EXTENSIONS
User-built models, drivers, vaults, and reports — the parts that plug into swamp.
Filter by what you need and pull what fits.
Hashicorp Vault
HashiCorp Vault secrets management via REST API (KV v1 and v2)
Aws/securityhub Findings
Query and manage AWS Security Hub findings from a delegated administrator
Azure
Azure infrastructure management via az CLI — 31 model types covering compute, networking, data, security, RBAC, Azure Policy, Defender for Cloud, Entra directory, monitoring, DNS, DevOps, and subscription-wide topology with Mermaid diagrams and cost estimation.
Tailscale
Install Tailscale on remote VMs over SSH and sync tailnet machine inventory from tailscale status JSON into per-machine resources.
Cloudflare Audit
Cloudflare security and configuration audit workflow.
Macos Doctor
Read-only local macOS security, sanity, and performance posture checks with a severity-rated report.
Github
GitHub models for swamp. Currently provides @hivemq/github/token, which audits a single GitHub token.
Trust Network
Inventory and report on OIDC trust policies and workload-identity federation across GitHub, Google Cloud, and Cloudflare One.
Cloudflare
Cloudflare One / Zero Trust Access discovery for swamp.
Aws/guardduty
Query and inspect GuardDuty findings from a delegated administrator account,
Mudroom
Run Claude Code (and other workloads) inside a macOS apple/container sandbox.
Cve/mini Shai Hulud
Scans deno.lock and package-lock.json files for npm packages compromised
Aws S3 Bucket Audit
Workflow-scope report that audits S3 buckets against standard security
Cve/dirtyfrag
Detects and mitigates the Dirty Frag Linux local privilege escalation
Mudroom
Run Claude Code (and other workloads) inside a macOS apple/container sandbox.
Github Security
GitHub repository security auditing with support for native features and third-party tool detection
Tailnet Healthcheck
Tailnet health reporting — find devices running outdated Tailscale clients and alert via Slack
Tailscale
Tailscale tailnet management — 10 model types covering devices, users, ACLs, DNS, auth keys, webhooks, settings, contacts, posture, and log config. 22 workflows for device inventory, user lifecycle, ACL audit, security audit, compliance, incident response, monitoring, and more. Fix: OAuth token cache now keys on credentials so different tailnets/OAuth clients no longer share tokens.