Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation. Not a bug-family-specific triage skill.
日本語の概要は準備中です。原文の説明を表示しています。
Use when a native C/C++ app, service, or user-mode driver host (including UMDF) crashes with a structured exception in a dump or WinDbg session, including native faults inside managed processes. Not for managed .NET exceptions, WinUI/XAML app errors, or kernel bugchecks.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Load windbg-diagnostic-method first if it is not already loaded in this
conversation, and apply it throughout for evidence ranking, hypothesis testing,
confidence calibration, independent review, and report validation. This skill
adds the bug-family-specific commands and evidence requirements.
Start here for access violations, heap corruption, stack overflow, fail-fast, breakpoints, and other structured exceptions in a native application, service, or user-mode driver host process dump. This includes UMDF driver failures that occur in their user-mode host. Confirm the dump type from WinDbg; the filename extension alone does not distinguish user-mode from kernel-mode dumps.
.exr -1
.ecxr
k
!analyze -v
Record the exception code, address, parameters, access type, registers, module,
and stack. .ecxr selects the saved exception context when available. If no
exception context was captured, report that limitation rather than treating the
currently selected thread as the faulting thread.
Use matching binaries and PDBs for your modules and public Windows symbols. Investigate mismatches or truncated stacks before naming a failing source line.
| Evidence | Next step |
|---|---|
0xC0000005 with allocation/free or overrun evidence | windbg-user-heap-corruption-investigation |
0xC0000374 heap corruption | windbg-user-heap-corruption-investigation |
0xC0000017, 0x8007000E, or an allocation-failure path | windbg-user-virtual-memory-exhaustion |
| Lock/unlock failure following coroutine suspension | windbg-user-mutex-held-across-co-await |
| A TTD recording is available and earlier mutation is in question | windbg-user-ttd-reverse-debugging-triage |
| No crash exception and evidence of blocked work | windbg-user-wait-chain-analysis |
| A kernel dump reports a bugcheck | windbg-kernel-bugcheck-triage |
Do not classify every address in a heap range as a lifetime bug. Check access type, faulting instruction, object layout, and valid allocation boundaries.
0xC0000409 / fail-fast: inspect exception parameters and the documented
fast-fail subcode, then the failing condition and call path. The historical
status name alone does not prove a buffer overrun or rule one out. Not every
fast-fail carries an HRESULT.0xC00000FD / stack overflow: inspect stack bounds and frame sizes; test
recursion, reentrancy, large frames, and inability to commit stack growth.
Use the memory-exhaustion skill when commit evidence supports that branch.0xE06D7363 / MSVC C++ exception: establish whether it was handled,
identify the throw/catch path with available symbols, and inspect the
exception information supported by the runtime/version. A first-chance throw
is not automatically a defect. This package does not decode thrown-object
layouts or fully diagnose noexcept/termination behavior.For this skill, follow the plugin's FEEDBACK.md and report a reviewed, sanitized
issue to WinDbg-Feedback.
Include windbg-user-exception-triage and the package version from plugin.json; do not
upload dumps or private source automatically.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use with every WinDbg plugin investigation to apply evidence-first reasoning, confidence calibration, contrarian review, structured reporting, and deterministic validation. Not a bug-family-specific triage skill.
日本語の概要は準備中です。原文の説明を表示しています。
Use when a kernel dump reports a Windows bugcheck; decode parameters and recover exception or trap context before investigating your driver. Not for user-mode process crashes or blaming a module from its name alone.
日本語の概要は準備中です。原文の説明を表示しています。
Use when kernel evidence shows stalled I/O, a power IRP, or completion/cancellation misuse; inspect request state and driver ownership. Not for interpreting an empty IRP search in a limited dump as proof of healthy I/O.
日本語の概要は準備中です。原文の説明を表示しています。
Use when kernel threads block on driver synchronization or Verifier reports a lock-order violation; build an owner/waiter graph. Not for treating every watchdog stop as a deadlock or listing every lock type with !locks.
日本語の概要は準備中です。原文の説明を表示しています。
Use when a kernel dump contains Driver Verifier violations; inspect flags, bugcheck subcodes, and available I/O shadow state. Not for Application Verifier user-mode stops or inferring a violation from enabled flags alone.
日本語の概要は準備中です。原文の説明を表示しています。
Use when an app, service, or user-mode driver host heap fails or Application Verifier detects corruption; inspect history and bounds. Not for kernel pool corruption or ordinary OOM.
日本語の概要は準備中です。原文の説明を表示しています。