Agent skill

Sybil Detection

by agiprolabs in agiprolabs/claude-trading-skills

Coordinated wallet cluster detection, wash trading identification, and fake activity analysis for Solana tokens

MITAuto-check passedBusiness, Finance & HR

Install Sybil Detection

skills CLI
$ npx skills add agiprolabs/claude-trading-skills --skill sybil-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agiprolabs/claude-trading-skills sybil-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agiprolabs/claude-trading-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sybil-detection .claude/skills/sybil-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sybil-detection
GitHub stars
410
Token cost
~2.6k tokens
SKILL.md length
579 words
Files
5 (incl. scripts, references)
Skills in repo
68
Repo updated
First seen
Licence
MIT

At a glance

Coordinated wallet cluster detection, wash trading identification, and fake activity analysis for Solana tokens

  • Works in 5 steps: Funding Source Analysis → Co-Trading Patterns → Bundled Transactions → …
  • Tasks that involve Trading and backtesting
  • SKILL.md covers Why Sybil Detection Matters, Detection Categories, Key Metrics and Composite Risk Score, plus 4 more sections
  • Runs Python scripts from its folder; reaches api.helius.xyz

What it does

Sybil Detection is an agent skill from agiprolabs/claude-trading-skills. Coordinated wallet cluster detection, wash trading identification, and fake activity analysis for Solana tokens

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/bundler_detection.md`, `references/clustering_methods.md` and `scripts/detect_sybils.py`).

It sits in Business, Finance & HR, covering Trading and backtesting. It works with Solana. The repository describes itself as: 68 trading, DeFi, and quantitative finance Agent Skills. Works with Claude Code, Cursor, Codex, Gemini CLI, and 30+ other tools. The licence is MIT.

When your agent uses it

  • Tasks that involve Trading and backtesting

Example prompts

  • “/sybil-detection”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Funding Source Analysis
  2. Co-Trading Patterns
  3. Bundled Transactions
  4. Wash Trading Detection
  5. Creator Network Analysis

What it can do on your machine

Read from SKILL.md and the folder at commit 981e1d7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.helius.xyz

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sybil Detection loads about 2.6k tokens when it runs, and up to ~7.2k if it reads all its reference files. Until then it costs about 32 tokens; SKILL.md has 579 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from agiprolabs/claude-trading-skills at commit 981e1d7, republished under its MIT licence (© agiprolabs). 579 words, ~2,581 tokens.

Download SKILL.mdSave it as .claude/skills/sybil-detection/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
sybil-detection
description
Coordinated wallet cluster detection, wash trading identification, and fake activity analysis for Solana tokens

Sybil Detection — Coordinated Wallet & Fake Activity Analysis

Sybil attacks in Solana token markets involve a single entity operating many wallets to create the illusion of organic activity. This skill covers detecting coordinated wallet clusters, wash trading, bundled transactions, and fake holder inflation — critical for evaluating whether a token's metrics reflect real demand or manufactured signals.

Why Sybil Detection Matters

Token markets on Solana are rife with manufactured signals:

  • Inflated holder counts: 500 "holders" that are really 10 entities with 50 wallets each
  • Fake volume: Wash trading between self-controlled wallets to simulate demand
  • Artificial social proof: Many wallets holding small amounts to appear broadly distributed
  • Rug preparation: Creator distributes supply across many wallets, then sells coordinated
  • Bundled launches: PumpFun tokens where creator buys via Jito bundle in first slot

A token showing 1,000 holders with 80% funded from 3 wallets is fundamentally different from one with 1,000 independently-funded holders. Sybil detection separates real demand from theater.

Detection Categories

1. Funding Source Analysis

Trace each holder wallet back 1-2 hops to find who sent them SOL:

python
import httpx

def trace_funding_source(wallet: str, api_key: str, max_hops: int = 2) -> list[str]:
    """Trace SOL funding sources for a wallet via Helius parsed transactions."""
    url = f"https://api.helius.xyz/v0/addresses/{wallet}/transactions"
    resp = httpx.get(url, params={"api-key": api_key, "type": "TRANSFER", "limit": 50})
    transfers = resp.json()

    funders = []
    for tx in transfers:
        for transfer in tx.get("nativeTransfers", []):
            if transfer["toUserAccount"] == wallet and transfer["amount"] > 0.001 * 1e9:
                funders.append(transfer["fromUserAccount"])
    return funders

Key signals:

  • 3+ holder wallets funded from the same source = cluster
  • Funding within 24h of token creation = high suspicion
  • Funding amounts are identical (e.g., 0.05 SOL to each) = automated distribution
2. Co-Trading Patterns

Wallets that buy the same token at nearly the same time are likely coordinated:

python
def detect_co_trades(buy_events: list[dict], slot_window: int = 3) -> list[list[str]]:
    """Group wallets that bought within the same slot window."""
    buy_events.sort(key=lambda x: x["slot"])
    clusters = []
    current_cluster = [buy_events[0]]

    for i in range(1, len(buy_events)):
        if buy_events[i]["slot"] - current_cluster[0]["slot"] <= slot_window:
            current_cluster.append(buy_events[i])
        else:
            if len(current_cluster) >= 3:
                clusters.append([b["wallet"] for b in current_cluster])
            current_cluster = [buy_events[i]]

    if len(current_cluster) >= 3:
        clusters.append([b["wallet"] for b in current_cluster])
    return clusters

Interpretation:

  • Same slot, different transactions = coordinated (bot-driven)
  • Same transaction = bundled (definite sybil)
  • First 3 slots after token creation = launch sniping cluster
3. Bundled Transactions

Multiple buys packed into a single Solana transaction or Jito bundle:

python
def check_bundle_ratio(early_buys: list[dict], bundle_window_slots: int = 5) -> dict:
    """Calculate the ratio of bundled vs independent early buys."""
    bundled = [b for b in early_buys if b.get("is_bundled", False)]
    first_slot = min(b["slot"] for b in early_buys) if early_buys else 0
    early = [b for b in early_buys if b["slot"] - first_slot <= bundle_window_slots]

    return {
        "total_early_buys": len(early),
        "bundled_buys": len(bundled),
        "bundle_ratio": len(bundled) / max(len(early), 1),
        "bundled_supply_pct": sum(b["amount"] for b in bundled) / max(sum(b["amount"] for b in early), 1),
    }

See references/bundler_detection.md for PumpFun-specific patterns and Jito bundle mechanics.

4. Wash Trading Detection

Same entity buying and selling through multiple wallets to inflate volume:

Signals:

  • Wallet A buys token, transfers to Wallet B, Wallet B sells — circular flow
  • Multiple wallets trading back and forth with no net position change
  • Volume concentrated in wallet pairs with funding links
python
def detect_wash_cycles(transfers: list[dict], holder_set: set[str]) -> list[tuple]:
    """Find circular transfer patterns among known holders."""
    # Build directed graph of transfers between holders
    edges: dict[tuple, float] = {}
    for t in transfers:
        if t["from"] in holder_set and t["to"] in holder_set:
            key = (t["from"], t["to"])
            edges[key] = edges.get(key, 0) + t["amount"]

    # Find reciprocal pairs (A->B and B->A both exist)
    wash_pairs = []
    for (a, b), vol_ab in edges.items():
        vol_ba = edges.get((b, a), 0)
        if vol_ba > 0:
            wash_pairs.append((a, b, vol_ab, vol_ba))
    return wash_pairs
5. Creator Network Analysis

Identify wallets controlled by the token creator:

  • Creator wallet's funding history reveals other wallets it funded
  • Those wallets holding token supply = insider distribution
  • Creator selling from "different" wallets = disguised dump
Show full SKILL.md (232 more words)Show less

Key Metrics

MetricFormulaHealthySuspiciousCritical
Unique funder ratiounique_funders / total_holders> 0.80.4-0.8< 0.4
Funding cluster sizemax(cluster_sizes)< 55-20> 20
Co-trade scorewallets_in_first_3_slots / total_holders< 0.10.1-0.3> 0.3
Bundle ratiobundled_buys / total_early_buys< 0.10.1-0.4> 0.4
Bundled supply %bundled_token_amount / total_supply_sold< 5%5-20%> 20%
Transfer densityinternal_transfers / total_transfers< 0.10.1-0.3> 0.3
Wash trade pairsreciprocal_pairs / total_holder_pairs01-3 pairs> 3 pairs

Composite Risk Score

Combine individual signals into a single sybil risk score (0-100):

python
def compute_sybil_score(metrics: dict) -> dict:
    """Compute composite sybil risk score from individual metrics."""
    weights = {
        "funding_cluster": 25,    # Wallets from same funder
        "co_trade": 20,           # Coordinated buy timing
        "bundle_ratio": 20,       # Bundled early transactions
        "unique_funder": 15,      # Diversity of funding sources
        "transfer_density": 10,   # Internal transfers between holders
        "wash_trade": 10,         # Circular trading patterns
    }

    scores = {}
    # Each sub-score normalized to 0-1, then weighted
    scores["funding_cluster"] = min(metrics.get("max_cluster_size", 0) / 20, 1.0)
    scores["co_trade"] = min(metrics.get("co_trade_pct", 0) / 0.3, 1.0)
    scores["bundle_ratio"] = min(metrics.get("bundle_ratio", 0) / 0.5, 1.0)
    scores["unique_funder"] = 1.0 - min(metrics.get("unique_funder_ratio", 1.0), 1.0)
    scores["transfer_density"] = min(metrics.get("transfer_density", 0) / 0.3, 1.0)
    scores["wash_trade"] = min(metrics.get("wash_pairs", 0) / 5, 1.0)

    composite = sum(scores[k] * weights[k] for k in weights)
    risk_level = "LOW" if composite < 30 else "MEDIUM" if composite < 60 else "HIGH"

    return {"score": round(composite, 1), "risk_level": risk_level, "components": scores}

Data Sources

SourceWhat It ProvidesAuth Required
Helius parsed transactionsFunding history, transfer details, parsed instruction dataAPI key (free tier: 30 req/s)
SolanaTracker APIBundler detection, holder lists, token metadataAPI key
Solana RPC (getSignaturesForAddress)Raw transaction signatures for any walletRPC URL
Solana RPC (getTokenLargestAccounts)Top holders by balanceRPC URL
DexScreenerBasic token/pair data for cross-referencingNone

Workflow: Evaluate a Token

python
# 1. Get top holders
holders = get_top_holders(token_mint, rpc_url)

# 2. Trace funding sources for each holder
funding_map = {}
for wallet in holders[:30]:  # Top 30 is usually sufficient
    funding_map[wallet] = trace_funding_source(wallet, helius_key)

# 3. Cluster by common funder
clusters = cluster_by_funder(funding_map)

# 4. Check co-trade timing
early_buys = get_early_buy_events(token_mint, helius_key)
co_trade_groups = detect_co_trades(early_buys)

# 5. Check for bundles
bundle_stats = check_bundle_ratio(early_buys)

# 6. Check wash trading
transfers = get_token_transfers(token_mint, helius_key)
wash_pairs = detect_wash_cycles(transfers, set(holders))

# 7. Compute composite score
metrics = {
    "max_cluster_size": max(len(c) for c in clusters) if clusters else 0,
    "co_trade_pct": sum(len(g) for g in co_trade_groups) / len(holders),
    "bundle_ratio": bundle_stats["bundle_ratio"],
    "unique_funder_ratio": len(set(f for fs in funding_map.values() for f in fs)) / len(holders),
    "transfer_density": len(wash_pairs) / max(len(holders), 1),
    "wash_pairs": len(wash_pairs),
}
result = compute_sybil_score(metrics)
print(f"Sybil Risk: {result['risk_level']} ({result['score']}/100)")

Integration with Other Skills

  • token-holder-analysis: Use holder list as input; sybil detection adds cluster context
  • helius-api: Primary data source for parsed transaction history
  • jito-bundles: Detailed bundle detection and MEV context
  • liquidity-analysis: Combine with sybil score — low liquidity + high sybil = extreme risk
  • whale-tracking: Distinguish real whales from sybil cluster aggregates

Files

FileDescription
references/clustering_methods.mdFunding source clustering, co-trade timing analysis, graph-based detection methods
references/bundler_detection.mdBundled transaction detection, PumpFun patterns, Jito bundle mechanics
scripts/detect_sybils.pyFull sybil detection pipeline: holders -> funding -> clusters -> risk score
scripts/funding_tracer.pyTrace funding sources for a set of wallets, group by common ancestor

© agiprolabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/sybil-detection of agiprolabs/claude-trading-skills.

  • SKILL.md
  • references/bundler_detection.md
  • references/clustering_methods.md
  • scripts/detect_sybils.py
  • scripts/funding_tracer.py

Open the folder on GitHubat commit 981e1d7

Compare with similar skills

Sybil Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sybil Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sybil Detection this skillagiprolabs/claude-trading-skills410—~2.6kAutomated safety check: PassMIT
Prismirfndi/prism-liquidity-agent123—~1.5kAutomated safety check: PassMIT
Solana Sniper Botnpc-live/clawfirm156—~913Automated safety check: NotesNone
Solana Payments Wallets Tradingnpc-live/clawfirm1561 repos~4.7kAutomated safety check: PassMIT
Gmgn PortfolioGMGNAI/gmgn-skills607—~5.8kAutomated safety check: NotesMIT
Trading Signalbinance/binance-skills-hub1.1k—~682Automated safety check: PassNone

Similar skills

  • Prism

    irfndi/prism-liquidity-agent

    Operate Prism, an autonomous Solana DLMM liquidity agent for Meteora pools.

    123 GitHub stars~1.5k tokensUpdated 11 days ago
    Business, Finance & HRAuto-check passed
  • Solana Sniper Bot

    npc-live/clawfirm

    Autonomous Solana token sniper and trading bot. An agent skill from npc-live/clawfirm.

    156 GitHub stars~913 tokensUpdated 3 mo ago
    Business, Finance & HRAuto-check: notes
  • Pay people in SOL or USDC, buy and sell tokens, check prices, discover trending and new tokens, create and manage Solana wallets, stake SOL, earn yield through lending and managed vaults, borrow…

    156 GitHub starsUsed in 1 repo~4.7k tokens
    Business, Finance & HRAuto-check passed
  • Gmgn Portfolio

    GMGNAI/gmgn-skills

    Analyze one or many crypto wallets by address — holdings, batch realized/unrealized P&L, win rate, trading history, performance stats, specific token balance, and tokens created by a developer…

    607 GitHub stars~5.8k tokensUpdated 11 days ago
    Business, Finance & HRAuto-check: notes
  • Trading Signal

    binance/binance-skills-hub

    Per-trade smart-money signals — each result is a discrete buy or sell event from a tracked smart-money wallet, with trigger price, current price, max gain since trigger, and exit rate.

    1.1k GitHub stars~682 tokensUpdated 28 days ago
    Business, Finance & HRAuto-check passed
  • Bags

    alsk1992/CloddsBot

    Bags.fm - Complete Solana token launchpad with creator monetization

    2.9k GitHub stars~864 tokensUpdated 7 days ago
    Business, Finance & HRAuto-check passed

More from agiprolabs/claude-trading-skills

All 68 skills in this repo
  • Backtrader

    agiprolabs/claude-trading-skills

    Event-driven backtesting with bar-by-bar execution, complex order types, multiple analyzers, and custom indicators

    410 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Birdeye API

    agiprolabs/claude-trading-skills

    Solana token market data via Birdeye — prices, OHLCV, trades, token metadata, security checks, and trader activity

    410 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Coingecko API

    agiprolabs/claude-trading-skills

    Broad crypto market data from CoinGecko covering 13,000+ tokens.

    410 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Cointegration Analysis

    agiprolabs/claude-trading-skills

    Cointegration testing for pairs trading using Engle-Granger, Johansen, and rolling stability analysis

    410 GitHub stars~2.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Copy Trading

    agiprolabs/claude-trading-skills

    Wallet evaluation, monitoring, and copy-trade strategy design for Solana DEX trading

    410 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Correlation Analysis

    agiprolabs/claude-trading-skills

    Cross-asset correlation analysis including rolling correlation, hierarchical clustering, tail dependence, and regime-dependent correlation

    410 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Sybil Detection

What does Sybil Detection do?

Coordinated wallet cluster detection, wash trading identification, and fake activity analysis for Solana tokens. Sybil Detection is an agent skill from agiprolabs/claude-trading-skills.

When should I use Sybil Detection?

Sybil Detection fits situations like: tasks that involve Trading and backtesting.

How do I install Sybil Detection in Claude Code?

Run `npx skills add agiprolabs/claude-trading-skills --skill sybil-detection -a claude-code`. Or copy the skill folder (skills/sybil-detection in agiprolabs/claude-trading-skills) into .claude/skills/sybil-detection in your project. Claude Code loads it when a task matches its description.

How do I install Sybil Detection in Codex?

Run `npx skills add agiprolabs/claude-trading-skills --skill sybil-detection -a codex`. Or copy the skill folder (skills/sybil-detection in agiprolabs/claude-trading-skills) into .agents/skills/sybil-detection in your project. Codex loads it when a task matches its description.

Can I use Sybil Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agiprolabs/claude-trading-skills --skill sybil-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sybil-detection, .gemini/skills/sybil-detection, .github/skills/sybil-detection and .opencode/skills/sybil-detection in your project.

What does Sybil Detection need to run?

Going by SKILL.md and its folder, Sybil Detection needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Sybil Detection access the network?

SKILL.md names 1 domain. In commands or code: api.helius.xyz; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Sybil Detection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sybil Detection use?

Sybil Detection is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sybil Detection use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.

What are the alternatives to Sybil Detection?

Skills that share tags, products or a category with Sybil Detection: Prism (irfndi/prism-liquidity-agent, 123 stars), Solana Sniper Bot (npc-live/clawfirm, 156 stars), Solana Payments Wallets Trading (npc-live/clawfirm, 156 stars) and Gmgn Portfolio (GMGNAI/gmgn-skills, 607 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sybil Detection?

agiprolabs (a GitHub user) maintains it in agiprolabs/claude-trading-skills, which has 410 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on September 3, 2026.

Source: agiprolabs/claude-trading-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.