Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
53 results
label:security

B2 Hygiene

@sntxrr/b2-hygiene · v2026.08.06.1

Audit a scanned Backblaze B2 account for hidden-version retention gaps, over-scoped or orphaned application keys, and public buckets. Two reports: a method-scope audit of one b2-account scan, and a workflow-scope companion that joins those findings to @sntxrr/b2/files byte totals so each gap is ranked by what fixing it recovers. Read-only — both analyse resources already written and never call B2.

upd Aug 70 pullsA100/100

Purview

@dougschaefer/purview · v2026.08.05.2

Microsoft Purview compliance-portal RBAC — role groups, their constituent management roles, membership, and the eDiscovery Administrator list, over Security & Compliance PowerShell. Exists because eDiscovery permission is invisible from Entra: Global Administrator maps to OrganizationManagement, which carries Case Management, Compliance Search, Hold and Search And Purge but not Export, Preview, Review, RMS Decrypt or Custodian, so a tenant admin can run a search yet be unable to export a single item. auditPrincipals separates canSearch from canExport and flags eDiscovery Administrators, who can open every case in the tenant. Carries its own credential surface because the compliance endpoint rejects Azure CLI tokens regardless of user.

upd Aug 60 pullsA100/100

Aws/securityhub Findings

@webframp/aws/securityhub-findings · v2026.08.05.1

Query and manage AWS Security Hub findings from a delegated administrator

upd Aug 617 pullsA100/100

Aws/guardduty

@webframp/aws/guardduty · v2026.08.05.1

Read-only observability model for GuardDuty findings. Query and inspect

upd Aug 610 pullsA100/100

Aws/iam

@webframp/aws/iam · v2026.08.05.1

Cross-account IAM observation model for role, user, and policy inventory.

upd Aug 62 pullsA100/100

B2 Key

@sntxrr/b2-key · v2026.08.05.3

Manage a Backblaze B2 application key via the Native API v4 — sync, create, and idempotent delete. The one-shot applicationKey secret is delivered straight to 1Password Connect and never written to a resource snapshot; create fails closed when no destination is configured.

upd Aug 50 pullsA100/100

Azure

@dougschaefer/azure · v2026.08.05.1

Azure infrastructure management via az CLI — 43 model types covering compute, networking, data, security, RBAC, Azure Policy, Defender for Cloud, Entra directory, monitoring, DNS, DevOps, Azure AI Foundry (accounts, model deployments, projects, quota), AI Search, Cosmos DB, PostgreSQL Flexible Server, Static Web Apps, Service Bus, Event Grid, Recovery Services, Log Analytics, subscription-wide topology with Mermaid diagrams and cost estimation, actual-spend cost analysis and waste auditing via Cost Management/Resource Graph/Advisor, and the Azure AI Vision Face REST API for identity-aware room services.

upd Aug 543 pullsA100/100

Hashicorp Vault

@webframp/hashicorp-vault · v2026.07.30.1

HashiCorp Vault secrets management via REST API (KV v1 and v2). Emits OpenTelemetry spans for get, put, and list, with one child span per request in the recursive list walk, so vault reads are visible in traces including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and KV version only — never secret values, tokens, or error messages.

upd Jul 3152 pullsA100/100

Macos Keychain

@webframp/macos-keychain · v2026.07.30.1

macOS Keychain vault using the security CLI. Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and keychain service only — never secret values, argv, or error messages.

upd Jul 3048 pullsA100/100

Github

@hivemq/github · v2026.07.30.1785404499

GitHub models for swamp.

upd Jul 3050 pullsB85/100

Cloudflare/rulesets

@webframp/cloudflare/rulesets · v2026.07.27.1

Cloudflare Rulesets — WAF custom rules, transform rules, managed rulesets

upd Jul 270 pullsA100/100

Datadog/rbac

@figura/datadog/rbac · v2026.07.24.3

Datadog RBAC — role, permission, user, and restriction query analysis via the Datadog RBAC API (v2). Answers "who can access what data?" by resolving the full chain: user → roles → permissions + restriction queries → effective access. Supports all Datadog sites (us1, us3, us5, eu1, ap1, us1-fed).

upd Jul 240 pullsA100/100

Cloudflare Audit

@webframp/cloudflare-audit · v2026.07.24.1

Cloudflare security and configuration audit workflow.

upd Jul 2498 pullsA100/100

Nmap

@jeremy/nmap · v2026.07.23.2

Network scanning with nmap, stored as structured data for change tracking over time. Produces host and port resources keyed by IP and port number, so consecutive scans naturally version and diff via the swamp data model.

upd Jul 241 pullsA100/100

Base Images

@hivemq/base-images · v2026.07.22.1784718348

A declared fleet of base OCI images we keep security-patched. The whole job — what to patch (`source` = registry/repository/tag), how (`patch`, default: apply all pending security updates), where to publish (`destination` = repository/tag under a run-time `registry`), and what to assert (`expect`, optional version floor) — lives in the model instance's `globalArguments.images`, so a single `swamp model method run <instance> patch --input registry=<registry[/namespace]>` builds, verifies, and pushes every image. The destination registry is the `registry` arg (or `globalArguments.registry`), so one instance retargets to a different registry per run. No workflow. Verify is foreknowledge-free (asserts no security updates remain pending on every platform), which fits a scheduled cadence; an optional per-image `expect` adds a version floor. Composes the pure logic of @hivemq/oci/image/patch and the buildx wrapper of @hivemq/docker; it is the only one of the three that drives buildx. Motivated by PLT-941 (openssl CVE-2026-45447): own the patch cadence instead of waiting on upstream base rebuilds.

upd Jul 2268 pullsD50/100

Unifi Networks

@shrug/unifi-networks · v2026.07.22.1

Query UniFi Network sites via the official integration API — VLANs, firewall

upd Jul 222 pullsA100/100

Snyk/issues

@webframp/snyk/issues · v2026.07.20.1

Snyk Issues — vulnerability issues across projects and groups

upd Jul 200 pullsA100/100

Datadog/security Rules

@webframp/datadog/security-rules · v2026.07.20.11

Datadog Security Rules — detection rule CRUD and management

upd Jul 200 pullsA100/100

Datadog/security Signals

@webframp/datadog/security-signals · v2026.07.20.11

Datadog Security Signals — signal search, triage, and archiving

upd Jul 200 pullsA100/100

Datadog/security Suppressions

@webframp/datadog/security-suppressions · v2026.07.20.11

Datadog Security Suppressions — suppression rule management

upd Jul 200 pullsA100/100

Aws Default Sg Audit

@jentz/aws-default-sg-audit · v2026.07.20.1

Fleet audit for AWS Security Hub control EC2.2 ("VPC default security groups

upd Jul 207 pullsA100/100

Snyk/projects

@webframp/snyk/projects · v2026.07.19.1

Snyk Projects — project listing, attributes, relationships, and target management

upd Jul 200 pullsA100/100

Snyk/sast

@webframp/snyk/sast · v2026.07.19.1

Snyk SAST — static application security testing results and management

upd Jul 200 pullsA100/100

Snyk/policies

@webframp/snyk/policies · v2026.07.19.1

Snyk Policies — security policy management and rule configuration

upd Jul 200 pullsA100/100