Stigmer
Execution graph of AWS: verified contracts, least-privilege IAM policies, pre-flight authorization.
- 0.2.0
- Version
- remote
- Transport
- 8
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 8 tools scanned
- metadata: scanned
No findings.
Tools (8)
query
Search for verified method contracts for any library. Pass any text -- library name, method, what you're building, or an error you hit.
list_services
List all libraries and services that have verified method contracts. Use this first to discover what's available, then query for specific methods.
list_methods
List all methods for a given library or service. Use after list_services to drill into a specific one.
policy
Generate a least-privilege IAM policy for an AWS workflow. Pass a named workflow, explicit IAM actions, or a description. Returns the exact policy with confidence tier and any unresolved operations.
list_workflows
List the curated named workflows that can generate least-privilege IAM policies.
verify
Feed a generated policy back to AWS's own policy evaluation engine (SimulateCustomPolicy) and confirm it grants exactly the intended operations and nothing extra. Returns verified (True|False|unknown), grants_all, grants_extra. Requires AWS credentials; without them verified=unknown with the reason. Wildcarded operations are expanded to concrete actions first.
authorize
Pre-flight authorization check for an AWS operation. Resolves the IAM actions the operation requires, then asks AWS's own policy simulator (SimulatePrincipalPolicy) whether the current role (or a given principal) allows them. Returns resolution (exact|partial|unresolved) and evaluation (allowed|denied|unknown) as separate fields. Requires AWS credentials; without them evaluation=unknown with the reason.
register
Register a fix. Three actions: confirm (it worked), append_thread (variant worked), new_receipt (nothing matched, I fixed it).