Takeaways: Reveals security vulnerabilities in LLM-based web crawling agents and empirically demonstrates the dangers of indirect prompt injection attacks. Suggests the need for strengthening the security of LLM-based autonomous systems. Provides an important foundation for research on attack techniques and defense strategies. Easy reproducibility and verification of research results through open source software and demo websites.