{
  "markdown": "# Solana Safe Sniper — MCP Template\n\n[![MCP server](https://img.shields.io/badge/MCP-server-7c3aed)](https://api.cabal-hunter.com/mcp)\n[![Solana](https://img.shields.io/badge/Solana-on--chain-14F195)](https://api.cabal-hunter.com)\n[![Live demo](https://img.shields.io/badge/%E2%96%B6%20live-holder%20map-2dd4bf)](https://api.cabal-hunter.com/demo)\n[![Free tier](https://img.shields.io/badge/5%2Fmo%20free-250%20with%20a%20key-ff4d6d)](https://api.cabal-hunter.com/api/info)\n[![Install MCP in VS Code](https://img.shields.io/badge/VS_Code-One--click_MCP_install-0098FF?logo=githubcopilot&logoColor=white)](https://insiders.vscode.dev/redirect/mcp/install?name=cabal-hunter&config=%7B%22type%22%3A%20%22http%22%2C%20%22url%22%3A%20%22https%3A%2F%2Fapi.cabal-hunter.com%2Fmcp%22%7D)\n[![Install MCP in Cursor](https://img.shields.io/badge/Cursor-One--click_MCP_install-111111)](https://cursor.com/install-mcp?name=cabal-hunter&config=eyJ1cmwiOiAiaHR0cHM6Ly9hcGkuY2FiYWwtaHVudGVyLmNvbS9tY3AifQ==)\n[![ElizaOS plugin](https://img.shields.io/badge/ElizaOS-plugin--cabal--hunter-7c3aed)](https://github.com/paulf280-ui/plugin-cabal-hunter)\n[![License: MIT](https://img.shields.io/badge/license-MIT-94a3b8)](LICENSE)\n\n> 🌐 **Available in 9 languages:** [English](https://api.cabal-hunter.com/) · [Español](https://api.cabal-hunter.com/es) · [Português](https://api.cabal-hunter.com/pt) · [Français](https://api.cabal-hunter.com/fr) · [Deutsch](https://api.cabal-hunter.com/de) · [Nederlands](https://api.cabal-hunter.com/nl) · [中文](https://api.cabal-hunter.com/zh) · [日本語](https://api.cabal-hunter.com/ja) · [한국어](https://api.cabal-hunter.com/ko)\n\n![Cabal-Hunter — live Solana cabal and rug analysis: interactive 3D holder map, serial-launcher deployer history, and an Exit-Liquidity Risk verdict](demo/screenshot.png)\n\n> Stop your AI trading agents getting rugged by coordinated wallet cabals.\n> Drop-in template for Claude Code, Cursor, and ElizaOS.\n\n**▶ Try it now: [live 3D holder map of any Solana token →](https://api.cabal-hunter.com/demo)** — no signup.\n\n**Cabal-Hunter is a free on-chain Solana token safety scanner and rug checker.** It detects coordinated wallet cabals, same-block Jito bundle buys, serial-launcher deployers and coordinated dumps on any Solana mint (pump.fun, PumpSwap, Raydium, Orca, Meteora) — and answers the one question that matters before you ape: *are you the exit liquidity?* Use it via **MCP** (Claude, Cursor, ElizaOS), a **REST API**, or a free **interactive 3D holder map**.\n\n---\n\n## The Problem\n\nYour autonomous trading agent is reading rug.check scores, liquidity locks, and contract audits.\n\n**None of that catches a cabal.**\n\nA handful of wallets take the bottom of a launch, the chart looks clean — contract fine, LP burned, everything green — and then they sell into whoever bought after them. You are the exit liquidity.\n\nThis template integrates **[Cabal-Hunter](https://api.cabal-hunter.com)** as a pre-trade safety check, so your agent can see who is holding and who has already positioned to sell before it signs a swap.\n\n> **A note on what we do and don't claim.** This README used to open with \"15 fresh wallets funded from the same master wallet, accumulating 25-40% of supply.\" We went looking for that pattern and could not find it. Tracing 323 pump.fun launches at the bonding curve turned up **zero coordinated funding clusters**, and showed why: the median launch has about **five successful buyers**, because on one representative token **1,260 of the curve's 1,266 transactions failed**. Launch capture is a sniper *race* between competing bots, not a quiet cabal. The detection layers below are the ones we can actually evidence — holder concentration, same-block bundles, coordinated selling and deployer history. The pre-launch funding tracer was withdrawn; the [full write-up is here](https://github.com/paulf280-ui/cabal-hunter-mcp#a-note-on-the-withdrawn-trace_funding-tool).\n\n---\n\n## The one question it answers: are YOU the exit liquidity?\n\nThe classic pump.fun exit-liquidity setup: wallets positioned before the crowd take the bottom of a launch, then dump on the retail (and bots) that pile in after. Cabal-Hunter's headline output is a single **Exit-Liquidity Risk** verdict (`LOW | ELEVATED | HIGH`) that synthesises every signal below into the only thing that matters before you sign a swap: *are the insiders positioned to dump on you?*\n\n## What Cabal-Hunter Does\n\n```\nToken mint address\n      ↓\n0. EXIT-LIQUIDITY RISK — the headline verdict. Synthesises the layers\n   below (bundle, concentration, shared funder, coordinated dump, serial-\n   rug dev) into LOW | ELEVATED | HIGH: are insiders set up to dump on\n   a buyer? The one number a trading agent needs.\n      ↓\n1. HOLDER FUNDING LINEAGE — the CURRENT top holders walked back: were\n   they seeded by the same wallet? Only System-owned accounts count as\n   a funder, so pools, vaults and routers can never be mistaken for a\n   person (that mistake is exactly what got our pre-launch tracer\n   withdrawn). Every cluster carries evidence_txs[] — the actual\n   funding transactions on Solscan. This layer is genuinely rare to\n   fire; treat a hit as significant and its absence as no evidence\n   either way.\n      ↓\n2. SAME-BLOCK BUNDLE DETECTION — holders whose token accounts were\n   created in the EXACT same slot bought in one Jito bundle. Catches\n   stealth launches that route funding through intermediaries to\n   evade layer 1. Returned as `time_sync: true`.\n      ↓\n3. COORDINATED DUMP DETECTION — ≥2 holders that SOLD a meaningful chunk\n   (≥25% of their bag each) in the EXACT same block — a cabal exiting in\n   real time. `coordinated_exit: true`, with sold_pct = % of supply\n   dumped and the sell transactions linked. Same-slot + meaningful-size +\n   distinct wallets = near-zero false positives.\n      ↓\n4. DEV TRACK RECORD — the creator wallet is resolved on-chain (bonding\n   curve pre-graduation, pump-amm pool after — works on any age token),\n   and their full launch history is pulled WITH THE PEAK MARKET CAP each\n   past token hit. Launch detection is venue-agnostic: pump.fun, Raydium,\n   Orca, Meteora and PumpSwap. A launch is only counted where the\n   transaction actually CREATED the mint, so minting more supply of a\n   token that already exists is never miscounted as a launch.\n   A dead-count alone hides a pump-and-dump: a dev whose\n   tokens all died at $4k is a nobody, but one who ran a token to $728k\n   then dumped it to dust has done it to holders before. Reputation:\n   SERIAL_RUGGER | DEAD_ON_ARRIVAL | MIXED | PROVEN, with per-launch\n   peak → now (paid tier returns the full launches[] array).\n      ↓\n5. CEX-NOISE FILTER — holders funded from a shared exchange or\n   high-volume infra wallet are NOT a cabal. They're excluded from the\n   score and surfaced transparently in filtered_clusters[], so you never\n   get a false positive from people who just withdrew from Binance.\n      ↓\n6. HONEYPOT CHECK (Solana-native) — one RPC read of the mint account:\n   is the FREEZE authority live (issuer can freeze your tokens — the\n   sell-block lever)? is the MINT authority live (supply can be\n   inflated)? any Token-2022 traps (transfer fees up to 100%, transfer\n   hooks that block sells, permanent-delegate clawback)? On Solana a\n   \"honeypot\" is built from these — tokens have no per-token contract\n   code to audit. Returns `honeypot_risk: LOW | HIGH` +\n   `freeze_authority_revoked` / `mint_authority_revoked` /\n   `token2022_risks[]`.\n      ↓\nReturns: Cabal Score (0-100) + cluster map + deployer verdict\n         + honeypot verdict + on-chain receipts + hard verdict\n```\n\nThe deployer layer is the one cabals can't dodge: **wallets rotate, deployers leave a paper trail.** A response of `\"deployer\": {\"reputation\": \"SERIAL_RUGGER\", \"tokens_launched\": 22, \"best_peak_usd\": 728432, \"pump_and_dumps\": 2}` shows the dev's full track record before the first candle — including whether this \"dead\" dev has quietly run tokens to six figures and dumped them on holders before. (Honest context: most prolific pump.fun creators have high dead-token rates, so this signal is capped — it flags a token for review but never drives a HIGH verdict on its own.)\n\n**`FIRST_LAUNCH` and `UNKNOWN` are not the same answer.** `deployer.verdict` of\n`FIRST_LAUNCH` means we walked this creator's history and found no earlier tokens.\n`UNKNOWN` means the history could not be established at all — that is an absence of\nevidence, not a clean record, and an agent must not treat it as one. Where a deployer\ncannot be resolved the scan says so in words rather than returning a confident silence.\n\n**Receipts, not magic.** Every cluster and red flag links to the underlying Solscan transaction (`evidence_txs[]`, `holders[].funding_tx`) — verify the trail yourself instead of trusting a score.\n\n**Response in <100ms** on pre-indexed tokens — every pump.fun graduation is scanned and cached automatically as it happens.\n\n**Free tier: 5 scans/month with no account, or 250/month with a free key (one email).** Then $0.001 per scan — priced at cost (it covers the Helius RPC calls behind each live on-chain trace). Pay by card, in USDC on Solana, or via x402 — same price through every door. $9/month buys unlimited fair-use scans; by card that renews automatically and can be cancelled anytime at [cabal-hunter.com/billing](https://cabal-hunter.com/billing).\n\n---\n\n## Quick Start\n\n### 1. Claude Code / Claude Desktop\n\nAdd to your MCP config (`~/.claude/mcp.json` or project `.mcp.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"cabal-hunter\": {\n      \"url\": \"https://api.cabal-hunter.com/mcp\"\n    }\n  }\n}\n```\n\nThat's it. Claude will now call `check_cabal_risk` automatically when you ask it to analyse a Solana token.\n\n**Example prompt:**\n> \"Before we buy into this token, check if there are any coordinated wallets: `EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v`\"\n\nClaude calls the tool, pays $0.001 USDC from your connected wallet, and returns the full analysis.\n\n---\n\n### 2. Cursor\n\nAdd to `.cursor/mcp.json` in your project root:\n\n```json\n{\n  \"mcpServers\": {\n    \"cabal-hunter\": {\n      \"url\": \"https://api.cabal-hunter.com/mcp\"\n    }\n  }\n}\n```\n\n---\n\n### 3. ElizaOS (with automatic x402 payment)\n\nIf you're using ElizaOS with `@hugen/plugin-x402-solana`, payment is handled automatically. Add to your agent config:\n\n```json\n{\n  \"plugins\": [\"@hugen/plugin-x402-solana\"],\n  \"mcpServers\": {\n    \"cabal-hunter\": {\n      \"url\": \"https://api.cabal-hunter.com/mcp\"\n    }\n  }\n}\n```\n\nYour agent will call `check_cabal_risk(mintAddress)` before any swap and abort if `cabalScore >= 35` or `isControlled === true`.\n\n---\n\n### 4. Direct REST API\n\nFor headless scripts, custom bots, or any language. **The first 5 calls/month are free — no key, no signup.** A free key (one email) raises that to 250/month. Just call it:\n\n```bash\ncurl \"https://api.cabal-hunter.com/api/scan-cabal?mintAddress=YOUR_MINT_ADDRESS\"\n```\n\nYou get the full analysis back immediately, with `free_queries_remaining` so you always know where you stand. Machine-readable contract: [`/openapi.json`](https://api.cabal-hunter.com/openapi.json).\n\nOnce the free tier is used up, calls are $0.001 USDC via x402 — your agent just pays, no billing setup:\n\n**Step 1 — Request analysis (get payment instructions):**\n```bash\ncurl -X POST https://api.cabal-hunter.com/api/scan-cabal \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"mintAddress\": \"YOUR_MINT_ADDRESS\"}'\n```\n\nResponse (HTTP 402):\n```json\n{\n  \"error\": \"payment_required\",\n  \"payment\": {\n    \"recipient\": \"ATYjZ1kWoHWhj74umGJ8wFqUeW1yeSGBbLi1UQpahPxt\",\n    \"amount_usdc\": 0.001,\n    \"memo_required\": \"ch-xxxx-xxxx-xxxx\",\n    \"instructions\": \"Send 0.001 USDC with this memo, then resubmit with X-Payment-Signature header\"\n  }\n}\n```\n\n**Step 2 — Pay & resubmit:**\n```bash\ncurl -X POST https://api.cabal-hunter.com/api/scan-cabal \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-Payment-Signature: YOUR_TX_SIGNATURE\" \\\n  -d '{\"mintAddress\": \"YOUR_MINT_ADDRESS\"}'\n```\n\n**Response (HTTP 200):**\n```json\n{\n  \"mint\": \"YOUR_MINT\",\n  \"token_name\": \"EXAMPLE\",\n  \"risk\": \"HIGH\",\n  \"cabal_score\": 72.4,\n  \"is_controlled\": true,\n  \"time_sync\": true,\n  \"verdict\": \"AVOID — 4 wallets bought in the EXACT same block (bundled launch), controlling 34.1% of supply. DEPLOYER ALERT: this creator has launched 14 tokens, 13 of 13 checked are dead (100%).\",\n  \"coordinated_clusters\": [\n    {\n      \"type\": \"funding\",\n      \"master_full\": \"FvbEKF...9RUg\",\n      \"master_short\": \"FvbEKF…9RUg\",\n      \"wallet_count\": 4,\n      \"combined_pct\": 34.1,\n      \"risk\": \"HIGH\",\n      \"evidence_txs\": [\"4Y8auc5G...\", \"2XQx9LFv...\", \"AAbJ7rej...\"]\n    }\n  ],\n  \"filtered_clusters\": [\n    {\n      \"funder_label\": \"high-volume wallet\",\n      \"master_short\": \"43ViqZ…Z6iy\",\n      \"wallet_count\": 2,\n      \"combined_pct\": 4.4\n    }\n  ],\n  \"deployer\": {\n    \"creator\": \"5TbRN6...full address...\",\n    \"creator_short\": \"5TbRN6…2TGC\",\n    \"tokens_launched\": 14,\n    \"dead\": 13,\n    \"sampled\": 13,\n    \"dead_pct\": 100.0,\n    \"verdict\": \"SERIAL_LAUNCHER\"\n  },\n  \"holders\": [\n    { \"rank\": 1, \"address\": \"...\", \"pct\": 12.4, \"cluster_id\": 0, \"funding_tx\": \"4Y8auc5G...\" }\n  ],\n  \"wallets_checked\": 12,\n  \"analysis_time_ms\": 487,\n  \"source\": \"real_time\"\n}\n```\n\n### 5. Run the MCP server locally (Docker / Node)\n\n**Fastest — no clone needed:** `npx cabal-hunter-mcp` — the same stdio server, published to npm ([cabal-hunter-mcp](https://github.com/paulf280-ui/cabal-hunter-mcp) · [npm](https://www.npmjs.com/package/cabal-hunter-mcp)). Or run it from this repo:\n\nPrefer to run the connector yourself instead of hitting the hosted `/mcp`\nendpoint? This repo ships a thin **stdio MCP server** that exposes\n`check_cabal_risk(mintAddress)` and proxies to the Cabal-Hunter API (free tier\nworks with no key; paid scans use x402 at call time):\n\n```bash\n# Node 18+\nnpm install\nnode server/index.mjs\n\n# or Docker\ndocker build -t cabal-hunter-mcp .\ndocker run -i cabal-hunter-mcp\n```\n\nThen point any MCP client at the local command:\n\n```json\n{\n  \"mcpServers\": {\n    \"cabal-hunter\": {\n      \"command\": \"node\",\n      \"args\": [\"server/index.mjs\"]\n    }\n  }\n}\n```\n\n---\n\n## Integrate into Your Trading Logic\n\n```python\nimport requests\n\ndef is_safe_to_buy(mint_address: str, payment_sig: str) -> bool:\n    \"\"\"Returns True if token passes cabal check.\"\"\"\n    resp = requests.post(\n        \"https://api.cabal-hunter.com/api/scan-cabal\",\n        json={\"mintAddress\": mint_address},\n        headers={\"X-Payment-Signature\": payment_sig}\n    )\n    if resp.status_code != 200:\n        return False  # fail-safe: don't buy on error\n    data = resp.json()\n    # Block on: coordinated control, high score, bundled launch,\n    # or a deployer with a history of dead tokens\n    deployer_verdict = (data.get(\"deployer\") or {}).get(\"verdict\", \"UNKNOWN\")\n    return (\n        not data.get(\"is_controlled\")\n        and data.get(\"cabal_score\", 100) < 35\n        and not data.get(\"time_sync\")\n        and deployer_verdict not in (\"SERIAL_RUGGER\", \"SERIAL_LAUNCHER\", \"POOR_TRACK_RECORD\")\n    )\n\n# In your bot's buy logic:\nif is_safe_to_buy(token_mint, my_payment_sig):\n    execute_swap(token_mint, sol_amount)\nelse:\n    print(f\"Cabal detected — skipping {token_mint}\")\n```\n\n---\n\n## Interactive 3D Holder Map (Free)\n\nSee exactly what the analysis found. Every real holder is a faceted crystal sized by its share of supply; wallets in the same cluster are joined by light beams, and the liquidity pool and locked supply sit apart in a wireframe vault because they cannot be sold. Drag to rotate, hover for the wallet, click through to Solscan:\n\n```\nhttps://api.cabal-hunter.com/map?mint=ANY_SOLANA_MINT\n```\n\nFree to view, in 9 languages. Share this URL when you catch a rug. Every crystal is clickable and links to Solscan for deep-dive research.\n\n---\n\n## Cabal-Hunter everywhere\n\nSame detection engine, wherever your stack lives:\n\n- **`npx cabal-hunter-mcp`** — standalone MCP server for Claude · Cursor · VS Code · any MCP client: [cabal-hunter-mcp](https://github.com/paulf280-ui/cabal-hunter-mcp) · [npm](https://www.npmjs.com/package/cabal-hunter-mcp)\n- **ElizaOS plugin:** `npm i elizaos-plugin-cabal-hunter` — [plugin-cabal-hunter](https://github.com/paulf280-ui/plugin-cabal-hunter) · [npm](https://www.npmjs.com/package/elizaos-plugin-cabal-hunter)\n- **REST API + OpenAPI:** [api.cabal-hunter.com](https://api.cabal-hunter.com) · [/openapi.json](https://api.cabal-hunter.com/openapi.json)\n\n---\n\n## Pricing\n\n**First 5 scans every month are free** — no signup, no API key. A free key (one email) raises that to 250/month.\n\nAfter that, pick whatever matches how hard your bot works (priced at cost — it covers the Helius RPC behind each live on-chain trace):\n\n| Plan | Price | What you get |\n|------|-------|--------------|\n| **Unlimited** ⭐ | $9 USDC / month | Scan all you want — _fair use: 50,000/mo, more than any bot needs_ |\n| **Pay as you go** | $0.001 USDC / scan | Only what you use — prepaid or per-call, no commitment |\n\nPrepaid keys: send USDC once → `POST /api/buy-key` with the tx signature → use header `X-API-Key` on every scan. Or pay per-call via x402 (`X-Payment-Signature` header). No credit card, no account, no lock-in.\n\n**Does it pay for itself?** Work it out with your own numbers rather than ours: the Unlimited tier is $9 a month, so it pays for itself the first time it keeps you out of a position bigger than $9 that goes to zero. Whether that happens once a month or once a week depends on what you trade and how often — we are not going to invent an average for you.\n\nPayment is native on Solana — no credit card, no account, no subscription lock-in.\n\n---\n\n## Live dashboard badge\n\nDrop a live safety badge into your own bot's dashboard — two lines of HTML, and every token shows its verdict as it trades:\n\n```html\n<div class=\"cabal-hunter-badge\" data-mint=\"YOUR_TOKEN_MINT\"></div>\n<script src=\"https://api.cabal-hunter.com/widget.js\" defer></script>\n```\n\nIt renders the 0–100 score, the plain-English verdict, and the active flags (bundled launch, coordinated dump, whale concentration, serial-launcher deployer, honeypot). Add `data-refresh=\"120\"` to re-scan live as you trade, and `data-api-key=\"...\"` once you're past your free scans. Works anywhere — React, plain HTML, any site.\n\n---\n\n## API Reference\n\n| Endpoint | Description | Auth |\n|----------|-------------|------|\n| `POST /api/scan-cabal` | Full cabal analysis | $0.001 USDC |\n| `GET /api/scan-cabal?mintAddress=` | GET version | $0.001 USDC |\n| `GET /map?mint=` | Interactive 3D holder map | Free |\n| `GET /api/cex-funding?mint=` | Per-exchange funding breakdown (which CEXes funded holders, % each) | Free |\n| `GET /api/trade-analysis?mint=` | Cohort PnL (Team/Snipers/Insiders) + wash-trading score + exit-liquidity price impact, one call | Free |\n| `POST /api/watch` | Register an emergency dump webhook for a mint (push on dump/rug start) | Free |\n| `GET /api/info` | Pricing, endpoints | Free |\n\n### Emergency dump webhook (auto-exit)\n\nInstead of polling, let your bot subscribe to a token it holds — we push the moment a coordinated dump or liquidity drain starts:\n\n```bash\ncurl -X POST https://api.cabal-hunter.com/api/watch \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"mint\":\"YOUR_MINT\",\"webhook_url\":\"https://your-bot.com/dump-alert\"}'\n```\n\nYour endpoint receives:\n```json\n{ \"event\":\"dump_detected\", \"mint\":\"...\", \"reason\":\"price −34% since last check\",\n  \"coordinated\": true, \"price_usd\": 0.0001, \"liquidity_usd\": 4200,\n  \"action\":\"consider_immediate_exit\", \"ts\": 1781370000 }\n```\n| `GET /health` | Uptime check | Free |\n| `POST /mcp` | MCP tool endpoint | $0.001 USDC per call |\n\n---\n\n## Infrastructure\n\n- **RPC**: Dedicated Helius node (Frankfurt) — fastest Solana data available\n- **Hosting**: AWS EC2 Frankfurt — low latency for EU/global\n- **Analysis**: Real on-chain data — no scrapers, no caches of cached caches\n- **Uptime**: 99.9% target — monitored, auto-restart via systemd\n\n---\n\n## FAQ\n\n**What is a Solana cabal?**\nA group of wallets — often funded from the same source and buying in the same block — that quietly accumulate a large share of a token's supply before retail, then dump simultaneously into everyone who buys after launch.\n\n**How do I check if a Solana token is a rug?**\nScan the mint with Cabal-Hunter (MCP, REST API, or the free 3D holder map). It traces holder funding back to shared sources, detects same-block bundle buys, flags serial-launcher deployers and live coordinated dumps, and returns an **Exit-Liquidity Risk** verdict: `LOW`, `ELEVATED`, or `HIGH`.\n\n**Is it free?**\nYes — 5 scans/month with no signup or API key, and 250/month with a free key (one email). Beyond that it's $0.001 USDC per scan — which just covers the Helius RPC cost of the live trace — paid natively on Solana.\n\n**Can AI trading agents use it?**\nYes — that's the whole point. The MCP server (`api.cabal-hunter.com/mcp`) lets Claude, Cursor and ElizaOS agents call `check_cabal_risk(mintAddress)` automatically before any swap, and a REST API covers any other language.\n\n---\n\n## License\n\nMIT — fork it, build on it, integrate it. If you build something with this, share it.\n\n---\n\n*Built by [PF Capital](https://api.cabal-hunter.com) · Powered by Helius · Contact: api.cabal-hunter.com/api/info*\n",
  "bytes": 21274,
  "sha": "28d194673608d6db491b3117638f63455d333559caee53c9fdd82125c3d30202",
  "repo_slug": "paulf280-ui/solana-safe-sniper-mcp-template",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_com_cabal_hunter_api_cabal_hunter_a6725dcd/readme"
}