scanned 17d ago·osv · gitleaks · opengrep · picklescan + heuristics·full breakdown in the Security tab ↓
STORM
STORM (Synthesis of Topic Outlines through Retrieval and Multi-perspective Question Asking) is a research agent from Stanford OVAL that turns any topic into a well-cited, Wikipedia-quality article. It uses a multi-agent perspective-guided research loop to gather diverse information before writing.
Key Features
Perspective-driven research: Identifies multiple expert viewpoints and generates questions from each angle to ensure comprehensive coverage
Multi-source retrieval: Searches the web (Bing, You.com, Tavily) and synthesizes information with citations
Outline-first writing: Generates a structured outline before writing to ensure logical flow
Co-STORM mode: Interactive, collaborative research session where a human and multiple AI agents research together in real time
Any LLM backend: Works with GPT-4, Claude, Gemini, Llama, and local models via LiteLLM
Citation grounding: Every claim in the output is linked to a source URL
Quick Start
pip install knowledge-storm
from knowledge_storm import STORMWikiRunnerArguments, STORMWikiRunner
from knowledge_storm.lm import OpenAIModel
from knowledge_storm.rm import YouRM
lm_configs = STORMWikiRunnerArguments(output_dir="./output")
runner = STORMWikiRunner(lm_configs, OpenAIModel("gpt-4o"), YouRM())
runner.run(
topic="The impact of large language models on scientific research",
do_research=True, do_generate_outline=True, do_generate_article=True
)
Add to ai-supply
npx ai-supply add storm-research-agent
Curated mirror of the open-source STORM (MIT). Get it from the source.
! Security: Review · 7575/100 · grade Bscanned 17d ago
✓ no compromise signals11 risk-surface · 6/20 OWASP controls flagged
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
What this capability can do · med confidence (static)
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
OWASP Top 10 for LLM Applications
⚠LLM03Supply Chaincritical
Vulnerable/compromised dependencies, models or archives in the artifact.