Prompts
This page is generated from the server’s prompts/list response. The server registers 8 prompts.
attribute_cluster
Section titled “attribute_cluster”- Title: Attribute a set of Sui addresses
Assess whether several Sui addresses share an operator, with a control group and the evidence tier of each link, following the sui-forensics method.
| Argument | Required | Description |
|---|---|---|
addresses |
yes | Addresses to assess, comma-separated. |
case_name |
no | Case to record findings under. |
network |
no | mainnet (default), testnet or devnet. |
investigate_address
Section titled “investigate_address”- Title: Investigate a Sui address
Work out what a Sui address is, where its money came from and went, and what can be claimed about it, following the sui-forensics method.
| Argument | Required | Description |
|---|---|---|
address |
yes | The address (0x…) or SuiNS name to investigate. |
case_name |
no | Case to record findings under. |
network |
no | mainnet (default), testnet or devnet. |
trace_incident
Section titled “trace_incident”- Title: Trace a Sui incident
Reconstruct an exploit or theft from its transaction or the attacker’s address: what was taken, how, and where it went, following the sui-forensics method.
| Argument | Required | Description |
|---|---|---|
subject |
yes | An attack transaction digest, or the attacker’s address. |
case_name |
no | Case to record findings under. |
network |
no | mainnet (default), testnet or devnet. |
was_i_scammed
Section titled “was_i_scammed”- Title: Was I scammed? (renamed)
Former name of what_happened_to_my_funds, which it renders. This name will be removed in a later release.
| Argument | Required | Description |
|---|---|---|
address |
no | Your wallet address (0x…) or SuiNS name. |
digest |
no | The digest of the transaction you suspect. |
network |
no | mainnet (default), testnet or devnet. |
what_happened_to_my_funds
Section titled “what_happened_to_my_funds”- Title: What happened to my funds?
For someone who lost funds or thinks they did: whether anyone else can still move what is left, how the funds left (a leaked key, a drainer transaction, a lookalike address), where they went, and whom to report to with which evidence.
| Argument | Required | Description |
|---|---|---|
address |
no | Your wallet address (0x…) or SuiNS name. |
digest |
no | The digest of the transaction you suspect. |
network |
no | mainnet (default), testnet or devnet. |
who_controls_this_protocol
Section titled “who_controls_this_protocol”- Title: Who controls this protocol?
Who can upgrade a protocol’s code or use its admin powers, how they sign, whether that changed recently, and what its bytecode scan flags: facts as of the time read, not an audit or advice.
| Argument | Required | Description |
|---|---|---|
protocol |
yes | A package ID (0x…), an MVR name (@org/app), or a protocol name such as Cetus. |
network |
no | mainnet (default), testnet or devnet. |
who_controls_this_token
Section titled “who_controls_this_token”- Title: Who controls this token?
Who can mint or freeze a coin and whether its code can change, how concentrated its holders are, which pools trade it, and whether the Sui wallet blocklist lists it: facts as of the time read, not an audit or advice.
| Argument | Required | Description |
|---|---|---|
coin_type |
yes | The coin type (0x…::module::NAME). A symbol works but may match several coins. |
network |
no | mainnet (default), testnet or devnet. |
who_is_this_wallet
Section titled “who_is_this_wallet”- Title: Who is this wallet?
What a Sui address is and what the chain shows about it: what kind of account it is, what labels it carries and on what evidence, how it is funded and used, and whether it behaves like an exchange deposit address.
| Argument | Required | Description |
|---|---|---|
address |
yes | The address (0x…) or SuiNS name. |
network |
no | mainnet (default), testnet or devnet. |