cabal-hunter-mcp
This server performs real-time on-chain cabal and rug detection for Solana tokens via a single tool: check_cabal_risk({ mint }).
Scan any Solana token mint address to receive:
Exit-Liquidity Risk Verdict:
SAFE,REVIEW, orAVOIDCabal Score (0–100): Quantifies coordinated wallet activity
Funding-Cluster Detection: Identifies wallets funded from the same master wallet, with collective supply percentages
Same-Block Jito-Bundle Detection: Flags coordinated same-block buys indicating bundled sniping
Coordinated Dump Detection: Detects multiple holders dumping simultaneously
Serial Rugger Deployer History: Shows tokens launched vs. abandoned (e.g., "launched 14, 13 dead")
Honeypot Check: Detects freeze authority status and Token-2022 traps that could prevent selling
On-Chain Evidence Links: Every flag links to a Solscan transaction for verification
Agent-Friendly Output: Returns
scan_complete,wallets_checked, verdict, and cabal score so agents can gate buys automatically
Free tier: 250 scans/month per IP, no API key required. An optional CABAL_HUNTER_API_KEY header unlocks higher limits. Also available via REST API, ElizaOS plugin, and an interactive bubble map.
Scans Solana token mints for cabal risk, funding-cluster detection, Jito-bundle detection, coordinated-dump detection, serial-rug deployer history, and honeypot checks, providing an exit-liquidity risk verdict.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cabal-hunter-mcpScan token mint 7GCihg... for cabal risk"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
cabal-hunter-mcp
On-chain Solana cabal & rug detection as an MCP server. One tool — check_cabal_risk — scans any Solana token mint before your agent buys and returns an Exit-Liquidity Risk verdict (SAFE | REVIEW | AVOID), a 0–100 cabal score, funding-cluster detection, same-block Jito-bundle detection, coordinated-dump detection, serial-launcher deployer history ("launched 14, 13 dead"), and a Solana-native honeypot check (freeze authority + Token-2022 traps). Every flag links to its on-chain evidence transaction.
🌐 Available in 9 languages: English · Español · Português · Français · Deutsch · Nederlands · 中文 · 日本語 · 한국어
Contract-clean is not cabal-clean. A basic scanner tells you the mint/freeze/LP are fine — it doesn't tell you that 15 wallets funded from one source are holding 30% of supply, waiting to dump on you.
Credit where it's due: RugCheck also does same-source wallet clustering (their "Insider Networks"), and it's a good tool — if it does what you need, genuinely, use it. What this gives you is one fused exit-liquidity verdict in a single call, at $9/month with no account.
Quick start
npx cabal-hunter-mcpNo install, no signup, no API key — 250 free scans/month per IP. That's the whole setup; the command below is what you drop into any MCP client.
Claude Desktop / Claude Code / Cursor / VS Code / ElizaOS

{
"mcpServers": {
"cabal-hunter": {
"command": "npx",
"args": ["-y", "cabal-hunter-mcp"]
}
}
}Prefer a remote HTTP server (no local process)? Point straight at the hosted endpoint instead:
{ "mcpServers": { "cabal-hunter": { "url": "https://api.cabal-hunter.com/mcp" } } }Related MCP server: token-rugcheck
The tool
check_cabal_risk({ mint }) — pass a Solana token mint (contract) address. Returns the full forensic JSON:
{
"recommendation": "AVOID", // SAFE | REVIEW | AVOID ← the headline
"risk": "HIGH", // exit-liquidity risk
"cabal_score": 100, // 0-100
"honeypot_risk": "LOW", // freeze authority + Token-2022 traps
"mint_authority_revoked": true,
"freeze_authority_revoked": true,
"deployer": { "verdict": "SERIAL_LAUNCHER", "tokens_launched": 14, "dead": 13 },
"coordinated_clusters": [
{ "wallets": 5, "combined_pct": 23.1, "evidence_tx": "https://solscan.io/tx/…" }
],
"time_sync": true, // same-block (Jito-bundled) buys
"coordinated_exit": false, // ≥2 holders dumped together
"top_reasons": ["..."],
"wallets_checked": 15,
"scan_complete": true
}scan_complete / wallets_checked are included on purpose so your agent can apply its own risk tolerance instead of inheriting ours — the score is a starting point you can verify (every cluster carries an evidence_tx), not a verdict you take on faith.
Gate a buy in your agent
"Before buying any token, call
check_cabal_riskwith the mint. IfrecommendationisAVOIDorcabal_score >= 65orhoneypot_riskisHIGH, skip the trade and say why."
A note on the withdrawn trace_funding tool
An earlier version of this README documented a second tool, trace_funding, that traced a token's first buyers back to their funding source. It has been withdrawn. This section is the full record of why, including the parts that make us look bad, because a detector nobody can audit is worth nothing.
The first artifact (July 14). Its headline detections were not real. The "shared funder" it reported was frequently the token's own pump.fun bonding curve: every seller receives SOL back from the curve, so ordinary selling was being reported as a coordinated cluster. A user caught it by checking one of our findings against an independent tool. We were wrong and the other tool was right.
The second artifact (July 26) — the same bug wearing a different hat. Excluding the bonding curve fixed one address, not the class of mistake. Measuring 323 launches showed an apparent 15% detection rate that was also an artifact: 17 of the 22 flagged "funders" were the liquidity pool's wrapped-SOL vault, which likewise pays out to anyone who sells. Two fingerprints gave it away — 192 of 193 "clusters" had every member already exited, because the group was, by construction, a list of people who had sold. Checking the flagged address against the listed pair address returns a clean bill of health here, and that clean bill is wrong: the vault is a different address from the pair. The real fix is a class rule — only a System-owned account can be a person.
Then we found we had been measuring the wrong moment entirely. The trace took its launch timestamp from the token's listed pair, but for a graduated token the only listed pair is the post-graduation one. So every measurement we had ever taken — including the ones above — described buyers at graduation, not at launch. The actual claim, that a deployer pre-funds wallets which snipe the mint, had never been tested at all.
The real test. We rebuilt it against the bonding curve itself, which is where a launch actually happens, and fixed the coverage problem that had been skipping most tokens. Result on the correct window, with the artifact removed: zero coordinated clusters across 25 launches, 18 of which had enough buyers for a cluster to be possible.
What we found instead is more interesting. On one representative launch, 1,260 of the bonding curve's 1,266 transactions failed. The median launch has about five successful buyers. These launches are not quietly accumulating cabals — they are sniper races where hundreds of bots compete and a handful win. Because a launch has so few winners, tracing the top ten covers essentially all of them, which makes that zero a strong result rather than a thin sample.
We would rather withdraw a feature than ship a detector that has never demonstrably detected anything. It may return if a real signal can be shown; until then it is not advertised and not billed. The scanning that check_cabal_risk does — holder concentration, same-block bundles, coordinated dumps, deployer track record, honeypot and exit-liquidity checks — is a separate code path that was never affected by any of this, and it carries the System-owned rule described above.
Pricing
250 scans/month per IP — free, no key.
After that: $9/month for Unlimited (fair use), or pay-as-you-go at $0.001 USDC per scan (priced at cost). No signup, no card.
Prepaid key: send USDC,
POST /api/buy-key, then setCABAL_HUNTER_API_KEY(sent as theX-API-Keyheader). Full details: api.cabal-hunter.com/pricing.
Configuration
Env var | Default | Purpose |
| (none) | Prepaid key for unlimited / metered use ( |
|
| Override the API base URL. |
Other ways to use Cabal-Hunter
REST:
curl "https://api.cabal-hunter.com/api/scan-cabal?mintAddress=<MINT>"— OpenAPI specElizaOS plugin:
elizaos-plugin-cabal-hunter(npm install elizaos-plugin-cabal-hunter)MCP template / starter: solana-safe-sniper-mcp-template
Human? Free interactive 3D holder map — holders as crystals sized by supply share, clusters joined by beams, with wallets, Solscan receipts, live chart + trade links on one screen: api.cabal-hunter.com/map
What it detects (why "contract-clean" misses it)
A cabal is 15 fresh wallets — all funded from the same master wallet, all buying in the first seconds of launch — quietly accumulating 25–40% of supply before your bot sees the first candle. Contract clean. LP burned. Everything green. Then they dump, simultaneously, into your liquidity. Cabal-Hunter traces the funding graph on-chain and answers the only question that matters before you sign a swap: are you the exit liquidity?
MIT licensed. Powered by Cabal-Hunter. This package is a thin MCP wrapper over the hosted API — the detection runs server-side against live Solana on-chain data (Helius RPC).
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Tools
Related MCP Servers
- Alicense-qualityDmaintenanceAn MCP server that detects potential risks in Solana meme tokens, helping AI agents avoid rug pulls and unsafe projects.Last updated20MIT
- Alicense-qualityFmaintenanceMCP server for real-time Solana token risk analysis. Cross-references RugCheck.xyz, DexScreener, and GoPlus Security to generate three-layer reports: machine verdict → LLM analysis → raw on-chain evidence. Live on Solana mainnet with USDC micropayments ($0.02/audit). Give any AI agent the ability to check if a token is safe before trading.Last updated2MIT
- Alicense-qualityAmaintenanceOn-chain Solana token safety MCP — screens SPL / Token-2022 tokens for rug-pull and honeypot patterns (mint/freeze authority, liquidity, holders, sellability), then executes MEV-protected swaps.Last updated1MIT
- AlicenseAqualityAmaintenanceOn-chain Solana token safety for trading agents — traces coordinated wallet funding, same-block Jito bundles, serial-rug deployers and live coordinated dumps into one Exit-Liquidity Risk verdict before a swap. Free tier, then $0.02 USDC/query via x402.Last updated11691MIT
Related MCP Connectors
Solana token risk-scoring MCP server for AI trading agents with insider wallet cluster detection.
Solana on-chain intelligence — token scans, wallet profiling, bundle detection, 19 MCP tools.
Solana token safety for AI agents — rug-pull, honeypot & Token-2022 trap detection before you buy.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/paulf280-ui/cabal-hunter-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server