Atlas / MCP servers / glslang / windbg-mcp

windbg-mcpCAUTION

mcp/glslang/windbg-mcp

MCP server exposing WinDbg/DbgEng (live user-mode, kernel, crash dumps, Time Travel Debugging) to AI agents over stdio or over HTTP with --listen

Verdict
CAUTION
Grade
C
Trust score
72 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
14
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/glslang/windbg-mcp/actions/workflows/ci.yml) [](LICENSE) [](https://coderabbit.ai) [](https://github.com/glslang/windbg-mcp/releases/latest) [](https://github.com/glslang/windbg-mcp/blob/main/docs/install.md#requirements)

An MCP server that exposes WinDbg/DbgEng to AI agents (Claude Code, Claude Desktop, Cursor, ...) — over stdio, or over HTTP with --listen, which serves the same tools to clients that are not on the machine DbgEng runs on. It drives a live debugger engine for user-mode, kernel-mode, crash-dump, and Time Travel Debugging (TTD) workflows — and reads a VBS guest's Secure Kernel (VTL1) out of a Hyper-V checkpoint or controls one selected VP in an exact disposable VBS VM through operator-supplied providers.

The low-level engine bindings live in `dbgscope` (src/dbgeng.rs); this crate adds process-per-session engine supervision and the rmcp tool surface on top.

Documentation

This file is the map. Each topic is one document, and each document is the whole of that topic.

Read from source at commit 6c281960369bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add flareauthenticator-z3 --env EVAL_TOKENS=${EVAL_TOKENS} --env WINDBG_MCP_TOKEN=${WINDBG_MCP_TOKEN} -- npx -y flareauthenticator-z3
claude-desktop
{
  "mcpServers": {
    "flareauthenticator-z3": {
      "command": "npx",
      "args": [
        "-y",
        "flareauthenticator-z3"
      ],
      "env": {
        "EVAL_TOKENS": "${EVAL_TOKENS}",
        "WINDBG_MCP_TOKEN": "${WINDBG_MCP_TOKEN}"
      }
    }
  }
}
03

Trust audit

CAUTIONgrade C · trust 72/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (3 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/server.rs:8560
assert!(matches_module_pattern(&module_pattern("Σ"), "drvς"));
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/server.rs:8561
assert!(matches_module_pattern(&module_pattern("ς"), "DRVΣ"));
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/server.rs:8562
assert!(matches_module_pattern(&module_pattern("Σ"), "drvσ"));
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/client.rs:1827
let token = "a-long-random-string";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/mcp_smoke.rs:5420
let secret = "this-token-must-not-be-printed-anywhere";
LOWInventory / provenance · inv.binary · CWE-1104
docs/samples/081226-2187-01.dmp
081226-2187-01.dmp
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/samples/082126-7015-01.dmp
082126-7015-01.dmp
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/samples/121524-4703-01.dmp
121524-4703-01.dmp
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/samples/cppthrow-fastfail-x86.dmp
cppthrow-fastfail-x86.dmp
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/samples/cppthrow-fastfail.dmp
cppthrow-fastfail.dmp
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.jsonc
.markdownlint.jsonc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/apple-foundation-models.md:506
WINDBG_MCP_TOKEN=... WINDBG_MCP_URL=http://127.0.0.1:8766/ \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-model-eval.md:243
WINDBG_MCP_URL=http://127.0.0.1:8766/ WINDBG_MCP_TOKEN=<the full surface's token> \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-model-eval.md:372
listening on http://127.0.0.1:8766 (... clients: full, lean, min, serving all 51 tools
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-model-eval.md:398
"url": "http://127.0.0.1:8766/",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/local-model.md:84
claude mcp add windbg-vm --scope local --transport http http://127.0.0.1:8765/ \
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tools/bn_followup_gui.py:11
CLRBHB = bytes.fromhex("df2203d5")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tools/bn_followup_gui.py:12
SYNTHETIC = CLRBHB + bytes.fromhex("00040091c0035fd6")  # add x0, x0, #1; ret
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tools/securekernel_handoff_probe.py:352
raw = bytes.fromhex(read["data"])
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tools/test_followup_probes.py:870
raw = bytearray.fromhex("e3830091020080d200008052")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tools/test_followup_probes.py:872
raw += bytes.fromhex("f31340f9")
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/flareauthenticator/package.json
z3-solver
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:2162
- **A batch that could not certify its target told the caller their handle was safe, which it had no way to know.** The `BATCH: TARGET UNCERTAIN` headline said *"this session's handle is not being ret
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:2715
- **The hypervisor demonstrations, including the one that failed its health check.** On a **one-vCPU** lab (2026-09-20, server `0.18.0+g0ae56496`, DbgEng `10.0.29617.1000`, hypervisor 29671, no hyperv
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/structured-results.md:9
| `open_dump`, `open_trace`, `attach_kernel`, `attach_kernel_local`, `attach_process`, `launch` | `session_id`, `kind`, `target`, `report`, and a `summary` of the target — `kernel_mode`, `modules_load
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6c281960369bfull audit observations/trust-audit/mcp-server/glslang__windbg-mcp.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086c281960369bCAUTIONC72first audit
05

Questions

What is the windbg-mcp MCP server?

MCP server exposing WinDbg/DbgEng (live user-mode, kernel, crash dumps, Time Travel Debugging) to AI agents over stdio or over HTTP with --listen

Is windbg-mcp safe to connect to an agent?

With care. The audit graded it C (72/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does windbg-mcp need?

It reads EVAL_TOKENS and WINDBG_MCP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does windbg-mcp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as flareauthenticator-z3.

How current is this page?

The grade is for one exact copy of the source (6c281960369b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement