EXTENSIONS
Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.
Filter by what you need and pull what fits.
Container Verification
Docker verification with structured read-only source mounts, cancellation protection, and retained evidence. Reuses the official container-image runner.
Claimbook
Breach-claim ledger and verification state machine on DuckDB. Files claims with asserted levels (L0 rumor → L5 published), attaches sha256-attributed evidence, reconciles asserted dump profiles against observed inventories, records public statements, tracks onion watch-state diffs, and emits verification reports. Persistence layer of the breach-verification bench.
Syscheck
Fleet node verification framework. A catalog of tagged checks (category × cadence × scope) contributed by domains — host-OS/apt hygiene & fitness over scripts/host-probe.sh, plus a proxmox provider for PVE-scoped checks — run by the syscheck workflow and scored into a per-node pass/warn/fail verdict. Domains (proxmox, future @stateless/docker, …) plug in via a CheckProvider contract. Sits above the domains; results belong in @stateless/inventory.