EXTENSIONS
Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.
Filter by what you need and pull what fits.
Datadog/security Signals
Datadog Security Signals — signal search, triage, and archiving
Aws/alarm Investigation
CloudWatch alarm investigation and triage model.
Github Issue Lifecycle
GitHub issue lifecycle tracker for swamp. Drives issues from open through
Triage
Cross-provider, approval-gated triage policy, workflows, prompts, and factory definition.
Swamp Club
Narrow, typed Swamp Club Lab issue intake and approved-ripple adapter.
Claude Sessions
Read Claude Code's own session transcripts as swamp data.
Dependabot Sweep
Sweep an owner's repositories for open Dependabot pull requests and split the review queue from the abandoned-repo noise
Swamp Triage
Investigate why any swamp model or workflow is failing, without knowing anything about the domain it automates. Every method and workflow run leaves a @swamp/method-summary or @swamp/workflow-summary report behind as versioned model data, written on failure as well as success — so the full history of a target is already on disk with nothing extra instrumented. `investigate` resolves a target by name at call time, walks that history back to the boundary where it stopped working, and classifies the error into auth / unreachable / timeout / tls / rate_limit / not_found / config, each with a concrete next step. The distinction it exists to make is auth vs unreachable: a remote answering 403 is healthy and rejecting your credential (go to the vault), while a remote that never answers is a network problem (go to the host) — the two read almost identically in a notification and lead opposite ways. Unrecognised errors are reported as `unknown` verbatim rather than filed under a plausible-looking category. Read-only: it reads what previous runs recorded and never invokes the failing target.
Triage Snapshot
Workflow-scope report that renders a one-look snapshot of the