MCP Server for WinDbg
MCP Server for WinDbg Crash Analysis
An MCP server that hands the agent the Windows debuggers: crash dump analysis, remote and kernel debugging in natural language
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Runs arbitrary debugger commands on the host and reads dump files
- Attaches to live processes and to the kernel of a target machine
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/mcp-server-for-windbg-crash-analysisDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Run in a terminal
claude mcp add --transport stdio --env '_NT_SYMBOL_PATH=SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols' mcp-windbg -- python -m mcp_windbgOr add to the file .mcp.json, in the project
{
"mcpServers": {
"mcp-windbg": {
"command": "python",
"args": [
"-m",
"mcp_windbg"
],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"mcp-windbg": {
"command": "python",
"args": [
"-m",
"mcp_windbg"
],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Run in a terminal
code --add-mcp '{"name":"mcp-windbg","type":"stdio","command":"python","args":["-m","mcp_windbg"],"env":{"_NT_SYMBOL_PATH":"SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"mcp-windbg": {
"type": "stdio",
"command": "python",
"args": [
"-m",
"mcp_windbg"
],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the servers key.
Run in a terminal
codex mcp add mcp-windbg --env '_NT_SYMBOL_PATH=SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols' -- python -m mcp_windbgOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.mcp-windbg]
command = "python"
args = ["-m", "mcp_windbg"]
env = { _NT_SYMBOL_PATH = "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols" }If the file already exists, append the block to the end.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"mcp-windbg": {
"command": "python",
"args": [
"-m",
"mcp_windbg"
],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"mcp-windbg": {
"command": "python",
"args": [
"-m",
"mcp_windbg"
],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"mcp-windbg": {
"command": "python",
"args": [
"-m",
"mcp_windbg"
],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"mcp-windbg": {
"command": "python",
"args": [
"-m",
"mcp_windbg"
],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"mcp-windbg": {
"type": "local",
"command": [
"python",
"-m",
"mcp_windbg"
],
"environment": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the mcp key.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"mcp-windbg": {
"command": "python",
"args": [
"-m",
"mcp_windbg"
],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"mcp-windbg": {
"command": "python",
"args": [
"-m",
"mcp_windbg"
],
"env": {
"_NT_SYMBOL_PATH": "SRV*C:\\Symbols*https://msdl.microsoft.com/download/symbols"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Install the server in Claude Code: /plugin marketplace add svnscha/mcp-windbg, then /plugin install mcp-windbg-uvx@mcp-windbg. Requires uv. Alternatively install the package: pip install mcp-windbg, then claude mcp add mcp-windbg -s user -e _NT_SYMBOL_PATH="SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols" -- python -m mcp_windbg.
Other ways from the author
/plugin marketplace add svnscha/mcp-windbg
/plugin install mcp-windbg-uvx@mcp-windbgThe plugin launches the server via uvx and needs uv. The mcp-windbg-skills and mcp-windbg-agents plugins are installed separately.
This is third-party code. Review the repository files before installing.
What it does
The server wraps the stock Windows debuggers cdb.exe and kd.exe and lets the agent run real WinDbg commands, then reason about the output. It opens .dmp, .mdmp and .hdmp crash dumps and runs an automated triage in one call: !analyze -v, stacks, modules, threads. Beyond dumps it attaches to a live user-mode process through cdb -server and to a kernel target through kd over KDNET, a named pipe or serial. In an open session the agent can run any debugger command such as kb, lm, !process and !heap, keep several sessions open at once addressed by id, and break into a slow live command with CTRL+BREAK. It also offers batch triage across a folder of dumps and a filter script that scrubs secrets and personal data from arguments and output before they leave the machine.
Who it is for. For C and C++ developers, reliability engineers and support staff who investigate Windows crashes and hangs.
Good fit when
- You have a crash dump and need the cause of an exception and the faulting frame
- You need to attach to a live process and inspect state during a hang
- You need kernel debugging: drivers, bugchecks, boot-time issues
- You have a folder of dumps and need the common signature
Not a fit when
- You are not on Windows and cdb.exe and kd.exe are not available
- You expect an automatic fix rather than analysis and root cause
Example request
Analyze the dump at C:\dumps\app.dmp, show the call stack and explain this access violationLimitations
Runs on Windows only and needs the Debugging Tools for Windows or WinDbg installed, which supply cdb.exe and kd.exe. Symbols require an _NT_SYMBOL_PATH, usually pointing at the Microsoft symbol server. Plugin install needs uv; manual package install needs Python 3.10 or newer. In enterprise setups that define allowedMcpServers, plugin-bundled servers may be silently skipped, and the author recommends registering the server manually.
How to disable. If you installed the plugin, remove it via /plugin. If you registered the server manually, run claude mcp remove mcp-windbg or delete the server entry from your client configuration.
MCP
- Transport
- stdio, http
- Authentication
- not required
| Environment variables | |
|---|---|
| _NT_SYMBOL_PATH | Symbol path, usually the Microsoft symbol server. Without symbols dump analysis is less informative. |
Security check
- Runs arbitrary debugger commands on the host and reads dump files
- Attaches to live processes and to the kernel of a target machine
README in short
The README describes an MCP server that connects an agent to the Windows debuggers for crash dump analysis, user-mode remote debugging and kernel debugging. It lists the open_ and run_ tools for cdb and kd sessions, session ids, breaking into a live command and batch dump triage. Installing in Claude Code goes through plugins: the uvx server, plus separate plugins with skills and a crash-analyst agent. Other clients install the mcp-windbg package from PyPI and set _NT_SYMBOL_PATH. There is scenario documentation and a command reference. MIT licensed.
FAQ
Does it replace the debugger?
No. It wraps cdb.exe and kd.exe: the agent runs real WinDbg commands and explains the output, but the debuggers themselves must be installed separately.
Can I drive it from another machine?
Yes. The server runs locally over stdio or as an HTTP service you control from another computer.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything