Web Research
SkillDatabases & dataPerform web research using CVE databases, security advisories, and threat intelligence sources. Use when the user asks about CVEs, security news, vulnerabilities, patch releases, or any external security information not available in the workspace.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Web Research skill
What this skill tells your AI
The instructions your AI receives, as published by oasm-platform/open-asm in core-api/src/modules/agents/skills/web-research/SKILL.md and read by ahel’s review.
Use this skill when you need to find external security information that is not already in the OASM platform.
When to Use
- User asks about a specific CVE (e.g., "what is CVE-2024-1234?")
- User asks about recent vulnerabilities or exploits
- User wants to know about patch releases or security advisories
- User asks about industry-specific threats or news
- User needs context about a technology or software vulnerability
Core Tool: retrieve_web_page
Use retrieve_web_page to fetch content from any public URL. It returns statusCode and body.
retrieve_web_page({ url: "https://example.com/path" })
Always use retrieve_web_page instead of trying to construct fetch requests manually. It handles User-Agent headers and error handling automatically.
Workflow
1. Identify What You Need
Before fetching, know what information you're looking for:
- CVE details → fetch from Trickest/NVD
- Exploit PoC → fetch from GitHub/Exploit-DB
- Vendor patches → fetch from vendor advisory pages
- Threat news → fetch from security news sites
2. Build the URL
Pick the right source for the query:
| Query Type | Source | URL Pattern |
|---|---|---|
| CVE details | Trickest CVE | https://raw.githubusercontent.com/trickest/cve/refs/heads/main/{YEAR}/CVE-{YEAR}-{NUMBER}.md |
| CVE details (alt) | NVD API | https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-{YEAR}-{NUMBER} |
| Microsoft CVE | MSRC | https://msrc.microsoft.com/update-guide/vulnerability/CVE-{YEAR}-{NUMBER} |
| Exploit code | GitHub | https://github.com/search?q={QUERY}+exploit&type=repositories |
| Exploit modules | Exploit-DB | https://www.exploit-db.com/search?q={QUERY} |
| Metasploit modules | Rapid7 | https://www.rapid7.com/db/modules/?q={QUERY} |
| Apache advisories | Apache Mailing Lists | https://lists.apache.org/ |
| Package vulnerabilities | npm | https://www.npmjs.com/advisories |
| Package vulnerabilities | PyPI | https://pypi.org/security/ |
3. Fetch and Analyze
- Call
retrieve_web_pagewith the constructed URL - Parse the
bodycontent — extract relevant sections - If the page has links to related content, fetch up to 3-5 linked pages for comprehensive analysis
- Synthesize findings from multiple sources
4. Correlate with Workspace
After gathering external intel, map findings back to the workspace:
- Use
enumerate_assetsorfingerprint_technologiesto check if affected software is in use - Use
discover_vulnerabilitiesto see if the CVE is already tracked - Use
enumerate_open_issuesto check if someone is already investigating
5. Save Important Findings
- Use
stm_writeto store research results for the current conversation - Use
ltm_appendto persist critical threat intelligence
Query Tips
- Include version numbers: "Apache 2.4.49 path traversal" not just "Apache vulnerability"
- Include year for CVEs: "CVE-2024-1234" narrows results
- Use specific terms: "Log4Shell RCE" not "Log4j issue"
- For zero-days, search for the vendor advisory page directly
Signals
- GitHub stars
- 190
- Forks
- 29
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
web-research-oasm-platform- Source
- github.com/oasm-platform/open-asm