Firefly AI: Safe Web Browsing for AI Agents
Krish Gaba · Team Firefly
Submitted to Defensive Acceleration Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
Firefly AI is a security layer designed to protect AI agents when they browse the web. As modern LLM systems fetch URLs, they become vulnerable to malicious webpages containing hidden prompt injections, unsafe scripts, phishing elements, and manipulative content.
Firefly AI solves this by intercepting every URL before it reaches the model. It validates the domain, fetches pages safely with no JavaScript, sanitizes HTML, extracts clean text, and uses an AI Shield detector to identify harmful patterns. The system then allows, flags, or blocks the content, ensuring only safe information reaches the LLM.
This pipeline prevents prompt injection, data leaks, incorrect outputs, SSRF attacks, and corrupted inputs—problems that can cost organizations millions per incident. Firefly AI reduces operational risk, strengthens compliance, maintains trust, and saves companies between $500K to $5M per year.
With a roadmap including transformer-based detection, sandboxed JS analysis, domain reputation scoring, and continuous learning, Firefly AI aims to become the foundational safety infrastructure for future AI agents.

Reviews
No public critique yet.
Cite this project
@misc{gaba2025firefly,
title = {{Firefly AI: Safe Web Browsing for AI Agents}},
author = {Krish Gaba},
year = {2025},
month = nov,
note = {Submitted to Defensive Acceleration Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/firefly-ai-safe-web-browsing-for-ai-agents-h5sd}},
url = {https://apartresearch.com/sprints/projects/firefly-ai-safe-web-browsing-for-ai-agents-h5sd}
}More from Defensive Acceleration Hackathon
- View project: Neops - DevSecOps for the AI era
Neops - DevSecOps for the AI era
Broad Bros
NEOps is a CLI-based tool that embeds AI safety into your product lifecycle from day one. While development teams routinely build cybersecurity checks, AI-safety often comes later—or not at all. NEOps fills that gap by …
- View project: Assisted Audit of Solana Programs
Assisted Audit of Solana Programs
GLAM
Multi-agent solution that assists in auditing Solana programs, allows to consolidate audit findings into a knowledge base, and can integrate into CI/CD pipelines to prevent security regressions.
- View project: Mechanistic Watchdog
Mechanistic Watchdog
SL5
Mechanistic Watchdog is a mechanistic-interpretability-based “cognitive kill switch” for language models. Instead of only filtering final text, we monitor a model’s internal activations in real time and learn linear …