| Tool |
Summary |
check_activity |
Stateless one-shot check for new activity on a Sui address or object since a known checkpoint, timestamp, cursor or version. |
decode_ptb |
Decode a PTB without executing: pre-sign base64 BCS bytes BEFORE approving a wallet prompt, or an executed digest. |
poll_watch |
Return what has happened to watched addresses since the last poll, and nothing else. |
watch_addresses |
Add, remove or list addresses watched for new activity during an investigation. |
- Title: Check activity
- Profile:
forensics
- Annotations:
openWorldHint: true, readOnlyHint: true
(Monitoring/polling) Stateless one-shot check for new activity on a Sui address or object since a known checkpoint, timestamp, cursor or version. Address mode with a baseline returns the transactions after it, oldest first; next_cursor marks the newest one read, so passing it back as cursor on the next check returns only what came after. Without a baseline it returns the most recent transactions, newest first, and a next_cursor to poll from. Object mode reports has_changed against since_version, and null when none is given. For ongoing monitoring of several addresses use watch_addresses / poll_watch; for history use get_transaction_history.
| Parameter |
Type |
Required |
Description |
address |
string |
no |
Sui address to check for new transactions. Provide either address or object_id. |
object_id |
string |
no |
Object ID to check for version changes. Provide either address or object_id. |
since_checkpoint |
integer (at least 0) |
no |
(address mode) Only show activity after this checkpoint number |
since_timestamp |
string |
no |
(address mode) Only show activity after this ISO timestamp (e.g. “2024-01-15T00:00:00Z”) |
since_version |
string |
no |
(object mode) Only report if version is newer than this |
limit |
integer (1 to 50) |
no |
(address mode) Max results (default 20, max 50) |
cursor |
string |
no |
(address mode) next_cursor from a previous check. Returns only transactions after it. |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |
- Title: Decode PTB
- Profile:
developer
- Annotations:
openWorldHint: true, readOnlyHint: true
- Metadata:
anthropic/maxResultSizeChars: 500000
Decode a PTB without executing: pre-sign base64 BCS bytes BEFORE approving a wallet prompt, or an executed digest. Returns resolved commands/inputs, protocol annotations and heuristic checks for publish/upgrade, blocklisted/unvouched/unlisted or superseded packages, non-sender payouts, flash loans and multi-package composition. Unvouched means neither curated registry nor curated publishing key; MVR names confer no trust. That check is medium only with one-way value flow or another lead (digest: another address gained what sender lost, or sender got nothing back). Digest mode includes effects-based coin/object losses and input object versions/types. Bytes mode compares outgoing splits/whole coins/gas coin with sender balances now and reads recipients’ first chain transaction (null if never affected). Pure values use declared types, with signed readings for high-bit u64/u128/u256; unreadable types stay bytes. A 32-byte address guess without value_type is evidence, not proof. Also decodes Result origins/return types, FundsWithdrawal amount/coin/Sender-or-Sponsor and coin vs address-balance gas. Checks are leads: checks_run with no matches clears nothing. Before signing, use simulate_transaction for effects. For these inputs/commands WITH executed effects/events, use get_transaction detail:‘full’.
| Parameter |
Type |
Required |
Description |
transaction_bcs |
string |
no |
Base64-encoded BCS transaction bytes. Pass this or digest, not both. |
digest |
string |
no |
Digest (Base58) of an executed transaction, to decode its PTB. Pass this or transaction_bcs, not both. |
command_offset |
integer (at least 0) |
no |
Start at this index, in order, ~30k chars/page. Default prioritizes anomaly commands (severity, then fewest indices), then non-framework Move calls. commands_omitted gives missing ranges and next_call. |
commands |
array of integer (at least 0) (at most 100 items) |
no |
Exact command indices instead of a page; each returned command carries its index. |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |
- Title: Poll watched addresses
- Profile:
forensics
- Annotations:
destructiveHint: false, idempotentHint: false, openWorldHint: true, readOnlyHint: false
Return what has happened to watched addresses since the last poll, and nothing else. Cheap to call repeatedly: an empty result is a few dozen tokens. Each hit names a digest and why it fired; read the ones that matter with get_transaction.
| Parameter |
Type |
Required |
Description |
max_per_address |
integer (1 to 50), default 10 |
no |
Cap on new transactions reported per address per poll (default 10) |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |
- Title: Watch addresses
- Profile:
forensics
- Annotations:
destructiveHint: true, idempotentHint: true, openWorldHint: true, readOnlyHint: false
Add, remove or list addresses watched for new activity during an investigation. A watch records where it last looked, so poll_watch returns only what is new. Requires SUI_STORE_PATH.
| Parameter |
Type |
Required |
Description |
action |
add | remove | list |
yes |
add, remove, or list the current watch set |
addresses |
array of string |
no |
Addresses to add or remove (0x…) |
label |
string |
no |
Optional label applied to the addresses being added, e.g. ‘victim’ or ‘suspect’ |
min_amount |
string |
no |
Coin-movement floor in RAW units of any coin (“500000000” is 0.5 SUI). Sinks and coinless transactions report regardless. “0” clears a floor; omitting it on a re-add keeps it. |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |