Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
1080 results
plat:darwin-x86_64

Freeipa/group

@shrug/freeipa/group · v2026.07.17.1

Manage FreeIPA user & host groups over the JSON-RPC API: snapshot the inventory, generic user-group CRUD (groupShow/groupAdd/groupMod/groupDel) plus a desired-state groupSync reconcile, ensure the FreeRADIUS radius-vlan-<id> group pair, and add/remove members — idempotent and auditable, with a confirm-guarded delete.

upd Jul 170 pullsA100/100

Freeipa/cert

@shrug/freeipa/cert · v2026.07.17.1

Issue, inspect, and revoke X.509 certificates for any FreeIPA principal (user/host/service) over the JSON-RPC API, with optional in-model RSA/EC keygen and vaulted private keys.

upd Jul 170 pullsA100/100

Vyos

@shrug/vyos · v2026.07.16.1

Manage a VyOS router over SSH: read the running config, apply set/delete commands via vbash, and run arbitrary op-/config-mode commands.

upd Jul 172 pullsA100/100

Lemonade

@indistinct_talk/lemonade · v2026.07.16.2

Swamp model for interacting with Lemonade AI server — chat, completions, streaming, model lifecycle, system health, audio, images, and backend management via OpenAI-compatible and Lemonade-specific APIs

upd Jul 160 pullsA100/100

Career Ops

@sntxrr/career-ops · v2026.07.16.2

Mirrors the career-ops job-application tracker into swamp with bidirectional status write-back, posting URL + legitimacy enrichment, and a pipeline funnel report.

upd Jul 160 pullsB85/100

Gitlab Datastore

@webframp/gitlab-datastore · v2026.07.16.1

Stores swamp runtime data in GitLab using the Terraform state HTTP API. Provides distributed locking via GitLab's native state locking mechanism and bidirectional sync between local cache and GitLab.

upd Jul 1623 pullsA100/100

Postgres Datastore

@webframp/postgres-datastore · v2026.07.16.1

Stores swamp runtime data in PostgreSQL with row-based distributed locking. Compatible with AWS RDS, Aurora, and Aurora Serverless v2. Uses fencing tokens for split-brain safety across failover events.

upd Jul 16151 pullsA100/100

Reddit/moderation

@webframp/reddit/moderation · v2026.07.16.1

Reddit moderation model for subreddit management.

upd Jul 165 pullsA100/100

Agentcore Bootstrap

@webframp/agentcore-bootstrap · v2026.07.16.2

One-shot bootstrap for @webframp/agentcore. Ships a provisioner model

upd Jul 167 pullsA100/100

Gitlab

@webframp/gitlab · v2026.07.16.1

Read and write GitLab data via GraphQL (REST fallback for branches and

upd Jul 1669 pullsA100/100

Session Execute

@vcjdeboer/session-execute · v2026.07.16.1

Deterministically reproduce a governed data-science run — or replay someone else's captured Claude Science session. The headless runtime of the session-* suite: `run` executes a filled analysis template (R/qmd in a pinned nix R env), `run-targets` a targets pipeline via a harvester, `run-notebook` Python/ipynb via papermill in a locked conda/Docker env — each with the recorder armed and its swamp.returns contract verified. `replay` faithfully re-runs recorded R against frozen tolerance rules (nix preferred, docker fallback), and a Python host-replay shim serves a captured session's host.* calls offline (or falls through to the live API in hybrid mode). Same inputs, same environment, same result — reproducibility you can run, not just cite.

upd Jul 165 pullsA92/100

Session Write

@vcjdeboer/session-write · v2026.07.16.1

Let an AI fill in an analysis template without letting it touch the science. Governed parameter-fill: the AI fills ONLY the typed parameter slots of a frozen template, and `validate` is the deterministic gate that asserts the frozen structure was untouched and every fill satisfies its slot contract — bounded, validated, reproducible AI authoring, not free-form code generation. `author` builds Quarto (.qmd) or Jupyter (.ipynb) templates from structured cells (the writer owns the document layout and binds each param at its declared type) for R or Python; `init` wires an R project to record its work. The guarantee: what the AI can change is exactly the typed slots and nothing else — the template is the contract.

upd Jul 166 pullsA100/100

Session Record

@vcjdeboer/session-record · v2026.07.16.1

Never lose how a result was computed. A language-agnostic provenance ledger for interactive data-science sessions: append one immutable, content-checksummed record per executed cell/chunk — its code, value, figures, console output, warnings, packages, and even runtime-declared functions with their internal dependencies — from any client (R/RStudio, Python/Jupyter, targets, …). One append-only ledger, one record per cell, identical shape across languages: the foundation the rest of the session-* suite fills, seals, and replays. Capture the real computation as it happens, so a session can be audited, sealed (session-witness), or re-run later — not reconstructed from memory.

upd Jul 164 pullsA100/100

Session Witness

@vcjdeboer/session-witness · v2026.07.16.1

Prove a recorded data-science session hasn't been altered since you sealed it. The Master member of the session-* suite: a tamper-evident seal + authorship attestation, with no keypairs or infrastructure. `seal` chains the per-version content checksums of a session-record ledger (in sequence) into one sha256 session digest and attests its authors; `verify` recomputes the digest and reports whether a sealed session still matches. `seal_manifest` generalizes the primitive to ANY ordered {name, checksum} list — so a session-ingest bundle-manifest seals exactly the same way. Change one byte of any past record and the digest changes: the seal breaks, loudly. Ultralight integrity for governed, reproducible science — the trust layer under the whole suite.

upd Jul 163 pullsA92/100

Krb5

@kneel/krb5 · v2026.07.16.2

GSSAPI initial-token producer (no mutual authentication or continuation): native-JS Kerberos 5 / SPNEGO client (no shell-out) — password → AS pre-auth → TGT → TGS → service ticket → SPNEGO `Negotiate` token, with session keys, tickets, and headers stored as vault-backed datastore resources (requires installing a vault named `krb5`; any backend). Drives GSSAPI-protected HTTP endpoints and hands single-use SPNEGO headers to other models via data + CEL. Pure WebCrypto + fetch over MS-KKDCP (works in a fetch-only sandbox); raw TCP/UDP KDC transports available where socket permissions allow.

upd Jul 162 pullsA100/100

Aws/iam

@webframp/aws/iam · v2026.07.16.1

Cross-account IAM observation model for role, user, and policy inventory.

upd Jul 161 pullsA100/100

Session Patch

@vcjdeboer/session-patch · v2026.07.16.1

Capture a PyLabRobot lab protocol ONCE as a sealed, citable IDENTITY, then lower that single intent onto whatever hardware you have — byte-exact, reproducible, provenance-tracked. `seal` freezes a `.patch.yaml` into a content-addressed bytestring (encoded as MIDI UMP/SysEx) and records the 64-hex patch sha you cite, plus its four sealed artifacts (patch/ump/syx/manifest) as a typed resource: the exact bytes of a scientific intent, pinned. `run` lowers ONE sealed sha through a chosen PLR driver and records the run — status, invocations, device calls, and the full NDJSON event stream — the provenance of how an intent became machine calls. `resource_model` captures the content-addressed deck layout (slots + role->labware) a run binds to; `init` scaffolds the store. The thesis in one line: the SAME sealed sha lowers to device-appropriate calls that DIFFER — a channel pipette runs pick_up_tips -> aspirate -> dispense -> drop_tips while a Labcyte Echo runs open_source_plate -> run_picklist -> close; same intent, transposed per device, 'the diff is the answer'. A pure-TypeScript codec/player makes identity byte-exact (flip one byte -> ContentHashError) and reproduces every run call-for-call.

upd Jul 160 pullsA100/100

Terraform

@webframp/terraform · v2026.07.16.1

Read Terraform and OpenTofu state via CLI and marshal into swamp data.

upd Jul 1670 pullsA100/100

Github

@webframp/github · v2026.07.16.1

Query GitHub data using the gh CLI for repository, PR, issue, release, and workflow visibility.

upd Jul 1640 pullsA100/100

Aws Cost Audit

@webframp/aws-cost-audit · v2026.07.16.1

AWS cost audit workflow — identifies infrastructure waste by combining

upd Jul 1629 pullsA100/100

Network

@webframp/network · v2026.07.16.1

DNS and network probing model that generates diverse diagnostic events.

upd Jul 16168 pullsA100/100

Ai Usage

@webframp/ai-usage · v2026.07.16.1

Unified cross-provider AI token usage monitoring — workflow, model, and

upd Jul 165 pullsA100/100

Aws/adopt

@webframp/aws/adopt · v2026.07.16.1

Brownfield adoption of existing AWS infrastructure into swamp models.

upd Jul 1645 pullsA100/100

Git Workspace

@twonines/git-workspace · v2026.07.16.1

Local git operations model — clone, branch, read, commit, push. Designed for agent-driven development workflows where code changes are authored locally and pushed to a remote forge. Supports a configurable workspace layout (default: $HOME/{host}/{group}/{project}) and commit message format enforcement.

upd Jul 169 pullsA100/100