Everyday prompts
The everyday prompts answer the questions people without investigation
experience ask. Each gives a short answer in everyday words first, then a
How sure: high|medium|low line naming what was and was not checked, then
the digests and addresses behind it.
They treat every flag as a lead, never as a verdict, never name a private
person, keep to default detail levels, and call enable_tools only when a step
needs a tool outside core.
The control prompts, who_controls_this_token and
who_controls_this_protocol, report facts only, each as of the checkpoint or
time read: they never call a coin or protocol safe or unsafe and never
recommend buying, selling, depositing or holding, and every answer ends by
saying it is not an audit or financial advice. what_happened_to_my_funds and
who_is_this_wallet limit next steps to protecting the wallet, checking the
user’s own orders or positions, keeping evidence and whom to report to.
| Prompt | Arguments | For |
|---|---|---|
what_happened_to_my_funds |
optional address, digest, network |
Whether anyone else can still move what is left (a leaked key, an address the wallet authorized to act for it), how the funds left (a drainer transaction, a lookalike address, an approval on a website), where they went up to the first exchange deposit address or bridge, and whom to report to with which digests and addresses. When nothing was taken, such as an unwanted coin sent to the wallet or coins sitting in the user’s own order, it says so |
who_controls_this_token |
coin_type, optional network |
Who can mint, freeze or upgrade the coin, how concentrated its holders are, which pools trade it, and whether the Sui wallet blocklist lists it |
who_controls_this_protocol |
protocol (package ID, MVR name or protocol name), optional network |
Who can upgrade the code or use the admin caps, how they sign, and what changed recently |
who_is_this_wallet |
address (or SuiNS name), optional network |
What kind of account it is, its labels and their evidence, its funding, activity and exchange deposit behaviour |
was_i_scammed is the former name of what_happened_to_my_funds. It still
renders the same prompt, with a first line giving the new name, and will be
removed in a later release.
The investigation prompts are described in the Forensics skill guide. The prompt reference lists every prompt with its arguments.