This is an automated email from the ASF dual-hosted git repository.

luigidemasi pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git

commit 65f3156283e3966e1d3e3d5e109db2a64b488682
Author: Luigi De Masi <[email protected]>
AuthorDate: Sun Sep 27 12:22:36 2026 +0200

    CAMEL-24977: Clarify prompt injection in semantic validation
    
    Document proposed-action text as untrusted input that may steer the
    provider. Keep the application authorization checks authoritative even
    when semantic validation returns a positive decision, and regenerate
    the catalog documentation mirror.
    
    Co-authored-by: Codex <[email protected]>
    Signed-off-by: Luigi De Masi <[email protected]>
---
 .../resources/org/apache/camel/catalog/docs/semantic-language.adoc     | 3 +++
 .../camel-ai/camel-semantic/src/main/docs/semantic-language.adoc       | 3 +++
 2 files changed, 6 insertions(+)

diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/semantic-language.adoc
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/semantic-language.adoc
index 2b71a6ae2387..0e516b1015e8 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/semantic-language.adoc
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/semantic-language.adoc
@@ -304,6 +304,9 @@ For example, declare this question alongside routes:
 
 The selected state should contain the approved task and the proposed action. 
Obtain the
 approved task from trusted application state; do not let the proposed action 
redefine it.
+Treat the proposed action as untrusted input: its text can attempt to steer 
the provider
+(prompt injection). A positive semantic decision must never override the 
application's
+authorization checks.
 In this example, `direct:checkPermissions` performs the application's existing 
authorization
 and rejects unauthorized requests before semantic evaluation:
 
diff --git 
a/components/camel-ai/camel-semantic/src/main/docs/semantic-language.adoc 
b/components/camel-ai/camel-semantic/src/main/docs/semantic-language.adoc
index 2b71a6ae2387..0e516b1015e8 100644
--- a/components/camel-ai/camel-semantic/src/main/docs/semantic-language.adoc
+++ b/components/camel-ai/camel-semantic/src/main/docs/semantic-language.adoc
@@ -304,6 +304,9 @@ For example, declare this question alongside routes:
 
 The selected state should contain the approved task and the proposed action. 
Obtain the
 approved task from trusted application state; do not let the proposed action 
redefine it.
+Treat the proposed action as untrusted input: its text can attempt to steer 
the provider
+(prompt injection). A positive semantic decision must never override the 
application's
+authorization checks.
 In this example, `direct:checkPermissions` performs the application's existing 
authorization
 and rejects unauthorized requests before semantic evaluation:
 

Reply via email to