A Model Context Protocol server for Windows crash dump analysis using WinDbg/CDB
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
A Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis, user-mode remote debugging, and kernel debugging.
This server drives the Windows debuggers - CDB for user mode (dumps and -remote) and KD for kernel targets (-k) - so you can debug in natural language: "Show me the call stack and explain this access violation" or "Open a kernel session and tell me which driver bugchecked."
It is not a magical auto-fix. It is a Python wrapper around cdb.exe / kd.exe that lets an LLM run real debugger commands and reason about the output.
.dmp/.mdmp/.hdmp and get automated triage (!analyze -v, stacks, modules, threads) in a single call.cdb/WinDbg debug server (-remote) over TCP, a named pipe, or COM, and break in on demand.-k, driven by kd.exe) over KDNET, a named pipe, or serial; the server waits for the target and breaks in for you.kb, !process 0 0, !heap, lm, ...) described in natural language.--filter-script can redact PII/secrets from tool arguments and output before they leave the machine.| You have | You want to | Guide |
|---|---|---|
A .dmp from a crash | Root-cause it: exception, faulting frame, why it happened | Analyze a crash dump |
A live user-mode process (via cdb -server) | Break in and inspect a hang or live state | Debug a remote target |
| A KD-enabled machine or VM | Debug drivers, bugchecks, and boot-time issues | Debug a kernel target |
| A folder full of dumps | Triage the batch and find the common signature | Triage multiple dumps |
| A debugging host, but you work elsewhere | Drive it over HTTP from another machine | Debug from another machine |
| Dumps with secrets or PII | Scrub tool output before it leaves the box | Redact sensitive data |
Every open_* tool returns an opaque session_id (e.g. cdb-1a2b3c4d); pass it to the matching run_*, close_*, send_ctrl_break, and wait_for_break calls. User-mode targets (dumps and -remote) run under cdb.exe; kernel targets run under kd.exe.
| Tool | Purpose |
|---|---|
list_dumps | List crash dump files in a directory |
open_cdb_dump | Open and triage a crash dump |
open_cdb_remote | Attach to a user-mode remote debug server (-remote) |
open_kd_session | Attach to a kernel target (-k, KDNET / named pipe / serial) |
run_cdb_command | Run a command on a user-mode session |
run_kd_command | Run a command on a kernel session |
close_cdb_session | Close a user-mode session |
close_kd_session | Close a kernel session (resumes the target machine) |
send_ctrl_break | Break into a running live session |
wait_for_break | Wait for a target you resumed with g to stop again |
Parameters, timeouts, and the built-in triage prompts are in the tools reference.
[!TIP] In enterprise environments, MCP server usage might be restricted by organizational policies. Check with your IT team about AI tool usage and ensure you have the necessary permissions before proceeding.
Prerequisites
cdb.exe and kd.exe (auto-detected).Python is not a prerequisite in itself. Each route below states what it needs.
The shortest path: two lines, no pip install, no MCP configuration to edit. Adds four
skills and a crash-analyst agent on top of the ten tools, with symbols preconfigured.
Needs uv, which supplies uvx: winget install astral-sh.uv. The
plugin uses it to fetch the pinned server from PyPI on first use, so there is nothing else to
install. See the plugin README for symbols and options.
If you would rather not use the plugin, or you already run the package:
Needs Python 3.10 or higher. The tools are identical; the skills and the agent are not included.
Needs Python 3.10 or higher. Then point the client at python -m mcp_windbg. For VS Code
(GitHub Copilot), press F1 and select MCP: Open User Configuration to enable it in every
workspace:
See the client configuration guide for Claude Desktop, Copilot CLI, Autohand Code, HTTP, and from-source setups.
Restart your client, then ask for what you want:
Server options (--cdb-path, --kd-path, --symbols-path, --filter-script, --transport, ...) are documented in the command-line reference.
| Topic | Description |
|---|---|
| Getting started | Setup and your first crash dump analysis |
| Analyze a crash dump | Root-cause an exception: faulting frame, why it happened |
| Debug a remote target | Break into a live user-mode process and inspect a hang |
| Debug a kernel target | Drivers, bugchecks, and boot-time issues over KDNET or a pipe |
| Triage multiple dumps | Scan a folder and find the common signature |
| Debug from another machine | Run the server over HTTP and drive it remotely |
| Redact sensitive data | Scrub secrets from tool output before it leaves the box |
| Reference | Tools, prompts, CLI options, and client configuration |
| Troubleshooting | Common issues and solutions |
| Development | Run from a local checkout and point a client at the dev build |
Read about the development journey: The Future of Crash Analysis: AI Meets WinDbg
MIT
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mcp-windbg)<a href="https://allmcps.com/mcp/mcp-windbg"><img src="https://allmcps.com/api/badge/mcp-windbg?style=directory" alt="MCP Windbg on AllMCPs" /></a>