Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
26 results
label:audit

Cloudflare Audit

@webframp/cloudflare-audit · v2026.08.21.1

Cloudflare security and configuration audit workflow.

upd Aug 2298 pullsA100/100

Aws Cost Audit

@webframp/aws-cost-audit · v2026.08.21.1

AWS cost audit workflow — identifies infrastructure waste by combining

upd Aug 2230 pullsA100/100

Anthropic/compliance

@webframp/anthropic/compliance · v2026.08.21.2

Observe a Claude Enterprise account via the Compliance API. Covers the

upd Aug 229 pullsA100/100

Restic Readiness

@sntxrr/restic-readiness · v2026.08.19.1

Rank a restic fleet by what has actually been proven restorable. A workflow-scope report that joins every @sntxrr/restic/repository step in a run — freshness, structural check, read-data verification, canary dump and restore drill — into one ranked findings list, where a rung that has never run is itself a finding. Read-only: it reads what the steps already wrote and never touches a repository.

upd Aug 197 pullsA100/100

Rust Security Catalog

@dieter/rust-security-catalog · v2026.08.19.1

Content-bound Rust security review decisions with exact reuse and conservative incremental-review planning.

upd Aug 190 pullsA100/100

Purview

@dougschaefer/purview · v2026.08.11.1

Microsoft Purview compliance-portal RBAC — role groups, their constituent management roles, membership, and the eDiscovery Administrator list, over Security & Compliance PowerShell. Exists because eDiscovery permission is invisible from Entra: Global Administrator maps to OrganizationManagement, which carries Case Management, Compliance Search, Hold and Search And Purge but not Export, Preview, Review, RMS Decrypt or Custodian, so a tenant admin can run a search yet be unable to export a single item. auditPrincipals separates canSearch from canExport and flags eDiscovery Administrators, who can open every case in the tenant. Carries its own credential surface because the compliance endpoint rejects Azure CLI tokens regardless of user.

upd Aug 110 pullsA100/100

B2 Hygiene

@sntxrr/b2-hygiene · v2026.08.06.1

Audit a scanned Backblaze B2 account for hidden-version retention gaps, over-scoped or orphaned application keys, and public buckets. Two reports: a method-scope audit of one b2-account scan, and a workflow-scope companion that joins those findings to @sntxrr/b2/files byte totals so each gap is ranked by what fixing it recovers. Read-only — both analyse resources already written and never call B2.

upd Aug 70 pullsA100/100

B2 Account

@sntxrr/b2-account · v2026.08.05.1

Inventory a Backblaze B2 account — one read-only scan method emits a resource per bucket and per application key, plus a summary, via the B2 Native API v4.

upd Aug 50 pullsA100/100

Audit Timeline

@jentz/audit-timeline · v2026.07.30.1

Workflow-scope report that renders a change-audit timeline from CloudWatch

upd Jul 316 pullsA100/100

Github

@hivemq/github · v2026.07.30.1785404499

GitHub models for swamp.

upd Jul 3067 pullsB85/100

Coder Audit Collector

@twonines/coder-audit-collector · v2026.07.20.1

Pages through the Coder audit log API and writes events as versioned data. Supports incremental collection with configurable limits and query filters.

upd Jul 200 pullsA100/100

Software Factory Run Audit

@mgreten/software-factory-run-audit · v2026.07.20.1

Deterministic run reconstruction and invariant-violation audit of a @swamp/software-factory work item — stale SHAs across the artifact lineage, impossible states, unresolved critical/high blockers, and retained resources — rendered statically from recorded run data with no LLM involved, every flag traceable to the record it came from. Optional retained-worktree and external issue-tracker (Linear) correlation joins are pluggable, not required.

upd Jul 206 pullsA100/100

Aws Vpc Inventory

@jentz/aws-vpc-inventory · v2026.07.20.1

Fleet-wide VPC inventory across `profiles × regions`. A single read-only

upd Jul 208 pullsA100/100

Aws Default Sg Audit

@jentz/aws-default-sg-audit · v2026.07.20.1

Fleet audit for AWS Security Hub control EC2.2 ("VPC default security groups

upd Jul 207 pullsA100/100

Aws Iam Role Audit

@jentz/aws-iam-role-audit · v2026.07.20.1

Read-only fleet IAM lens for an integration's roles across many accounts. A

upd Jul 205 pullsA100/100

Aws Rds Inventory

@jentz/aws-rds-inventory · v2026.07.20.1

Lists RDS DB clusters in the configured AWS region and emits two

upd Jul 2013 pullsA100/100

Aws Default Sg Audit Report

@jentz/aws-default-sg-audit-report · v2026.07.20.1

Workflow-scope report that renders an operator worklist for AWS Security Hub

upd Jul 203 pullsA100/100

Aws Stackset Audit

@jentz/aws-stackset-audit · v2026.07.19.0

Read-only operational audit of a CloudFormation StackSet and all of its stack

upd Jul 194 pullsA100/100

Aws Context Guard

@jentz/aws-context-guard · v2026.07.19.0

Generic AWS workflow-safety primitive. Fails closed before any AWS work

upd Jul 1940 pullsA100/100

Aws S3 Bucket Audit

@jentz/aws-s3-bucket-audit · v2026.07.19.0

Workflow-scope report that audits S3 buckets against standard security

upd Jul 1916 pullsA100/100

Dry Run

@webframp/dry-run · v2026.07.18.1

Dry-run execution driver that captures method requests without executing them. Useful for debugging, auditing, and validating workflows.

upd Jul 187 pullsA100/100

Aws Integration Coverage

@jentz/aws-integration-coverage · v2026.06.26.1

Coalesces a CloudFormation StackSet lens (@jentz/aws-stackset-audit) and an

upd Jun 272 pullsA100/100

Customerio

@goodcraft/customerio · v2026.06.14.2

Customer.io App API — snapshot segments and transactional messages, and run an idempotent per-brand readiness audit (segments + transactional messages) for a shared workspace.

upd Jun 143 pullsA100/100

Syscheck

@stateless/syscheck · v2026.06.12.2

Fleet node verification framework. A catalog of tagged checks (category × cadence × scope) contributed by domains — host-OS/apt hygiene & fitness over scripts/host-probe.sh, plus a proxmox provider for PVE-scoped checks — run by the syscheck workflow and scored into a per-node pass/warn/fail verdict. Domains (proxmox, future @stateless/docker, …) plug in via a CheckProvider contract. Sits above the domains; results belong in @stateless/inventory.

upd Jun 123 pullsA92/100