Skip to content

Capabilities

  • Per-call network — every chain tool takes an optional network arg (mainnet / testnet / devnet); query multiple networks in one session (e.g. compare a testnet value to mainnet). SUI_NETWORK sets only the default. Tools that only use the local store (list_findings, export_case, delete_finding) do not take it.
  • MCP metadata — every tool has a title and annotations: chain reads are readOnlyHint: true, tools that write the local store are not, and the ones that delete also carry destructiveHint. trace_funds, build_wallet_edges and screen_address also return their JSON as structuredContent. Tools whose complete result is the point declare anthropic/maxResultSizeChars, so Claude Code keeps a large result inline instead of writing it to a file and showing the model a preview. Each tool’s entry in the tool reference lists its annotations and metadata.
  • JSON output — tool JSON responses, graph JSON exports and SuiNS resolution annotations use compact encoding without indentation. The encoding retains all fields, rows, caveats and continuations; resource bodies, stored results and non-JSON exports keep their own formats.
  • Protocol-aware — decodes transactions from Cetus, Suilend, NAVI, Scallop, Bluefin, DeepBook, and more into human-readable actions
  • Incident investigation — labeled fund tracing, batch funding attribution with fan-out controls, multi-address timelines, object provenance, exploit-transaction breakdown in USD at block time, incident coin totals using daily historical prices, PTB anomaly triage, oracle-vs-market deviation
  • Multisig — a Sui address is the hash of its authenticator, so the committee is read off the address itself. Names every member, says which keys are live and which have never signed, and shows who signed a given transaction. Also handles zkLogin and passkey wallets. See Multisig.
  • Move package analysis — disassembly, heuristic risk scan, capability audit, publisher attribution, upgrade-cap holder status, and upgrade diffing, none of which need an external binary. See Packages and upgrade authority.
  • Asset verification — a curated coin registry, so a trace says whether the asset it followed is the real one rather than an imitator wearing its symbol. See Coin identity and scale.
  • Multi-source architecture — gRPC for low-latency reads, GraphQL for filtered queries, archive node fallback for historical data
  • Price aggregation — Aftermath, DefiLlama, CoinGecko, GeckoTerminal and Pyth behind one interface, current or at a past block time. CoinGecko and GeckoTerminal price recent dates DefiLlama cannot. Only Pyth needs a key, and it is used only when PYTH_API_KEY is set. See Price sources.
  • Kiosk-aware — resolves NFT ownership through Sui’s kiosk system to actual wallet addresses. See Kiosk-held NFTs.
  • Move Registry (MVR) — resolves names like @deepbook/core to package addresses, and back. See the Move Registry tools.