EXTENSIONS
Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.
Filter by what you need and pull what fits.
N8n
Read a running n8n deployment and report how far its pinned version has drifted behind the channel n8n itself calls stable, and which active workflows have no usable error workflow attached. All three methods are strictly read-only — this extension never upgrades n8n, edits a workflow, touches a credential, or restarts a container; it tells you an update exists and stops there. `audit_error_workflows` takes an optional n8n API key (used by no other method), because n8n has no instance-wide default error workflow and only the authenticated public API discloses each workflow's `settings.errorWorkflow`; it flags missing or wrong handlers and a handler that is inactive or archived, and never attaches one. `drift` takes the running version as an argument rather than reading it, because n8n does not disclose one: its `/rest/settings` answers 200 unauthenticated but with `settingsMode: public`, a reduced payload carrying no version field at all, and `versionCli` reaches authenticated callers only — so the version comes from the pinned image tag on the host, which is what the deployment actually is rather than what a process predating the current pin believes itself to be. The upgrade target is npm's dist-tag, never the newest published release: n8n ships its in-progress minor into the same GitHub release namespace flagged `prerelease: true` and promotes that line later, so on 2026-09-05 the newest release was 2.38.3 while stable was 2.37.10, and the 2.37 line had itself been prerelease through 2.37.6. GitHub releases are still read, but only to enumerate the stable releases that were missed and to link the notes, since the `prerelease` flag is the historical record of which line was stable when and dist-tags do not retain it. Image existence is verified against `registry-1.docker.io` rather than the `docker.n8n.io` mirror the pin names: that mirror 404s its own token endpoint, delegates auth to Docker Hub, and then answers 429 to every manifest request for tags that exist and tags that do not alike, so it cannot return a usable answer — and a 429 is raised as indeterminate rather than folded into `absent`, which would suppress every update forever while the check looked healthy. An exhausted GitHub rate limit, an unreachable registry, and an unparseable running version are all raised as errors rather than reported as a reassuring `current`.
Redmine Story Status
Read-only workflow for evidence-backed Redmine Story status analysis.
Aws Ops
AWS Operations Toolkit - Unified incident investigation and daily operational visibility.
Ai Usage
Unified cross-provider AI token usage monitoring — workflow, model, and
Aws Cost Audit
AWS cost audit workflow — identifies infrastructure waste by combining
Redmine Kanban
Kanban workflow reports and automation for Redmine.
Triage
Cross-provider, approval-gated triage policy, workflows, prompts, and factory definition.
Sre
SRE Health Check - Unified site reliability health check workflow with report.
Semantic Orchestrator
Deterministically compile requested semantic capabilities and arbitrary keyed facts into standalone Swamp workflow drafts with aggregation, dependency, and operational coordination provenance.
Notification Outbox Workflows
Transport-neutral workflow patterns for atomically enqueuing, exactly scoped dispatching, and explicitly draining notification outbox records.
Sleeper
Read fantasy league state from the Sleeper platform's public read-only API — no key, no OAuth, no write surface. Resolve a username to a user ID, list leagues and drafts, and read a league in depth: settings and scoring, rosters with owners joined and standings derived, weekly matchups paired head to head, the transaction log, traded picks, playoff brackets, the draft board, and league-wide add/drop trends. Player IDs are resolved to names from a locally cached catalogue, and a missing record (which Sleeper reports as HTTP 200 with a null body) fails loudly instead of reading as empty.
Github Pr
Narrow GitHub.com same-repository pull-request boundary: preflight, plan, apply, and read-back verification. Draft is requested per packet rather than fixed by the adapter. No merge, release, repository administration, PR update, or arbitrary endpoint capability.
Change Packet
Forge-neutral immutable change packets for reviewed repository delivery. Records exact Git base/head identity, validation evidence, requested draft submission metadata, a canonical SHA-256 digest, and derived readiness. Performs no network, Git, forge, approval, merge, or release operation.
Notification Outbox
A transport-neutral, secret-redacting notification outbox for swamp workflows that enqueues deduplicated notification records and drains them through a caller-supplied transport, performing no transport I/O itself.
Daily Briefing
A daily operator briefing workflow with companion report. Gathers data from GitLab (review queue, todos), Microsoft Teams (mentions, unread chats, channel messages), and Redmine (recent updates, new tickets), then renders a prioritized markdown briefing plus a stable JSON contract.
Branded Deck
On-brand slide deck pipeline for swamp: a workflow that renders a deck from a voiced brief and a design reference via openai-document.webpageDesign, plus a skill that guides authoring the copy in your writing-voice profile, pinning brand tokens, and converting the PDF to PPTX. Depends on the openai-document, writing-voice, and openai-image extensions.
Absurd
Drive an Absurd Postgres-based durable-execution task queue from swamp — spawn tasks, poll status, await results, emit events, cancel, and list.
Capability Orchestrator
Capability catalog and DAG planner models for Swamp workflows and direct model method calls. Publishes capability definitions and resolves per-host requested capabilities into dependency waves for execution.
Garfield
Adaptive Garfield review and repair workflow with deterministic validation,
Shodan
Query the Shodan internet-wide scan database to find and profile internet-exposed devices. Single API key resolved from vault. Read the account plan and remaining credits, run searches that return trimmed device records (IP, org, product, location, open port, CVEs) with facet rollups, count results without spending query credits, pull the full banner history for one IP, do keyless InternetDB lookups (ports, CPEs, tags, CVEs), and request on-demand scans of IPs you own. Built for AV/IoT exposure recon.
Review
Human-in-the-loop review canvas — serve a local web form the human gates while the agent keeps working. list mode renders a long candidate list as a curation grid (configurable option-scale + per-item comment) for migrations, triage, and cleanup approvals; doc mode is a pastebin-style markdown editor (editor left, live preview right, optional approve/revise/reject verdict) for reviewing generated docs and gating publishes. Detached serve / status / collect / stop lifecycle; every save dual-writes JSON + markdown + a timestamped append-log, and collect records the result into the data model for workflow consumption. Python-stdlib server bundled; private networks only (URL-token guarded).
Cybriq
Integrate with a CybrIQ (Sepio) asset-visibility / hardware-access-control platform over its REST + GraphQL API. Local-login bearer auth with vault-resolved credentials. Read the asset dashboard, inventory, device types, risk insights, switches, external scan engines (Netpollers), events, alarm destinations, policies, scopes, tags, and user attributes; create tags, user attributes, policies, and scopes; and reach any other endpoint through a generic authenticated passthrough.