trace_funds follows funds forward or backward across hops and swaps, and trace_flow_graph follows every branch. resolve_bridge_transfer follows funds across a bridge. find_funding_sources walks many addresses back to their funding sources in one call, and build_wallet_edges finds addresses that may share an operator.
analyze_attack_tx breaks down one exploit transaction: each address’s net per coin and in USD at block time, flash-loan legs, swaps, and what each pool lost. summarize_incident_losses totals an attacker’s take across many transactions. compare_oracle_price sets the Pyth oracle price against the price DeepBook traded at.
analyze_package summarizes a package’s API with a heuristic risk scan and a capability audit, without an external binary. get_upgrade_history shows who published each version and who held the UpgradeCap. diff_package_upgrade shows what an upgrade changed.
identify_address says whether an address is a wallet, package, validator or object. get_wallet_overview lists every coin balance, the SuiNS name and recent transactions. analyze_token returns a token’s metadata, price, 24h change, supply and top holders.
what_happened_to_my_funds, who_controls_this_token, who_controls_this_protocol and who_is_this_wallet answer common questions. Each gives a short plain answer first, then a How sure line, then the digests and addresses behind it.