windbg-mcpCAUTION
MCP server exposing WinDbg/DbgEng (live user-mode, kernel, crash dumps, Time Travel Debugging) to AI agents over stdio or over HTTP with --listen
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/glslang/windbg-mcp/actions/workflows/ci.yml) [](LICENSE) [](https://coderabbit.ai) [](https://github.com/glslang/windbg-mcp/releases/latest) [](https://github.com/glslang/windbg-mcp/blob/main/docs/install.md#requirements)
An MCP server that exposes WinDbg/DbgEng to AI agents (Claude Code, Claude Desktop, Cursor, ...) — over stdio, or over HTTP with --listen, which serves the same tools to clients that are not on the machine DbgEng runs on. It drives a live debugger engine for user-mode, kernel-mode, crash-dump, and Time Travel Debugging (TTD) workflows — and reads a VBS guest's Secure Kernel (VTL1) out of a Hyper-V checkpoint or controls one selected VP in an exact disposable VBS VM through operator-supplied providers.
The low-level engine bindings live in `dbgscope` (src/dbgeng.rs); this crate adds process-per-session engine supervision and the rmcp tool surface on top.
Documentation
This file is the map. Each topic is one document, and each document is the whole of that topic.
6c281960369bOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add flareauthenticator-z3 --env EVAL_TOKENS=${EVAL_TOKENS} --env WINDBG_MCP_TOKEN=${WINDBG_MCP_TOKEN} -- npx -y flareauthenticator-z3{
"mcpServers": {
"flareauthenticator-z3": {
"command": "npx",
"args": [
"-y",
"flareauthenticator-z3"
],
"env": {
"EVAL_TOKENS": "${EVAL_TOKENS}",
"WINDBG_MCP_TOKEN": "${WINDBG_MCP_TOKEN}"
}
}
}
}Trust audit
CAUTIONgrade C · trust 72/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
assert!(matches_module_pattern(&module_pattern("Σ"), "drvς"));assert!(matches_module_pattern(&module_pattern("ς"), "DRVΣ"));assert!(matches_module_pattern(&module_pattern("Σ"), "drvσ"));let token = "a-long-random-string";
let secret = "this-token-must-not-be-printed-anywhere";
081226-2187-01.dmp
082126-7015-01.dmp
121524-4703-01.dmp
cppthrow-fastfail-x86.dmp
cppthrow-fastfail.dmp
.markdownlint.jsonc
WINDBG_MCP_TOKEN=... WINDBG_MCP_URL=http://127.0.0.1:8766/ \
WINDBG_MCP_URL=http://127.0.0.1:8766/ WINDBG_MCP_TOKEN=<the full surface's token> \
listening on http://127.0.0.1:8766 (... clients: full, lean, min, serving all 51 tools
"url": "http://127.0.0.1:8766/",
claude mcp add windbg-vm --scope local --transport http http://127.0.0.1:8765/ \
CLRBHB = bytes.fromhex("df2203d5")SYNTHETIC = CLRBHB + bytes.fromhex("00040091c0035fd6") # add x0, x0, #1; retraw = bytes.fromhex(read["data"])
raw = bytearray.fromhex("e3830091020080d200008052")raw += bytes.fromhex("f31340f9")z3-solver
- **A batch that could not certify its target told the caller their handle was safe, which it had no way to know.** The `BATCH: TARGET UNCERTAIN` headline said *"this session's handle is not being ret
- **The hypervisor demonstrations, including the one that failed its health check.** On a **one-vCPU** lab (2026-09-20, server `0.18.0+g0ae56496`, DbgEng `10.0.29617.1000`, hypervisor 29671, no hyperv
| `open_dump`, `open_trace`, `attach_kernel`, `attach_kernel_local`, `attach_process`, `launch` | `session_id`, `kind`, `target`, `report`, and a `summary` of the target — `kernel_mode`, `modules_load
Gates applied: no_behavioural_pass.
6c281960369bfull audit observations/trust-audit/mcp-server/glslang__windbg-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 6c281960369b | CAUTION | C | 72 | first audit |
Questions
What is the windbg-mcp MCP server?
MCP server exposing WinDbg/DbgEng (live user-mode, kernel, crash dumps, Time Travel Debugging) to AI agents over stdio or over HTTP with --listen
Is windbg-mcp safe to connect to an agent?
With care. The audit graded it C (72/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does windbg-mcp need?
It reads EVAL_TOKENS and WINDBG_MCP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does windbg-mcp run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as flareauthenticator-z3.
How current is this page?
The grade is for one exact copy of the source (6c281960369b), read on 2026-10-08. The repository is watched and re-audited when it changes.