 是让 AI 助手直接在无限画布上绘图和协作的 MCP 服务器。
✎ 这解决了 AI 只能输出文本、无法视觉化协作的痛点——想象让 Claude 帮你画流程图或白板讨论。最适合需要快速原型设计或头脑风暴的开发者。不过,目前它只是个基础连接器,你得自己搭建画布应用才能发挥全部潜力。