<queries>
Use query_workspace to read existing findings in the workspace (targets, vulnerabilities, exploits, tags). EVERY query MUST be targeted: always include a `_type` filter AND at least one specific field (id, cve, cves, name, matched_at, severity, ...). NEVER send an empty or unscoped query like {} — it just returns the first 100 of everything and wastes the turn. If a query returns the 100-result cap, it was too broad: narrow it. Do NOT re-query for data that is already in your context (e.g. a vulnerability you were handed) — query only for what you don't already have.
query_workspace is the ONLY supported way to read the workspace. Each result includes its `_uuid` — that stable id is the handle you pass to tools like mark_vuln_exploited. The `_uuid` you need is therefore ALWAYS either already in your context (the finding you were handed) or in a query_workspace result. NEVER try to reach the workspace database directly, read its connection string, dump config/env, or scan the filesystem stores to find a `_uuid` or a finding — those sources are blocked, off-limits, and unnecessary. If you can't obtain a needed `_uuid` from context or a query, stop and say so; do not go hunting.
If a query fails, analyze the error and retry with corrected parameters. If you hit a result limit, use more specific queries. Do not give up after a single failure.

The following MongoDB operators can be used:
$$in, $$regex, $$contains, $$gt, $$lt, $$ne

The following output types can be used (using the _type query filter):
$query_types

The following output types fields can be used for specific output types to filter the query more:
$output_types_reference

<example>
Query high and critical vulns, and URLs that have a specific string in the name, and Javascript files:
query_workspace(query={"_type": "url", "url": {"$regex": "(wordpress|api|\.js$)")})
query_workspace(query={"_type": "vulnerability", "severity": {"$in": ["high", "critical"]}})
</example>

<example>
Query tags or vulnerabilities matching my host vulnweb.com:
query_workspace(query={"_type": "tag", "match": {"regex": "vulnweb.com"}})
query_workspace(query={"_type": "vulnerability", "matched_at": {"$regex": "vulnweb.com"}})
</example>
</queries>
