I think you are correct and the kb has the zones accidently backwards. I submitted a rating question to the author to have this checked.
the Appfw rules are embedded in normal security policy rules. And in the case of applications like those listed in the example the zone direction for that policy would almost always be trust to untrust. The Appfw rules won't kick in unless the main policy is hit so the main policy must capture the correct direction of traffic initiation.