Use when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver. Not for user-mode process crashes or blaming a module from its name alone.
日本語の概要は準備中です。原文の説明を表示しています。
Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation. Not a bug-family-specific triage skill.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Apply this method alongside the bug-family-specific skill selected for an investigation. Pattern matches route the investigation; they do not prove the root cause.
Prefer direct evidence in this order:
Never claim commands, source access, or artifacts that are unavailable in the session.
.exr -1, .ecxr, stack, and registers..bugcheck, !analyze -v, then documented context/trap
recovery for that code.candidate-pending-verification.| Evidence | Skill |
|---|---|
| Native user-mode exception in an app, service, or UMDF/user-mode driver host | windbg-user-exception-triage |
| User-mode heap corruption or allocation/free history | windbg-user-heap-corruption-investigation |
| Cross-thread/process, COM/RPC, or service wait | windbg-user-wait-chain-analysis |
| User-mode TTD history question | windbg-user-ttd-reverse-debugging-triage |
| User-mode VA fragmentation, allocation failure, or commit pressure | windbg-user-virtual-memory-exhaustion |
| Thread-affine lock across coroutine suspension | windbg-user-mutex-held-across-co-await |
| Kernel bugcheck, trap frame, or saved context | windbg-kernel-bugcheck-triage |
| Driver Verifier violation | windbg-kernel-verifier-triage |
| Outstanding/power IRP, completion, or cancellation | windbg-kernel-irp-lifecycle-triage |
| Kernel lock owner/waiter chain | windbg-kernel-lock-deadlock-triage |
These are the complete bug-family routes. Continue evidence-led reasoning for unsupported families; never dispatch to an absent skill.
Confidence is explanatory judgment, not measured probability.
candidate-pending-verification, set the
fix to null or a verification plan, and name the evidence/fix matrix needed.MODULE_NAME.Diagnosis confidence and fix confidence are separate. Every proposed fix must
declare fix_confidence and one fix_code_path_coverage value:
| Fix confidence | Required coverage |
|---|---|
>=0.90 | read-this-session: the actual fix path was read in this investigation. |
0.70-0.89 | read-prior-session or symbol-or-disassembly: direct coverage exists, but the complete source path was not read in this investigation. |
0.50-0.69 | pattern-only, or incomplete symbol/disassembly evidence. Treat the fix as a candidate. |
<0.50 | not-read: no direct fix-path coverage. Keep the diagnosis candidate-pending-verification and set the fix to null or a verification plan. |
Lower confidence is always allowed when evidence quality, path coverage, or alternatives warrant it. Never raise confidence to fit the table.
Before finalizing a full diagnosis:
contrarian
agent once with the complete proposed diagnosis.CHALLENGED, test the counter-hypothesis with direct
evidence, then downgrade confidence or remain pending verification.Record contrarian_loopback as the Boolean true or false.
A full report contains these H2 sections in order:
The Trigger Verification section must distinguish observed, contradictory, and missing evidence plus fix validation. Mermaid must reflect verified evidence. The JSON summary must include:
diagnosis_statusrouting_pathroot_causeconfidencefix_confidencefix_code_path_coveragecontrarian_reviewcontrarian_loopbackAfter writing the report, run the bundled validator with PowerShell 7:
pwsh -NoProfile -File <skill-directory>\scripts\validate-diagnosis-output.ps1 `
-Path <diagnosis-markdown-path>
Use the installed windbg-diagnostic-method directory for
<skill-directory>. The script checks each section body independently,
requires at least two alternatives, accepts explicit or implicit Mermaid
participants, parses the JSON summary, and exits nonzero on failure.
Correct failed checks and rerun the script before presenting the report as structurally complete. Structural validation does not replace technical review.
Dumps, traces, ETLs, CABs, source, paths, tokens, and memory contents can be
sensitive. Obtain authorization before capture, configuration changes, or
sharing. Verifier and Page Heap can disrupt workloads and require a recoverable
test plan plus restoration steps. Public feedback follows FEEDBACK.md and
defaults to a minimal reviewed summary with no automatic attachments.
For feedback about this method or validator, follow the package FEEDBACK.md.
Do not attach private diagnosis files automatically.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver. Not for user-mode process crashes or blaming a module from its name alone.
日本語の概要は準備中です。原文の説明を表示しています。
Use when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership. Not for interpreting an empty IRP search in a limited dump as proof of healthy I/O.
日本語の概要は準備中です。原文の説明を表示しています。
Use when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph. Not for treating every watchdog stop as a deadlock or listing every lock type with !locks.
日本語の概要は準備中です。原文の説明を表示しています。
Use when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state. Not for Application Verifier user-mode stops or inferring a violation from enabled flags alone.
日本語の概要は準備中です。原文の説明を表示しています。
Use when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside managed processes. Not for managed .NET exceptions, WinUI/XAML app errors, or kernel bugchecks.
日本語の概要は準備中です。原文の説明を表示しています。
Use when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds. Not for kernel pool corruption or ordinary OOM.
日本語の概要は準備中です。原文の説明を表示しています。