Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
9 results
label:triage

Datadog/security Signals

@webframp/datadog/security-signals · v2026.09.15.1

Datadog Security Signals — signal search, triage, and archiving

upd Sep 151 pullsA100/100

Aws/alarm Investigation

@webframp/aws/alarm-investigation · v2026.09.15.1

CloudWatch alarm investigation and triage model.

upd Sep 1513 pullsA100/100

Github Issue Lifecycle

@webframp/github-issue-lifecycle · v2026.09.15.1

GitHub issue lifecycle tracker for swamp. Drives issues from open through

upd Sep 15180 pullsA100/100

Triage

@webframp/triage · v2026.09.15.1

Cross-provider, approval-gated triage policy, workflows, prompts, and factory definition.

upd Sep 150 pullsA100/100

Swamp Club

@webframp/swamp-club · v2026.09.15.1

Narrow, typed Swamp Club Lab issue intake and approved-ripple adapter.

upd Sep 150 pullsA100/100

Claude Sessions

@magistr/claude-sessions · v2026.07.19.2

Read Claude Code's own session transcripts as swamp data.

upd Aug 191 pullsA100/100

Dependabot Sweep

@sntxrr/dependabot-sweep · v2026.08.13.1

Sweep an owner's repositories for open Dependabot pull requests and split the review queue from the abandoned-repo noise

upd Aug 1314 pullsA100/100

Swamp Triage

@sntxrr/swamp-triage · v2026.08.04.4

Investigate why any swamp model or workflow is failing, without knowing anything about the domain it automates. Every method and workflow run leaves a @swamp/method-summary or @swamp/workflow-summary report behind as versioned model data, written on failure as well as success — so the full history of a target is already on disk with nothing extra instrumented. `investigate` resolves a target by name at call time, walks that history back to the boundary where it stopped working, and classifies the error into auth / unreachable / timeout / tls / rate_limit / not_found / config, each with a concrete next step. The distinction it exists to make is auth vs unreachable: a remote answering 403 is healthy and rejecting your credential (go to the vault), while a remote that never answers is a network problem (go to the host) — the two read almost identically in a notification and lead opposite ways. Unrecognised errors are reported as `unknown` verbatim rather than filed under a plausible-looking category. Read-only: it reads what previous runs recorded and never invokes the failing target.

upd Aug 522 pullsA100/100

Triage Snapshot

@jentz/triage-snapshot · v2026.07.31.0

Workflow-scope report that renders a one-look snapshot of the

upd Jul 312 pullsA100/100