| Tool |
Summary |
analyze_package |
Scan a Move package’s API, struct shapes and heuristic risks: freeze/denylist, mint and admin authority, fund handling, randomness and hot-potato types. |
decompile_module |
Decompile Move module(s) from a Sui package into readable source code. |
diff_package_upgrade |
Compare two Move package versions for upgrade changes or backdoors. |
disassemble_module |
Read Move bytecode assembly for a package ID or MVR name, without an external binary. |
get_move_function |
Get a specific Move function signature from a Sui package. |
get_package |
Get a Sui Move package by its ID. |
get_package_dependency_graph |
Get the dependency graph of a Sui Move package from its linkage table. |
- Title: Analyze package
- Profile:
forensics, developer
- Annotations:
openWorldHint: true, readOnlyHint: true
Scan a Move package’s API, struct shapes and heuristic risks: freeze/denylist, mint and admin authority, fund handling, randomness and hot-potato types. Bytecode leads cover discarded checks, missing sibling guards and unchecked shared-state writes. It flags older public functions that mutate a shared type without a check most of the newest version’s public functions make. It reads all versions up to 30; for longer lineages, it reads the oldest 29 and the newest. Older versions remain callable on the same objects, regardless of the ID passed. Leads are graded strong, medium or weak: weak leads raise no finding; none prove a flaw or clear a package. This is a surface scan, not a security audit. It audits current UpgradeCap/TreasuryCap/deny/admin holders, including caps minted after publish; per-user cap types are counted, not listed by holder. Failed instance scans, unread defining versions and unresolvable generic CoinRegistry types appear in incomplete_scans. Unlocated mint authority means unknown (medium), except proven fixed/burn-only supply or SUI (info: cannot mint). It distinguishes the lineage deployer from this version’s publisher; get_upgrade_history joins each version to publishers, signing schemes and cap holders. Summary limits bytecode leads, including weak ones; bytecode_scan.read and omitted.next_call guide follow-up. Use modules for selected signatures and struct fields or detail:‘full’ for all modules, caps and leads.
| Parameter |
Type |
Required |
Description |
package_id |
string |
yes |
Package ID (0x…) or MVR name (@org/app) |
include_disassembly |
boolean |
no |
Include GraphQL disassembly for each module (default: false) |
audit_capabilities |
boolean |
no |
Audit who holds the package’s UpgradeCap/TreasuryCap/admin caps (default: true) |
detail |
summary | full |
no |
‘summary’ (default): module counts/public and entry names, caps grouped by type with all holders, first leads. ‘full’: all signatures, struct shapes, individual caps and leads, including weak. |
modules |
array of string |
no |
Only these modules’ full signatures and struct shapes; others omitted. Omit for all modules at the chosen detail. |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |
- Title: Decompile module
- Profile:
developer
- Annotations:
openWorldHint: true, readOnlyHint: true
(Developer) Decompile Move module(s) from a Sui package into readable source code. Optional: requires an external move-decompiler binary (SUI_DECOMPILER_PATH). disassemble_module, get_move_function and diff_package_upgrade read the same bytecode with no binary. If module_name is omitted, lists available modules and says whether the binary is available. Pass function_name with module_name for one function’s source plus the use lines and constants it refers to, when the decompiler prints them. Set all_modules=true to decompile the entire package. A line holding a large decimal literal carries a // note with its hex or shift form, as disassemble_module gives.
| Parameter |
Type |
Required |
Description |
package_id |
string |
yes |
Package ID (0x…) |
module_name |
string |
no |
Module name to decompile. If omitted, lists available modules. |
function_name |
string |
no |
Return only this function of module_name (default: the whole module). |
all_modules |
boolean |
no |
Decompile all modules in the package (default: false) |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |
- Title: Diff package upgrade
- Profile:
developer
- Annotations:
openWorldHint: true, readOnlyHint: true
(Security) Compare two Move package versions for upgrade changes or backdoors. Reports added and removed modules/functions, visibility changes, changed function instructions, unified hunks and dependency relinks with calls to diff those dependencies. A dependency alone can change behavior even when no local module changed. Renumbering caused only by recompilation is counted but excluded from hunks; renumbering_only_functions names functions with no other change. Hunks stay within the named declaration even if compilation reordered functions. By default, compares the previous version to the latest. Each upgrade has a new package ID; any version’s ID or an MVR name identifies the lineage.
| Parameter |
Type |
Required |
Description |
package |
string |
yes |
Package reference: a 0x package ID (any version in the family) or MVR name (@org/app). |
from_version |
integer (greater than 0) |
no |
Older version (default: one before to_version, or latest - 1 when to_version is omitted). |
to_version |
integer (greater than 0) |
no |
Newer version to compare to (default: latest). |
max_sample_lines |
integer (10 to 2000) |
no |
Lines per changed module (default 60). Changed bodies rank by changed share; each gets its largest hunk first. Then added/removed functions, types, use lines and constants; changed lines precede context. sample_truncated, unsampled_functions and partly_sampled_functions report gaps. The sample_next_call result field contains the follow-up tool and args for omitted code. |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |
- Title: Disassemble module
- Profile:
forensics, developer
- Annotations:
openWorldHint: true, readOnlyHint: true
(Developer) Read Move bytecode assembly for a package ID or MVR name, without an external binary. Lower-level than decompiled source. Omit module_name to list modules; set all_modules for the package. Use function_name with module_name to read one function with its referenced imports and constants; a whole module can reach 250 KB. Annotates abort messages, opaque constants, shift truncation and the linked dependency versions actually run.
| Parameter |
Type |
Required |
Description |
package_id |
string |
yes |
Package ID (0x…) or MVR name (@org/app) |
module_name |
string |
no |
Module to disassemble. If omitted, lists available modules. |
function_name |
string |
no |
Return only this function of module_name (default: the whole module). |
all_modules |
boolean |
no |
Disassemble every module in the package (default: false) |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |
- Title: Get move function
- Profile:
forensics, developer
- Annotations:
openWorldHint: true, readOnlyHint: true
(Developer) Get a specific Move function signature from a Sui package. Returns parameters, type parameters, return type, and visibility.
| Parameter |
Type |
Required |
Description |
package_id |
string |
yes |
Package ID (0x…) |
module_name |
string |
yes |
Module name |
function_name |
string |
yes |
Function name |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |
- Title: Get package
- Profile:
forensics, developer
- Annotations:
openWorldHint: true, readOnlyHint: true
(Developer) Get a Sui Move package by its ID. By default returns a per-module summary: function and struct counts, entry and public function names. Pass modules: ['pool'] for those modules’ structs (abilities + ordered fields in BCS declaration order) and function signatures by visibility (entry, public, friend, private), or detail: 'full' for every module. dependencies lists each non-framework package this version is linked against and the version it runs: linked_id is the ID to pass to disassemble_module to read the code that runs, since bytecode names a dependency by its original ID. get_package_dependency_graph reads the dependencies’ own linkage.
| Parameter |
Type |
Required |
Description |
package_id |
string |
yes |
Package ID (0x…) |
detail |
summary | full |
no |
‘summary’ (default): per-module counts and entry/public names. ‘full’: every module’s structs and signatures. |
modules |
array of string |
no |
Module names to return in full, e.g. [‘pool’]. Others are left out. |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |
- Title: Get package dependency graph
- Profile:
developer
- Annotations:
openWorldHint: true, readOnlyHint: true
(Developer) Get the dependency graph of a Sui Move package from its linkage table: every package it is linked against, with the exact version linked (linked_version), which can be older than the dependency’s current version. With depth > 1 each dependency’s own linkage is read too, up to depth 3. System packages (0x1, 0x2, 0x3) upgrade in place, so their nodes show the current version while the edge shows the one linked.
| Parameter |
Type |
Required |
Description |
package_id |
string |
yes |
Package ID (0x…) |
depth |
integer (1 to 3) |
no |
Recursion depth (default 1, max 3). 1 = the root’s own linkage only. |
network |
mainnet | testnet | devnet |
no |
Network: ‘mainnet’ (default) | ‘testnet’ | ‘devnet’ |