Learn-skills.dev blockchain-intelligence-playbook

Index skill for the blockint-skills bundle—includes a “choosing a skill” routing map and routes to focused skills on blockchain intelligence fundamentals, address clustering, analytics, tokenomics, investigation ethics, Phalcon Compliance documentation pointer, Chainalysis public Sanctions API/oracle router, FATF official AML/CFT glossary, Arkham Intel research article on leading crypto analysis tools for traders, Christoph Michel cmichel.io guide on becoming an EVM smart contract auditor, risk exposure, behavioral risk, address and transaction screening workflow concepts, Range AI investigation playbook (MCP), standalone Dune Sim and Dune Analytics on-chain analytics skill (dune-sim-onchain-analytics), crypto market mechanics, OSINT (Bellingcat toolkit), Solana external stacks (Helius, Range MCP, Tavily, PayAI, React Flow, Solana Policy Institute), DeFi/MEV/rug skills, privileged-access mitigation lessons (Chainalysis Drift case study), coral-xyz sealevel-attacks Solana security examples, Neodyme Solana Security Workshop (workshop.neodyme.io), Osec (osec.io) Solana auditor introduction blog post, canonical X post citation for @armaniferrante status 1411589629384355840, BlockchainSpider open-source data collection, MoTS (Know Your Transactions / transaction semantics research repo), Impersonator dApp devtools (EVM + Solana read-only address presentation), Katana web crawling, lcamtuf American Fuzzy Lop (AFL) classic documentation (lcamtuf.coredump.cx/afl), and the official Agent Skills open-format specification (agentskills/agentskills, agentskills.io/llms.txt doc index). Use when the task spans multiple topics or the user needs help picking which named skill to load.

install
source · Clone the upstream repo
git clone https://github.com/NeverSight/learn-skills.dev
Claude Code · Install into ~/.claude/skills/
T=$(mktemp -d) && git clone --depth=1 https://github.com/NeverSight/learn-skills.dev "$T" && mkdir -p ~/.claude/skills && cp -r "$T/data/skills-md/agentic-reserve/blockint-skills/blockchain-intelligence-playbook" ~/.claude/skills/neversight-learn-skills-dev-blockchain-intelligence-playbook && rm -rf "$T"
manifest: data/skills-md/agentic-reserve/blockint-skills/blockchain-intelligence-playbook/SKILL.md
source content

Blockchain intelligence — skill index

This repository splits topics into focused skills (load the specific skill when the task is narrow). Shared rules: educational patterns only; no sanctions evasion, harassment, or non-consensual doxxing; not legal/investment advice.

Choosing a skill (quick map)

If the user is asking about…Start here
Crime types, ethics, reporting, CEX/stablecoin limitscrypto-investigation-compliance
Phalcon Compliance product documentation URLphalcon-compliance-documentation
Chainalysis Sanctions API / public oracle,
Chainalysis.md
chainalysis-sanctions-screening
FATF AML/CFT glossary terms (CDD, STR, PEP, etc.)fatf-glossary-reference
Arkham “leading crypto analysis tools” research / trader tool landscapearkham-leading-crypto-analysis-tools
Becoming an EVM smart contract auditor (cmichel.io guide)cmichel-smart-contract-auditor-guide
Risk indicators, exposure %, address/tx screening templatesrisk-exposure-screening-concepts
Structuring-like frequency, large transfers, transit / rapid movementbehavioral-risk-screening-concepts
Address tags/markers, CSV screening, blacklist vs whitelist UXaddress-screening-workflow-concepts
Transaction hash screening, deposit/withdrawal direction, STR exportstransaction-screening-workflow-concepts
General OSINT tool discovery (non-chain)bellingcat-investigation-toolkit
Dune Sim + Analytics — workflows, multichain realtime vs SQLdune-sim-onchain-analytics
End-to-end on-chain forensics personaon-chain-investigator-agent
Solana txs, ATAs, SPLsolana-tracing-specialist
Helius/Range/Tavily docs, MCP, graph UI (React Flow), x402 (PayAI), Solana policy institutesolana-onchain-intelligence-resources
Range MCP wallet investigation steps, sanctions, transfersrange-ai-investigation-playbook
Solana entity clustering / Jito / launchpadssolana-clustering-advanced
Cross-chain bridges and unified graphscross-chain-clustering-techniques-agent
Broad DeFi audit + rug/governancedefi-security-audit-agent
Admin takeover, blind signing, Solana durable nonces (mitigations)defi-admin-takeover-mitigation-lessons
EVM Solidity contracts (Ethereum/L2)evm-solidity-defi-triage-agent
Solana programs (Anchor, PDAs, CPIs)solana-defi-vulnerability-analyst-agent
Sealevel Attacks repo (Solana exploit pattern examples)sealevel-attacks-solana
Neodyme Solana Security Workshop (workshop.neodyme.io)neodyme-solana-security-workshop
Osec “Solana: An Auditor’s Introduction” (runtime primer)osec-solana-auditor-introduction
@armaniferrante X post
1411589629384355840
(primary-source citation)
armaniferrante-x-status-solana-reference
Honeypot / sell restrictionshoneypot-detection-techniques
Launch rug red flagsrug-pull-pattern-detection-agent
Flash-loan incidentsflash-loan-exploit-investigator-agent
Sandwich MEV post-mortemssandwich-attack-investigator-agent
MEV infrastructure / searchersmev-bot-infrastructure-analysis-agent
MEV + rug overlap hypothesesmev-bot-rug-coordination-investigator-agent
Web crawlingkatana-web-crawling
Classic AFL / lcamtuf fuzzing docs (C/C++ coverage-guided)lcamtuf-afl-documentation
Agent Skills spec / SKILL.md format / agentskills.ioagentskills-specification
Scrapy/Python on-chain datasets, transfer subgraphs (BlockchainSpider)blockchain-spider-toolkit
MoTS / KYT transaction semantics, WWW 2023 paper reproductionmots-transaction-semantics
Impersonator (EVM/Solana dApp connect as any address, dev/testing)impersonator-dapp-devtools

When in doubt, load on-chain-investigator-agent or this index.

Skills in this bundle

SkillUse when
blockchain-intelligence-playbookThis index — routing when multiple domains apply
blockchain-intelligence-fundamentalsWhat BI is, tool categories (explorers, tracers, etc.), payment rails vs crypto rails
address-clustering-attributionWallet clustering (UTXO CIH, EVM deposit sweeps), entities/labels/tags, peel/taint concepts, attribution limits
cross-chain-clustering-techniques-agentMulti-chain clustering: bridges, wrapped assets, unified graphs, timing/behavior, confidence scoring
blockchain-analytics-operationsAnalytics platforms, AML/forensic use cases, tracers/visualizers as product layers
dune-sim-onchain-analyticsStandalone Dune skill — Sim vs SQL, EVM/SVM patterns, CUs, subscriptions; llms.txt + OpenAPI for implementation detail
blockchain-spider-toolkitBlockchainSpider — Python/Scrapy dataset collection (EVM/Solana blocks/txs, transfer subgraphs); not web crawling
mots-transaction-semanticsMoTSKYT / transaction semantic vectors & labels (research); upstream notes merge into BlockchainSpider
impersonator-dapp-devtoolsImpersonator / Solana — WalletConnect-style address presentation for dApp UI testing (no key custody; ethics-heavy)
on-chain-research-tokenomicsHoldings/flows/TVL/whales, tokenomics (supply, vesting, utility)
crypto-investigation-complianceCrime taxonomy, ethical OSINT + on-chain workflow, reporting posture
phalcon-compliance-documentationPhalcon Compliance public documentation portal — compliance investigation / monitoring product docs (read live site for features)
chainalysis-sanctions-screeningChainalysis public Sanctions API + EVM oracle — SDN-oriented address checks; live docs/Terms; optional repo
Chainalysis.md
excerpt
fatf-glossary-referenceFATF Glossary — official AML/CFT definitions; terminology alignment (not legal advice)
arkham-leading-crypto-analysis-toolsArkham researchfundamental / technical / on-chain tool survey for traders (not investment advice)
cmichel-smart-contract-auditor-guidecmichel.ioEVM auditor learning path, CTFs, canonical DeFi patterns, FAQ (2021 article; verify stale facts)
risk-exposure-screening-conceptsRisk exposure vocabulary: indicator taxonomies, exposure value/%, address vs transaction templates (entity, interaction, blacklist) — educational
behavioral-risk-screening-conceptsBehavioral patterns: large-value, high-frequency / structuring-like, transit addresses, rapid-transaction rules — educational
address-screening-workflow-conceptsAddress inventory: tags vs markers, CSV bulk import, list/detail pages, audit/alert views, blacklist/whitelist semantics — educational
transaction-screening-workflow-conceptsTransaction screening: transfer as unit, deposit/withdrawal direction, CSV import, list/detail, rescreen, STR-style export patterns — educational
bellingcat-investigation-toolkitBellingcat OSINT toolkit: GitBook + GitHub catalog for general investigation tool discovery
crypto-market-structuresMax pain, covered-call ETFs, arbitrage, bull/bear flags (non-prescriptive)
on-chain-investigator-agentEnd-to-end forensic investigator persona: tracing, contracts, scam heuristics, evidence reports, ethics
solana-tracing-specialistSolana-only forensics: ATAs, SPL flows, RPC/indexer patterns, Jito/DEX inner ix, evidence packs
solana-onchain-intelligence-resourcesResource router for Solana intel stacks: Helius, Range MCP, Tavily, PayAI x402, React Flow, Solana Foundation skills (
llms.txt
indexes), Solana Policy Institute (policy/education)
range-ai-investigation-playbookRange AI MCP investigation workflow: risk triage, sanctions, connections, transfers, funding source, entities, cross-chain pivot + one-shot prompt
solana-clustering-advancedSolana entity clustering: graphs, Jito/launchpad heuristics, PDAs, ML validation, confidence scoring
solana-clustering-case-study-agentSolana clustering → case studies: narrative, visuals, CSV/query exports, thread or long-form
defi-security-audit-agentDeFi security / rug-risk triage: contracts, liquidity, governance, bridges, severity reports from public data
defi-admin-takeover-mitigation-lessonsPrivileged access failures—signer hygiene, Solana durable nonces, oracle/collateral abuse, monitoring—using Chainalysis Drift analysis as case anchor
evm-solidity-defi-triage-agentEVM Solidity DeFi triage: proxies, oracles, reentrancy, access control (Ethereum / L2)
honeypot-detection-techniquesHoneypot-style risk: EVM/SPL patterns, static review, fork sim, observational heuristics
rug-pull-pattern-detection-agentLaunch rug-risk: liquidity locks/removal, dev/sniper clusters, contract authorities, tiered scores
mev-bot-rug-coordination-investigator-agentMEV + rug overlap: bundle/block co-occurrence, timing, joint flows, confidence-scored hypotheses
flash-loan-exploit-investigator-agentFlash-loan / atomic exploit post-mortems (EVM + Solana): traces, impact, evidence packs, mitigations
sandwich-attack-investigator-agentSandwich / DEX MEV post-mortems: same-block or bundle ordering, victim vs searcher metrics, mitigations
mev-bot-infrastructure-analysis-agentMEV infrastructure: searchers, bundles/builders/relays, strategies, profit paths, centralization metrics (public data)
solana-defi-vulnerability-analyst-agentSolana DeFi program risks: Anchor/PDAs/CPIs, oracles, pools, SPL, safe repro / severity reporting
sealevel-attacks-solanasealevel-attacksAnchor-based exploit / mitigation pattern examples for the Solana VM (educational; defensive use)
neodyme-solana-security-workshopworkshop.neodyme.io / neodyme-breakpoint-workshopSolana security levels, PoC framework, mdBook source (follow site legal notice)
osec-solana-auditor-introductionOsec blogauditor-oriented runtime intro (BPF, accounts, System Program; 2022; verify docs)
armaniferrante-x-status-solana-reference@armaniferrante X post bookmark — open URL for verbatim text; not a spec
katana-web-crawlingProjectDiscovery Katana install, crawl vs headless, scope, rate limits, pipelines
lcamtuf-afl-documentationlcamtuf AFLAmerican Fuzzy Lop classic coverage-guided fuzzing docs (C/C++); compare AFL++ for current fork tooling
agentskills-specificationagentskills/agentskillsAgent Skills open format; llms.txt index → specification.md, integrate-skills.md

Quality checklist (all domains)

  • Separate fact vs inference vs hypothesis
  • Cite sources for claims about entities or legal outcomes
  • Prefer primary docs for ETFs, sanctions, and filings
  • For clustering/attribution, assume probabilistic outputs

When one subdomain clearly dominates the request, prefer loading that named skill directly instead of this index.