EXTENSIONS
User-built models, drivers, vaults, and reports — the parts that plug into swamp.
Filter by what you need and pull what fits.
Aws Default Sg Audit
Fleet audit for AWS Security Hub control EC2.2 ("VPC default security groups
Aws S3 Bucket Audit
Workflow-scope report that audits S3 buckets against standard security
Discourse
Query Discourse forums via the public REST API. List categories, browse
Threat Model
Agile threat modeling as an agent-guided concept model.
Aws/guardduty
Query and inspect GuardDuty findings from a delegated administrator account,
Aws/securityhub Findings
Query and manage AWS Security Hub findings from a delegated administrator
Shodan
Query the Shodan internet-wide scan database to find and profile internet-exposed devices. Single API key resolved from vault. Read the account plan and remaining credits, run searches that return trimmed device records (IP, org, product, location, open port, CVEs) with facet rollups, count results without spending query credits, pull the full banner history for one IP, do keyless InternetDB lookups (ports, CPEs, tags, CVEs), and request on-demand scans of IPs you own. Built for AV/IoT exposure recon.
Hashicorp Vault
HashiCorp Vault secrets management via REST API (KV v1 and v2)
Trust Network
Inventory and report on OIDC trust policies and workload-identity federation across GitHub, Google Cloud, and Cloudflare One.
Cloudflare
Cloudflare One / Zero Trust Access discovery for swamp.
Cve/mini Shai Hulud
Scans deno.lock and package-lock.json files for npm packages compromised
Cve/dirtyfrag
Detects and mitigates the Dirty Frag Linux local privilege escalation
Azure
Azure infrastructure management via az CLI — 31 model types covering compute, networking, data, security, RBAC, Azure Policy, Defender for Cloud, Entra directory, monitoring, DNS, DevOps, and subscription-wide topology with Mermaid diagrams and cost estimation.
Tailscale
Install Tailscale on remote VMs over SSH and sync tailnet machine inventory from tailscale status JSON into per-machine resources.
Cloudflare Audit
Cloudflare security and configuration audit workflow.
Macos Doctor
Read-only local macOS security, sanity, and performance posture checks with a severity-rated report.
Github
GitHub models for swamp. Currently provides @hivemq/github/token, which audits a single GitHub token.
Mudroom
Run Claude Code (and other workloads) inside a macOS apple/container sandbox.
Mudroom
Run Claude Code (and other workloads) inside a macOS apple/container sandbox.
Github Security
GitHub repository security auditing with support for native features and third-party tool detection
Tailnet Healthcheck
Tailnet health reporting — find devices running outdated Tailscale clients and alert via Slack
Tailscale
Tailscale tailnet management — 10 model types covering devices, users, ACLs, DNS, auth keys, webhooks, settings, contacts, posture, and log config. 22 workflows for device inventory, user lifecycle, ACL audit, security audit, compliance, incident response, monitoring, and more. Fix: OAuth token cache now keys on credentials so different tailnets/OAuth clients no longer share tokens.