Prompt injection screening is an enterprise feature and is gated per organization. Contact your Firecrawl account team to have it enabled for your account.
Why scraped content is a risk
A scraped page is untrusted input. You control the request. You do not control the page. Text on a page can contain instructions. Those instructions target the model that reads the page later. That model is your agent, your extraction step, or your assistant. The page author writes the instructions. Your pipeline delivers them. Hidden text is the clearest case. A page can hide text in several ways:- White text on a white background
- Text set to a font size of zero
- Text positioned off the visible area of the page
- Comparable tricks that keep text out of sight
What the screen does
- Firecrawl classifies the content. Scraped content goes through a content classifier before delivery.
- Firecrawl flags suspected injection. The classifier marks content that reads as an instruction to a downstream model.
- Firecrawl does not withhold content by default. A flag on the content does not stop the delivery of that content.
This is not Lockdown Mode
Prompt injection screening and Lockdown Mode solve different problems. One feature does not replace the other. Prompt injection screening inspects content. It reads the scraped text and decides whether the text is safe to hand on. Lockdown Mode controls egress. It serves the page from Firecrawl’s index and cache. It never makes an outbound request to the target. It exists for compliance-constrained environments, where the request itself can leak sensitive information. Two differences apply:- Lockdown Mode does not inspect content. A cached page that carries a hidden instruction stays exactly as it was cached.
- Lockdown Mode changes how old a page can be. When a request does not set an age limit, the limit under Lockdown Mode is much longer. A served page can then be older.

