Skip to content

feat(tools): install swamp, and PRD 0019 for what to take from it - #539

Merged
ralyodio merged 1 commit into
mainfrom
swamp-club
Sep 25, 2026
Merged

ralyodio merged 1 commit into
mainfrom
swamp-club

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Adds swamp as an installable tool, and PRD 0019 for the ideas in it worth taking.

moshcode install swamp

Swamp (github.com/systeminit/swamp) is a deterministic automation CLI: typed models, workflow DAGs, versioned immutable runs, and a vault that injects credentials at execution time so they never reach a prompt. TypeScript on Deno, AGPL-3.0.

Tool, not engine. /agents is an alias for engines (cli-schema.mjs:1751), and engines are interactive coding agents you land a herd pane on and talk to. Swamp is driven by an agent rather than being one. It ships skills into .claude/skills, .cursor/skills and .agents/skills so Claude Code, Cursor, OpenCode and Codex can all call it, and it has no interactive session. So it sits with railway, gh and supabase. Moving it to ENGINES is a one-line change if that call is wrong.

Two installer details the entry has to carry:

  • The vendor script prompts for SWAMP CLUB signup partway through. A piped install under moshcode has no one to answer it, so SWAMP_NONINTERACTIVE=1 is set.
  • A non-root install lands in ~/.local/bin, ~/bin or ~/.swamp/bin depending on what is already on PATH, and the script edits no shell rc. All three are searched via binDirs.

No upgrade key: no vendor updater is documented and the installer always pulls stable, so re-running it is the upgrade, same as noodle.

PRD 0019

The lead item is heartbeat liveness. moshcode decides whether an engine is working, blocked or gone by regex-matching what the engine printed, plus pane titles. Those are guesses about another vendor's UI and they expire: Claude Code 2.1 overwrote the pane title and dropped "? for shortcuts", and detection broke. Swamp keeps a run tracker where a run is alive because it sent a heartbeat. That retires a recurring bug class rather than patching another pattern.

Then: immutable versioned run history extending the OpenFleet ledger, swarm pieces as a DAG so concurrency falls out of the graph instead of a hand-chosen phase count, moshcode doctor built from failures that have actually happened here, and documented config precedence, which PR #535 paid for the lack of.

The binding constraint is in Non-Goals: swamp is AGPL-3.0 with an extension exception, moshcode is MIT. Every requirement is an independently implemented idea and no swamp code or schema is to be copied in. Flagged explicitly because R5 and R11 are the requirements most likely to tempt someone into reading their YAML schemas.

The credential vault is deliberately not re-proposed here. It is PRD 0018 R8 already, arriving from omp. Two unrelated tools converging on it is the argument for building it, not for writing it twice.

Testing

node --test test/tools.test.mjs test/prd.test.mjs test/prd-index-cell.test.mjs test/completion.test.mjs test/help.test.mjs passes, 143/144 with 1 pre-existing skip. swamp flows into the help wall automatically from TOOLS, verified via moshcode --help.

🤖 Generated with Claude Code

Swamp (swamp-club.com, github.com/systeminit/swamp) is a deterministic
automation CLI: typed models, workflow DAGs, versioned immutable runs, and a
vault that injects credentials at execution time so they never reach a prompt.

Wired as a TOOL rather than an engine. `/agents` is an alias for `engines`
(cli-schema.mjs:1751) and engines are interactive coding agents you land a herd
pane on. Swamp is driven BY an agent, ships skills into .claude/skills,
.cursor/skills and .agents/skills for Claude Code, Cursor, OpenCode and Codex,
and has no interactive session, so it belongs with railway, gh and supabase.
Moving it is a one-line change if that call is wrong.

Two installer details the entry has to carry: the vendor script prompts for
SWAMP CLUB signup partway through, which would stall a piped install, so
SWAMP_NONINTERACTIVE is set; and a non-root install lands in ~/.local/bin,
~/bin or ~/.swamp/bin depending on what is already on PATH, while the script
edits no shell rc, so all three are searched.

PRD 0019 covers what is worth taking. The lead item is heartbeat liveness:
moshcode infers engine state by regex-matching vendor output, which is why
Claude Code 2.1 broke detection when it overwrote the pane title and dropped
"? for shortcuts". Swamp tracks runs by heartbeat instead. Then immutable run
history, swarm pieces as a DAG rather than a fixed phase list, `moshcode
doctor`, and documented config precedence, which PR #535 paid for the lack of.

The binding constraint is in Non-Goals: swamp is AGPL-3.0 and moshcode is MIT,
so the ideas are rippable and the code is not.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

0 finding(s) in the 3 file(s) this pull request changes.

Nothing in the files this pull request changes.

101 pre-existing finding(s) elsewhere in the repository — **HIGH/CRITICAL**: 8 | **MEDIUM**: 82 | **LOW**: 11

Not introduced by this pull request. The full set is in the Security tab.

Severity Rule Location
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
HIGH tls-verification-disabled apps/pwa/src/lib/moshpit-gateway.mjs:299
HIGH sh-remote-script-execution install.sh:86
HIGH sh-remote-script-execution install.sh:90
HIGH sh-remote-script-execution install.sh:258
HIGH sh-remote-script-execution install.sh:269
HIGH sh-remote-script-execution install.sh:275
HIGH tls-verification-disabled src/dns.mjs:766
MEDIUM sql-template-interpolation apps/pwa/src/lib/moshpit-certs.mjs:44
MEDIUM sql-template-interpolation apps/pwa/src/lib/moshpit-certs.mjs:82
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:139
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:153
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:179
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:373
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:377
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:422
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:671
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:867
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:869
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:928

…and 81 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 7765001 into main Sep 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant