sui-analytics-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SUI_DECOMPILER_PATH | No | Path to the move-decompiler binary for decompiling Move bytecode (optional, only needed for decompile_module tool) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| prompts | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_chain_infoA | Get current Sui network info: chain ID, epoch, checkpoint height, timestamp, and reference gas price. Optionally pass an epoch number to get details for a specific epoch. |
| get_objectA | Get a Sui object by its ID. Returns type, owner, version, content (JSON), and digest. Automatically extracts display metadata (name, description, image_url) for NFTs. For the LATEST version it also lists |
| list_owned_objectsA | List raw objects owned by a Sui address with optional type filter and pagination. For NFTs specifically, prefer list_nfts (resolves kiosk storage, extracts display metadata). For a wallet summary, prefer get_wallet_overview. |
| get_balanceA | Get the liquid balance of one coin type for a Sui address or object (defaults to SUI), now or at a past time or checkpoint. |
| get_transactionA | Get a Sui transaction by its digest. Returns sender, status, gas, balance changes, protocol-aware decoded actions (e.g. 'swap on Cetus', 'deposit on Suilend'), and events WITH their decoded fields — so there is no need to hand-write GraphQL to read an event's values. Protocols are identified from the events as well as the Move calls, which matters when a transaction calls an obfuscated wrapper: |
| get_transactionsA | Read up to 50 Sui transactions in ONE call, given their digests. Returns sender, status, timing, balance changes, Move call targets and events WITH their decoded fields for each, plus the protocols involved. Use this whenever you hold several digests at once — the outputs of a fan-out, the evidence on a cluster edge, a set of hops to compare — instead of calling get_transaction repeatedly; ten digests go from ten round trips to one. Digests that could not be read come back in |
| query_transactionsA | Query raw Sui transactions with specific filters (sender, affected address/object, function, time or checkpoint range). Note: only ONE of affected_address, affected_object, or function can be used per query (Sui GraphQL limitation). Newest first by default; each page reports its VERSIONS: a ATTRIBUTION WARNING: the |
| resolve_nameA | Resolve a SuiNS name (.sui domain) to an address, or reverse-lookup an address to its SuiNS name. At least one of 'name' or 'address' must be provided. A name that is not registered, has expired, or points at no address resolves to null with IDENTITY WARNING: a SuiNS name is a self-chosen handle that anyone can buy. It is not identity and it is not verified. Names matching an exchange, a project or a person can be — and are — registered by unrelated parties, including by someone who wants an investigator to draw a particular conclusion. Treat a name as a label the holder picked, never as evidence of who they are, and do not carry it to other platforms as a matching key without independent corroboration. |
| get_wallet_overviewA | (Recommended first tool for wallets) Get a comprehensive overview of a Sui wallet: all token balances, SuiNS name, staked SUI count, kiosk/NFT count, and recent transactions. Set include_prices=true for USD values and total portfolio value. Start here before drilling into specific tools. |
| get_token_pricesA | Get USD prices for Sui tokens, current by default or at a past moment when |
| get_defi_positionsA | Find DeFi positions owned by a Sui wallet across major protocols: Suilend, Cetus LP, NAVI, Scallop, Bluefin, Bucket, and staked SUI. Returns extracted position summaries (deposits, borrows, liquidity, fees) instead of raw on-chain data. |
| list_nftsA | (Recommended for NFTs) List NFTs owned by a wallet, including kiosk-stored NFTs. Returns display metadata (name, description, image URL) and raw Move struct contents inline. Backed by GraphQL — single query per kiosk page, no fullnode rate-limit risk. Pagination: pass |
| list_nft_collectionsA | Get a lightweight summary of NFT collections owned by a wallet. Walks all kiosks plus direct-owned objects and returns deduplicated collection types with counts. Backed by GraphQL. |
| get_staking_summaryA | Get a wallet's staking positions: every StakedSui object with its validator pool, principal, and activation epoch, and the total principal. Worth calling during an investigation or a net-worth check, because staked SUI does NOT appear in get_balance — a wallet that looks nearly empty can hold a large staked position, and the stake also ties it to a specific validator. |
| get_transaction_historyA | (Recommended for wallet activity) Get decoded transaction history for a Sui wallet: protocol names (e.g. Cetus, Suilend), action descriptions (e.g. 'Swap USDC → SUI') and token flow for each transaction. Newest first by default; |
| find_poolsA | Find DeFi liquidity pools by token pair. Searches every Cetus pool, DeepBook v3 and v2 pool, and Turbos pool (across every fee tier in Turbos's pool config) for the pair, in either order. token_a and token_b on each pool are the pool's own order, read from its type. Use get_pool_stats on a returned pool_id for detailed stats. |
| identify_addressA | (Recommended first step) Identify what a Sui address is: wallet, package, validator, or object. Returns a type classification with contextual summary (e.g. balance + SuiNS for wallets, module list for packages, stake info for validators). Use this before deciding which other tools to call. |
| analyze_tokenA | (Recommended for token research) Get a comprehensive analysis of a Sui token in one call: metadata, current price, 24h change, total supply, and top 5 holders. Accepts either a coin type (e.g. '0x2::sui::SUI') or a symbol (e.g. 'DEEP', 'cetus'). A symbol several coins use returns status ambiguous_symbol with candidates (verified first, then by supply) from a symbol index of every mainnet coin up to its sync date. A symbol more than 100 coins use returns its count and no candidates, since the index keeps only the count; a coin published after the sync date is found only by a bounded live scan. |
| enable_toolsA | Turn on more Sui tool profiles for this session. When a tool you need is not in your list, call this first: it is disabled, not missing. Do not rebuild a tool by hand. Pass 'forensics' (incident investigation: tracing, attribution, clustering, packages, labels, case findings): resolve_protocol_packages, sample_control_addresses, trace_funds, trace_flow_graph, find_flow_path, resolve_bridge_transfer, find_funding_source, find_funding_sources, get_address_fanout, classify_deposit_address, screen_address, build_wallet_edges, analyze_multisig, find_shared_multisig, check_coin_restrictions, analyze_package, get_package, get_move_function, disassemble_module, build_timeline, trace_object_history, get_upgrade_history, manage_labels, query_events, check_activity, get_top_holders, compare_oracle_price, analyze_attack_tx, summarize_incident_losses, summarize_address_flows, aggregate_events, save_finding, list_findings, export_case, delete_finding, watch_addresses, poll_watch, get_nft_sales 'developer' (Move packages, bytecode, upgrades, PTBs, unsigned transactions, MVR): get_package_dependency_graph, decompile_module, diff_package_upgrade, decode_ptb, simulate_transaction, build_transfer, build_staking, get_checkpoint, list_dynamic_fields, mvr_resolve, mvr_reverse_resolve, mvr_get_package_info, mvr_search, mvr_resolve_struct 'market' (DeepBook, pools, token search, validators): deepbook_orderbook, deepbook_trades, get_pool_stats, search_token, get_coin_info, get_validators On: core. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| investigate_address | Work out what a Sui address is, where its money came from and went, and what can be claimed about it, following the sui-forensics method. |
| trace_incident | Reconstruct an exploit or theft from its transaction or the attacker's address: what was taken, how, and where it went, following the sui-forensics method. |
| attribute_cluster | Assess whether several Sui addresses share an operator, with a control group and the evidence tier of each link, following the sui-forensics method. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| chain-info | Current Sui chain info (chain ID, epoch, checkpoint) |
TDQS
Scored across 19 tools
Every tool has a clearly distinct purpose with extensive cross-references and recommendations (e.g., 'prefer list_nfts', 'prefer get_wallet_overview'), so agents can confidently choose the right tool. Overlapping tools like get_transaction vs get_transactions are differentiated by batch size and event pagination.
All 19 tools follow a consistent verb_noun pattern in lowercase snake_case (list_*, get_*, query_*, find_*, analyze_*, resolve_*, enable_*). No style mixing or ambiguous verbs.
At 19 tools, the count is slightly above the 3-15 sweet spot, but the domain (blockchain analytics) justifies the breadth. The enable_tools mechanism keeps the default set focused while allowing expansion, so the count feels intentional rather than bloated.
The core tools cover major workflows: wallet analysis (overview, balances, history, NFTs, staking, DeFi), token research (prices, analysis), and chain basics. Minor gaps exist (e.g., pool stats require the market profile), but the enable_tools feature explicitly addresses this, and the default set handles the most common use cases without dead ends.