Skip to main content

CLI Reference

Generated by publisher tooling from CLI help output.

CommandDescription
staveRoot command
stave aliasManage command aliases
stave applyRun control evaluation after plan checks pass
stave attestSnapshot tamper detection via Ed25519 signatures
stave bisectFind when a security invariant was first violated
stave bundleGenerate a sealed evidence bundle for air-gap GRC integration
stave capabilitiesPrint supported input types and version constraints (default) or a user-facing catalog (subcommand)
stave celCEL expression tools
stave checkCompare before/after evaluations to check remediation
stave ciCI/CD policy and baseline commands
stave compareCompare compliance posture between two frameworks
stave completionGenerate shell completion scripts
stave configConfiguration commands
stave contractInspect Stave's per-asset-type input contracts
stave controlsWork with control definitions
stave coverageAnalyze observation field coverage against control predicates
stave diagnoseDiagnose evaluation inputs and results
stave diffCompare two observation snapshots or control catalogs
stave doctorCheck local environment readiness for Stave workflows
stave enforceGenerate deterministic enforcement templates from evaluation output
stave exemptManage risk acceptances (acknowledgments, exceptions, exemptions)
stave expandShow every control sharing a structural defect archetype
stave explainExplain how a control evaluates and which fields it needs
stave export-invariantsExport control catalog as solver-ready invariants
stave export-sirExport the Stave Intermediate Representation as JSON
stave exportExport controls and compliance evidence
stave featuresShow what Stave does and deliberately does not do
stave fmtFormat control and observation files deterministically
stave forgeAuthor and test custom controls
stave gapsReport which observation properties are absent + what they unlock
stave generateGenerate starter artifacts
stave graphVisualize control and asset relationships
stave helpHelp about any command
stave inspectLow-level security analysis primitives
stave lintLint control files for design quality
stave mapATT&CK tactic coverage and gap analysis
stave metricsWrite Prometheus scrape file for node_exporter
stave packsInspect built-in control packs
stave pathExport attack path graph data from active chain findings
stave permissionsQuery net effective permissions from a snapshot
stave profileManage compliance profiles
stave readinessReport what Stave can/can't evaluate given the supplied observations
stave reportGenerate executive security posture report
stave sanitizeSanitize a snapshot for cross-boundary sharing
stave schemasList all contract schemas
stave scorecardMulti-framework compliance scorecard
stave scoreCompute security posture score (0-100)
stave searchFind catalog entries matching a free-form intent
stave snapshotSnapshot inspection commands
stave statusShow project context and the next recommended command
stave telemetryEmit structured NDJSON telemetry from assessment output
stave testRun embedded control test cases
stave trendAnalyze compliance posture trends across assessment runs
stave validate-mappingValidate a Steampipe→Stave mapping file before use
stave validateValidate inputs without evaluation
stave versionPrint version and environment state