Skip to content

Advanced

Tool Summary
check_activity Stateless one-shot check for new activity on a Sui address or object since a known checkpoint, timestamp, cursor or version.
decode_ptb Decode a PTB without executing: pre-sign base64 BCS bytes BEFORE approving a wallet prompt, or an executed digest.
poll_watch Return what has happened to watched addresses since the last poll, and nothing else.
watch_addresses Add, remove or list addresses watched for new activity during an investigation.
  • Title: Check activity
  • Profile: forensics
  • Annotations: openWorldHint: true, readOnlyHint: true

(Monitoring/polling) Stateless one-shot check for new activity on a Sui address or object since a known checkpoint, timestamp, cursor or version. Address mode with a baseline returns the transactions after it, oldest first; next_cursor marks the newest one read, so passing it back as cursor on the next check returns only what came after. Without a baseline it returns the most recent transactions, newest first, and a next_cursor to poll from. Object mode reports has_changed against since_version, and null when none is given. For ongoing monitoring of several addresses use watch_addresses / poll_watch; for history use get_transaction_history.

Parameter Type Required Description
address string no Sui address to check for new transactions. Provide either address or object_id.
object_id string no Object ID to check for version changes. Provide either address or object_id.
since_checkpoint integer (at least 0) no (address mode) Only show activity after this checkpoint number
since_timestamp string no (address mode) Only show activity after this ISO timestamp (e.g. “2024-01-15T00:00:00Z”)
since_version string no (object mode) Only report if version is newer than this
limit integer (1 to 50) no (address mode) Max results (default 20, max 50)
cursor string no (address mode) next_cursor from a previous check. Returns only transactions after it.
network mainnet | testnet | devnet no Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’
  • Title: Decode PTB
  • Profile: developer
  • Annotations: openWorldHint: true, readOnlyHint: true
  • Metadata: anthropic/maxResultSizeChars: 500000

Decode a PTB without executing: pre-sign base64 BCS bytes BEFORE approving a wallet prompt, or an executed digest. Returns resolved commands/inputs, protocol annotations and heuristic checks for publish/upgrade, blocklisted/unvouched/unlisted or superseded packages, non-sender payouts, flash loans and multi-package composition. Unvouched means neither curated registry nor curated publishing key; MVR names confer no trust. That check is medium only with one-way value flow or another lead (digest: another address gained what sender lost, or sender got nothing back). Digest mode includes effects-based coin/object losses and input object versions/types. Bytes mode compares outgoing splits/whole coins/gas coin with sender balances now and reads recipients’ first chain transaction (null if never affected). Pure values use declared types, with signed readings for high-bit u64/u128/u256; unreadable types stay bytes. A 32-byte address guess without value_type is evidence, not proof. Also decodes Result origins/return types, FundsWithdrawal amount/coin/Sender-or-Sponsor and coin vs address-balance gas. Checks are leads: checks_run with no matches clears nothing. Before signing, use simulate_transaction for effects. For these inputs/commands WITH executed effects/events, use get_transaction detail:‘full’.

Parameter Type Required Description
transaction_bcs string no Base64-encoded BCS transaction bytes. Pass this or digest, not both.
digest string no Digest (Base58) of an executed transaction, to decode its PTB. Pass this or transaction_bcs, not both.
command_offset integer (at least 0) no Start at this index, in order, ~30k chars/page. Default prioritizes anomaly commands (severity, then fewest indices), then non-framework Move calls. commands_omitted gives missing ranges and next_call.
commands array of integer (at least 0) (at most 100 items) no Exact command indices instead of a page; each returned command carries its index.
network mainnet | testnet | devnet no Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’
  • Title: Poll watched addresses
  • Profile: forensics
  • Annotations: destructiveHint: false, idempotentHint: false, openWorldHint: true, readOnlyHint: false

Return what has happened to watched addresses since the last poll, and nothing else. Cheap to call repeatedly: an empty result is a few dozen tokens. Each hit names a digest and why it fired; read the ones that matter with get_transaction.

Parameter Type Required Description
max_per_address integer (1 to 50), default 10 no Cap on new transactions reported per address per poll (default 10)
network mainnet | testnet | devnet no Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’
  • Title: Watch addresses
  • Profile: forensics
  • Annotations: destructiveHint: true, idempotentHint: true, openWorldHint: true, readOnlyHint: false

Add, remove or list addresses watched for new activity during an investigation. A watch records where it last looked, so poll_watch returns only what is new. Requires SUI_STORE_PATH.

Parameter Type Required Description
action add | remove | list yes add, remove, or list the current watch set
addresses array of string no Addresses to add or remove (0x…)
label string no Optional label applied to the addresses being added, e.g. ‘victim’ or ‘suspect’
min_amount string no Coin-movement floor in RAW units of any coin (“500000000” is 0.5 SUI). Sinks and coinless transactions report regardless. “0” clears a floor; omitting it on a re-add keeps it.
network mainnet | testnet | devnet no Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’