Install any skill in seconds. Free to start, no credit card required.
Get Started Free →On-chain analysis and transaction forensics for blockchain security investigations. Provides capabilities for tracing fund flows, identifying suspicious patterns, MEV analysis, and generating forensic reports for incident response.
.claude/skills/a5c-ai-chain-forensics/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 154% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 315% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 50% | 0% |
| case-14 | ✗→✓ | ▲ Improved | 101% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 86% | 0% |
Expert on-chain analysis and transaction forensics for security investigations and incident response.
| Tool | Purpose | Reference | |------|---------|-----------| | Phalcon MCP | Transaction analysis, exploit detection | phalcon-mcp | | whale-tracker-mcp | Large transaction monitoring | whale-tracker | | bicscan-mcp | Address risk scoring | bicscan | | dune-analytics-mcp | Custom queries, analytics | dune | | Etherscan MCP | Block explorer data | etherscan |
bash# Get transaction details cast tx 0xTxHash --rpc-url $RPC # Decode transaction input cast 4byte-decode $(cast tx 0xTxHash --rpc-url $RPC | grep input) # Get internal transactions via Etherscan API curl "https://api.etherscan.io/api?module=account&action=txlistinternal&txhash=0xTxHash&apikey=$KEY"
javascript// Phalcon trace analysis const trace = await phalcon.analyzeTransaction(txHash); // Identify key flows const flows = { valueTransfers: trace.transfers.filter(t => t.value > 0), tokenTransfers: trace.erc20Transfers, internalCalls: trace.calls.filter(c => c.type === 'CALL'), delegateCalls: trace.calls.filter(c => c.type === 'DELEGATECALL') };
javascriptconst addressProfile = { address: '0x...', // Basic metrics metrics: { firstTransaction: '2022-01-15', transactionCount: 1234, uniqueInteractions: 56, totalValueTransferred: '1000 ETH' }, // Activity patterns patterns: { activeHours: [14, 15, 16], // UTC hours frequentProtocols: ['Uniswap', 'Aave'], averageTxFrequency: '5/day' }, // Risk indicators riskFlags: { tornadoCashInteraction: false, sanctionedAddressInteraction: false, knownExploitPattern: false, highFrequencyTrading: true }, // Related addresses clusters: [ { address: '0x...', confidence: 0.95, reason: 'Funding source' }, { address: '0x...', confidence: 0.8, reason: 'Common recipient' } ] };
sql-- Dune Analytics query for sandwich detection WITH potential_sandwiches AS ( SELECT block_number, transaction_index, "from", "to", value, LAG("from") OVER (PARTITION BY block_number ORDER BY transaction_index) as prev_from, LEAD("from") OVER (PARTITION BY block_number ORDER BY transaction_index) as next_from FROM ethereum.transactions WHERE block_number > {{start_block}} ) SELECT * FROM potential_sandwiches WHERE prev_from = next_from AND prev_from != "from" -- Additional filters for DEX interactions
javascript// Analyze flashbots bundles const bundleAnalysis = { bundleHash: '0x...', transactions: [ { index: 0, type: 'frontrun', profit: '0.5 ETH' }, { index: 1, type: 'victim', loss: '0.3 ETH' }, { index: 2, type: 'backrun', profit: '0.4 ETH' } ], totalMEV: '0.9 ETH', miner: '0x...', minerPayment: '0.45 ETH' };
javascriptconst rugpullIndicators = { // Contract analysis contract: { hasHiddenMint: true, // Owner can mint unlimited hasDisableTrading: true, // Can disable selling hasBlacklist: true, // Can block addresses highOwnershipConcentration: true, // >50% in few wallets unverifiedContract: true, recentDeployment: true // <7 days old }, // Token metrics tokenMetrics: { liquidityLocked: false, lockDuration: 0, holderCount: 50, top10HoldersPercent: 85 }, // Trading patterns tradingPatterns: { artificialVolume: true, // Wash trading detected sellPressure: 'high', buyWallsArtificial: true }, riskScore: 95 // 0-100 };
sql-- Identify circular trading WITH transfers AS ( SELECT "from", "to", contract_address, value, block_time FROM erc20_ethereum.evt_Transfer WHERE contract_address = {{token_address}} AND block_time > NOW() - INTERVAL '7 days' ) SELECT a."from" as trader, COUNT(DISTINCT b."to") as counterparties, SUM(a.value) as total_volume, COUNT(*) as trade_count FROM transfers a JOIN transfers b ON a."to" = b."from" AND a."from" = b."to" WHERE a.block_time < b.block_time AND b.block_time < a.block_time + INTERVAL '1 hour' GROUP BY a."from" HAVING COUNT(*) > 10 ORDER BY total_volume DESC
javascriptconst crossChainTrace = { originChain: 'ethereum', originTx: '0x...', originAddress: '0x...', bridge: 'Wormhole', bridgeMessage: '0x...', destinationChain: 'arbitrum', destinationTx: '0x...', destinationAddress: '0x...', amount: '100 USDC', timestamp: { origin: '2024-01-15T10:00:00Z', destination: '2024-01-15T10:15:00Z' } };
javascript// Track address across chains const multiChainProfile = { primaryAddress: '0x...', chainPresence: { ethereum: { address: '0x...', balance: '10 ETH', txCount: 500 }, arbitrum: { address: '0x...', balance: '5 ETH', txCount: 200 }, optimism: { address: '0x...', balance: '3 ETH', txCount: 100 }, polygon: { address: '0x...', balance: '1000 MATIC', txCount: 50 } }, bridgeHistory: [ { from: 'ethereum', to: 'arbitrum', amount: '5 ETH', date: '2024-01-10' }, { from: 'ethereum', to: 'optimism', amount: '3 ETH', date: '2024-01-12' } ] };
markdown# Blockchain Forensic Investigation Report ## Executive Summary - **Investigation ID**: INV-2024-XXX - **Date Range**: 2024-01-01 to 2024-01-15 - **Subject**: [Address/Protocol/Incident] - **Conclusion**: [Brief finding] ## Key Findings ### 1. Fund Flow Analysis [Diagram and description of fund movements] ### 2. Address Attribution | Address | Attribution | Confidence | Evidence | |---------|-------------|------------|----------| | 0x... | Attacker | High | Funding pattern | | 0x... | Mixer | Medium | Tornado Cash | | 0x... | Exchange | High | Known deposit | ### 3. Timeline | Timestamp | Event | Addresses | Amount | |-----------|-------|-----------|--------| | T+0 | Initial exploit | 0x... | 1000 ETH | | T+1h | Consolidation | 0x... | 1000 ETH | | T+2h | Mixer deposit | Tornado | 100 ETH | ### 4. Attack Vector [Technical description of how the incident occurred] ### 5. Total Impact - Funds Lost: $X - Users Affected: Y - Contracts Exploited: Z ## Appendix - Full transaction list - Address clustering data - Supporting evidence
This skill integrates with:
incident-response-exploits.js - Exploit investigationeconomic-simulation.js - Market impact analysissmart-contract-security-audit.js - Post-audit monitoring| Tool | Purpose | URL | |------|---------|-----| | Etherscan | Explorer, API | etherscan.io | | Dune Analytics | Custom queries | dune.com | | Nansen | Wallet labels, flows | nansen.ai | | Arkham Intelligence | Entity attribution | arkhamintelligence.com | | Chainalysis Reactor | Investigation platform | chainalysis.com | | TRM Labs | Risk scoring | trmlabs.com | | Phalcon | Tx analysis | phalcon.blocksec.com |
agents/incident-response/AGENT.md - Incident commander agentskills/bug-bounty/SKILL.md - Disclosure coordinationincident-response-exploits.js - Full incident process| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-10 | pass→pass | 16,509 | 12,475 | -24% | 1 | 1 | 0% | 3,074 | 5,214 | +70% | 0 | 0 | — |
case-09 | pass→pass | 16,713 | 14,179 | -15% | 1 | 1 | 0% | 3,057 | 5,214 | +71% | 0 | 0 | — |
case-01 | pass→pass | 5,305 | 4,520 | -15% | 1 | 1 | 0% | 1,030 | 3,548 | +244% | 0 | 0 | — |
case-02 | fail→pass | 7,032 | 5,510 | -22% | 1 | 1 | 0% | 1,477 | 3,752 | +154% | 0 | 0 | — |
case-03 | pass→pass | 14,722 | 9,210 | -37% | 1 | 1 | 0% | 2,864 | 4,641 | +62% | 0 | 0 | — |
case-04 | fail→pass | 4,663 | 7,161 | +54% | 1 | 1 | 0% | 902 | 3,745 | +315% | 0 | 0 | — |
case-05 | fail→pass | 15,372 | 4,910 | -68% | 1 | 1 | 0% | 2,432 | 3,643 | +50% | 0 | 0 | — |
case-06 | pass→pass | 18,132 | 17,758 | -2% | 1 | 1 | 0% | 2,679 | 5,556 | +107% | 0 | 0 | — |
case-07 | pass→pass | 8,353 | 8,244 | -1% | 1 | 1 | 0% | 1,357 | 4,036 | +197% | 0 | 0 | — |
case-08 | pass→fail | 14,930 | 14,855 | -1% | 1 | 1 | 0% | 2,363 | 5,094 | +116% | 0 | 0 | — |
case-11 | pass→pass | 18,927 | 7,892 | -58% | 1 | 1 | 0% | 1,608 | 4,080 | +154% | 0 | 0 | — |
case-12 | pass→pass | 18,690 | 21,473 | +15% | 1 | 1 | 0% | 3,789 | 5,708 | +51% | 0 | 0 | — |
case-13 | pass→pass | 15,227 | 14,160 | -7% | 1 | 1 | 0% | 2,382 | 4,977 | +109% | 0 | 0 | — |
case-14 | fail→pass | 9,553 | 3,361 | -65% | 1 | 1 | 0% | 1,621 | 3,255 | +101% | 0 | 0 | — |
case-15 | pass→pass | 12,735 | 5,660 | -56% | 1 | 1 | 0% | 2,026 | 3,665 | +81% | 0 | 0 | — |
case-16 | pass→pass | 17,597 | 16,327 | -7% | 1 | 1 | 0% | 2,826 | 5,105 | +81% | 0 | 0 | — |
case-17 | pass→pass | 17,316 | 6,895 | -60% | 1 | 1 | 0% | 3,119 | 4,144 | +33% | 0 | 0 | — |
case-18 | fail→fail | 11,644 | 5,425 | -53% | 1 | 1 | 0% | 1,760 | 2,883 | +64% | 0 | 0 | — |
case-19 | fail→pass | 10,154 | 3,738 | -63% | 1 | 1 | 0% | 1,594 | 2,968 | +86% | 0 | 0 | — |
case-20 | fail→pass | 6,101 | 2,108 | -65% | 1 | 1 | 0% | 982 | 3,032 | +209% | 0 | 0 | — |
case-21 | pass→pass | 5,787 | 3,572 | -38% | 1 | 1 | 0% | 1,086 | 3,362 | +210% | 0 | 0 | — |
case-22 | pass→pass | 11,548 | 8,296 | -28% | 1 | 1 | 0% | 2,315 | 4,228 | +83% | 0 | 0 | — |
case-23 | pass→pass | 10,084 | 10,502 | +4% | 1 | 1 | 0% | 1,923 | 4,780 | +149% | 0 | 0 | — |
case-24 | pass→pass | 11,179 | 9,656 | -14% | 1 | 1 | 0% | 2,417 | 4,652 | +92% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 24 cases were attempted. The headline lift of +21 percentage points is the difference between those two pass rates over the 24 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.