This is an automated email from the ASF dual-hosted git repository. luigidemasi pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/camel.git
commit 65f3156283e3966e1d3e3d5e109db2a64b488682 Author: Luigi De Masi <[email protected]> AuthorDate: Sun Sep 27 12:22:36 2026 +0200 CAMEL-24977: Clarify prompt injection in semantic validation Document proposed-action text as untrusted input that may steer the provider. Keep the application authorization checks authoritative even when semantic validation returns a positive decision, and regenerate the catalog documentation mirror. Co-authored-by: Codex <[email protected]> Signed-off-by: Luigi De Masi <[email protected]> --- .../resources/org/apache/camel/catalog/docs/semantic-language.adoc | 3 +++ .../camel-ai/camel-semantic/src/main/docs/semantic-language.adoc | 3 +++ 2 files changed, 6 insertions(+) diff --git a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/semantic-language.adoc b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/semantic-language.adoc index 2b71a6ae2387..0e516b1015e8 100644 --- a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/semantic-language.adoc +++ b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/semantic-language.adoc @@ -304,6 +304,9 @@ For example, declare this question alongside routes: The selected state should contain the approved task and the proposed action. Obtain the approved task from trusted application state; do not let the proposed action redefine it. +Treat the proposed action as untrusted input: its text can attempt to steer the provider +(prompt injection). A positive semantic decision must never override the application's +authorization checks. In this example, `direct:checkPermissions` performs the application's existing authorization and rejects unauthorized requests before semantic evaluation: diff --git a/components/camel-ai/camel-semantic/src/main/docs/semantic-language.adoc b/components/camel-ai/camel-semantic/src/main/docs/semantic-language.adoc index 2b71a6ae2387..0e516b1015e8 100644 --- a/components/camel-ai/camel-semantic/src/main/docs/semantic-language.adoc +++ b/components/camel-ai/camel-semantic/src/main/docs/semantic-language.adoc @@ -304,6 +304,9 @@ For example, declare this question alongside routes: The selected state should contain the approved task and the proposed action. Obtain the approved task from trusted application state; do not let the proposed action redefine it. +Treat the proposed action as untrusted input: its text can attempt to steer the provider +(prompt injection). A positive semantic decision must never override the application's +authorization checks. In this example, `direct:checkPermissions` performs the application's existing authorization and rejects unauthorized requests before semantic evaluation:
