with one click
stave
stave contains 10 collected skills from sufield, with repository-level occupation coverage and site-owned skill detail pages.
Skills in this repository
Build Stave from source and verify the binary and control catalog work, adapting to what is already installed
Author, test, and verify a custom Stave control using the forge toolchain
Run Stave against a tiny example observation and read your first findings — no AWS account required
Deploy a known-vulnerable Bishop Fox IAM lab, evaluate it with Stave, and confirm findings match the documented attack paths — trust via an independent oracle
Export Stave observation facts to JSONL/SMT-LIB and derive compound cross-asset chains with Z3, Soufflé, or Prolog — detection CEL alone cannot express
Capture a read-only configuration snapshot of your real AWS account and evaluate it with Stave on a local, deterministic snapshot
Verify cloud infrastructure security using the Stave platform with machine-verifiable contracts at every step
Write a reasoning specification for an external solver (Z3, cvc5, Soufflé, Clingo, Prolog, PRISM) that consumes Stave's SIR fact export, then trial it with a fresh agent
Author a new CEL control in the Stave catalog with test-first discipline and binary-checkpoint verification
Connect a new cloud data source to Stave by authoring a Steampipe → Stave observation mapping