Blockchain-based financial systems process billions in transactions but remain vulnerable to sophisticated fraud schemes. Current detection approaches analyze completed transactions, preventing neither fund loss nor protocol exploitation. We address this through an oracle-mediated prevention system integrating machine learning inference with smart contract execution. Training ensemble models on 12,847 Ethereum transactions with engineered features capturing gas anomalies and temporal patterns, we achieve 94.2\% fraud classification accuracy. Testnet deployment demonstrates 1.09-second response latency with 6.8\% computational overhead, contrasting favorably against prior on-chain implementations requiring 34\% overhead. Our working prototype validates practical viability for production environments where security requirements justify marginal transaction costs.
This paper explores contemporary blockchain applications in the supply chain and logistics sector, focusing on how distributed ledger technology enhances transparency, traceability, security, and operational efficiency across complex global supply networks. The study reviews key blockchain concepts, including consensus mechanisms, smart contracts, and tokenization, and examines their role in improving coordination among stakeholders. Real-world case studies from organizations such as Walmart, Nestlé, Pfizer, Moderna, and Maersk demonstrate practical implementations of blockchain for product traceability, anti-counterfeiting, and shipment tracking. The paper also analyzes major challenges facing blockchain adoption, including scalability limitations, regulatory uncertainty, interoperability issues, and data reliability concerns. Furthermore, it highlights emerging trends such as integration with artificial intelligence, Internet of Things technologies, digital twins, sustainability tracking, and cross-chain platforms. The findings suggest that blockchain plays a critical role in supporting digital transformation initiatives aligned with Industry 4.0 and enables the development of more resilient, transparent, and trustworthy supply chain ecosystems.
Renewable energy in Africa has gained increasing attention as a strategic pathway to achieving sustainable development, energy security, and economic transformation. A structured search of peer-reviewed studies was conducted using Web of Science, Scopus, and ProQuest. Fifteen empirical studies met the strict PRISMA inclusion criteria for detailed systematic synthesis, while additional high-quality review articles, book chapters, and policy reports were incorporated to strengthen contextual interpretation of renewable energy deployment trends across Africa. This systematic review synthesizes empirical evidence on renewable energy deployment across the continent, focusing on trends, challenges, and opportunities. Africa is endowed with abundant solar, wind, hydropower, geothermal, and biomass resources, yet actual utilization remains uneven and limited, with solar and wind experiencing the most rapid growth in recent years. Hydropower continues to dominate installed capacity, while geothermal and emerging technologies remain largely underdeveloped. Persistent barriers to deployment include inadequate grid infrastructure, limited access to finance, policy and regulatory inconsistencies, institutional capacity constraints, and political instability, particularly in rural and decentralized systems. Despite these challenges, opportunities exist in the form of declining technology costs, growing private and international investment, expansion of decentralized energy systems, and regional cooperation initiatives. Strengthening policy implementation, improving governance coordination, investing in infrastructure and human capital, and promoting innovative financing mechanisms are critical to accelerating Africa’s renewable energy transition.
By making smart farming and precision agriculture truly revolutionary, the intersection of Artificial Intelligence of Things (AIoT) and blockchain technology has enabled safe, transparent, and intelligent systems of food production. The major problem in this field is to provide a credible authentication of heterogeneous devices, sensors, and stakeholders and guarantee the integrity and privacy of data. The chapter discusses how blockchain can be implemented together with decentralized identity (DID) systems to provide strong, unaltered authentication systems to AIoT-based agricultural ecosystems. The given approach helps to remove single points of failure, increase accountability, and allow farmers to have a better opportunity to control the ownership and sharing of data by leveraging the distributed ledger technology. Centralized identity promotes cross-agricultural device interoperability, stakeholders in the supply chain, and service providers. The chapter offers a conceptual framework, explains the implementation issues of scalability and energy efficiency.
This white paper introduces the Coherence Ledger, a decentralized and time-weighted integrity scoring system designed to evaluate individuals and organizations based on long-term behavioral patterns rather than short-term claims.It critiques existing trust systems—including online reviews, credit scoring, and professional directories—as structurally vulnerable to manipulation, opacity, retaliation, and extraction incentives.The framework proposes a transparent scoring protocol combining behavioral events, exponential time decay, decentralized identity verification, and peer-based trust propagation to create measurable coherence scores.It integrates technologies such as decentralized identifiers (DIDs), Soulbound Tokens, and web-of-trust mechanisms to reduce gaming, increase accountability, and preserve auditability across digital systems.Positioned as post-extractive trust infrastructure, the work outlines how the Coherence Ledger could support hiring, finance, media verification, and institutional risk analysis by making extraction visible and rewarding sustained coherent behavior over time.
The rapid expansion of Artificial Intelligence Data Centers (AIDC) faces severe physical constraints, notably the linear O(n) scaling of power consumption, cooling requirements, and latency. In this paper, we propose the Lattice Swarm Protocol, a paradigm shift in distributed edge computing utilizing an O(1) constant memory architecture combined with the Virtual-to-Materialization (V2M) engine. We mathematically demonstrate that when interconnected via high-speed 400G/800G optical networks, multiple 1MW ultra-low-power edge nodes do not compute independently. Instead, they share Spatiotemporal Environmental Hashes across a 9192-D Lattice network. This mechanism exponentially reduces the computational load of the entire network as node count increases, creating a single 300MW-equivalent "Hyper-Organism" from merely 30 distributed 1MW nodes. We empirically validate this architecture through the implementation of zero-latency Stateless Custody protocols and interstellar acoustic materialization (Voyager 1), both audited by Google DeepMind Antigravity. This infrastructure establishes a new global standard for Autonomous Driving and Urban Air Mobility (UAM).Version 2 Update: Integrated Zero-Knowledge Proof (ZKP) mechanisms and Stateless Key Vaporization (0.024s), aligned with KIPO Patent No. 10-2026-0079266.
We introduce a new polynomial-time graph invariant combining three complementary components: (1) the enriched Bipartite Double Cover (BDC) vertex cover signature; (2) the Laplacian eigenvalue spectrum; and (3) the K_4 clique profile and Ollivier-Ricci curvature. We demonstrate that while spectral and standard BDC methods collapse on strongly regular graphs (SRGs) due to extreme symmetry, the geometric and dense-topological components of this hybrid invariant break the cospectrality. Specifically, the invariant successfully discriminates the classical cospectral pair Shrikhande vs. Rook(4,4) [SRG(16,6,2,2)] in polynomial time, where Shrikhande is K_4-free and Rook(4,4) contains exactly 8 cliques. Furthermore, empirical validation on low-power ARM Edge hardware demonstrates that the invariant scales efficiently, processing dense Paley graphs (up to N=97) in under 5 milliseconds. This confirms its sub-millisecond viability for real-time edge computing, zero-knowledge proofs (ZKPs) cryptanalysis, and cheminformatics.
This paper is the authoritative technical documentation of immo.quick Core version 2.1.0. It introduces and formally specifies the Deterministic Execution Proof Engine (DEPE) — the overarching orchestration layer that unifies five interlocking architectural components (Prior Admissibility Space, Exogenous Anchor Protocol, Sensor/Oracle Trust Bridge, Bi-Temporal Ledger, Machine Law Engine) into a single, unbroken, cryptographically provable execution corridor. Every transaction processed by DEPE produces an Execution Proof Artifact (EPA): a self-contained, externally verifiable, court-admissible proof object that the transaction was evaluated correctly under the rules applicable at the moment of execution. The EPA is not a log entry or a summary — it is a formal proof object that either verifies completely under the 6-step DEPE Verification Protocol, or does not verify at all. Version 2.1.0 introduces seven architectural advancements over v2.0.0: DEPE (Deterministic Execution Proof Engine): The integration layer producing a single signed EPA per transaction, cryptographically binding all five architectural layer outputs into an indivisible unit. EPA signature scheme: CRYSTALS-Dilithium-3 (NIST PQC standard). EPA generation latency: <100ms median. External verification latency: <50ms. JPO Pre-Fill Protocol: Reduces regulatory update latency for announced changes from 34ms to under 5ms by proactively compiling and staging rules upon legislative announcement, enabling millisecond-precision atomic swap at the effective date. Checker Rotation Governance (Six-Eye Principle): Formalizes a third independent checker drawn from a rotating governance pool for high-value and high-risk transactions. Rotation is deterministic (hash-based), requires no human discretion, and is itself bi-temporally logged and attested. Bypass requires simultaneous compromise of three institutionally separated hardware devices. BFT Quorum Specification: Formalizes Byzantine Fault Tolerance for the Bi-Temporal Ledger at f ≤ ⌊(n−1)/3⌋. Production configuration: n=7, f=2, quorum=5. Record commitment latency: 4ms median. Merkle replication lag: 12ms median. Deny Path Artifact (DPA): Every BLOCK decision generates a signed, immutable DPA specifying the exact gate condition, rule reference, and structural reason for rejection. Courts, regulators, and counterparties can independently verify not only that a transaction was blocked, but precisely why — with cryptographic proof. ZKP Circuit Library v2: Expanded to 47 pre-compiled, formally verified zero-knowledge proof circuits across banking/capital, AML/KYC, DORA/ICT, privacy/data, real estate, cross-border, and regulatory filing categories. All circuits use Groth16 and PLONK proving systems and are integrated directly into the Machine Law Engine compilation pipeline. Known Patterns Extension Protocol (KPEP): Enables ~70% acceleration for registered common transaction classes via formally verified proof templates, without any security reduction. Template match failure triggers automatic fallback to the full standard path. Additional v2.1.0 enhancements: ACASP Second-Order Anomaly Detection (ambiguity itself is a blocking condition); EAP dual-channel heartbeat with gap tolerance tightened from 50ms to 35ms; Offline Receipt Export for self-contained external verification without live system dependency. Central architectural guarantee (unchanged and strengthened): immo.quick Core is the only production architecture providing a complete, unbroken, cryptographically enforced provenance chain from the moment of physical real-world observation through the enforcement gate — with formally guaranteed zero false approval rate (Closed-World Assumption), formally guaranteed temporal accuracy (Bi-Temporal Ledger + BFT Quorum), and — as of v2.1.0 — a fully machine-verifiable Execution Proof Artifact for every transaction ever processed. This paper provides full formal specifications (TLA+/Z3 style), three detailed institutional case studies (DORA Art.11 ICT incident gate; cross-border real estate acquisition with §203 StGB / CLOUD Act conflict resolution; FATF Travel Rule enforcement with ZKP-selective disclosure), complete measured production performance data, and a complete attack surface analysis covering nine adversarial vectors including DEPE integration hash forgery and ACASP ambiguity injection. Supersedes: v2.0.0 (April 2026, DOI 10.5281/zenodo.19799660).
This study examines the role of impact investing and climate finance in generating measurable social value through renewable energy projects by applying the Social Return on Investment (SROI) framework. Growing global investment in renewable energy has emphasized financial performance and emission reduction outcomes, while systematic measurement of social impacts remains limited. The purpose of this research is to assess how SROI can be used to quantify the social and environmental value created by renewable energy investments and to demonstrate its relevance for impact-oriented decision-making. A mixed-methods approach was employed, combining secondary project data analysis, stakeholder engagement, outcome mapping, and monetization of social and environmental benefits to calculate SROI ratios. The findings reveal that renewable energy projects consistently produce social returns exceeding the initial investment, with SROI ratios varying according to project type, scale, stakeholder involvement, and socio-economic context. Community-based and decentralized projects tend to generate higher relative social returns, driven by employment creation, improved energy access, health improvements, and environmental benefits. The study concludes that integrating SROI into climate finance evaluation enhances transparency, accountability, and alignment between financial objectives and sustainable development goals.
The growing digitalisation of the tourism sector has led to increased vulnerability to cross-border cybercrime, exposing gaps in international legal cooperation. This study examines the legal and jurisdictional challenges in collecting and admitting digital evidence in tourism-related cybercrime. It analyses key international frameworks, including the Budapest Convention, UNTOC, and the EU-US Data Privacy Framework, highlighting conflicts in data sharing and evidence admissibility. Case studies such as Marriott, British Airways, and MakeMyTrip reveal inconsistencies in cross-border investigations. The paper also explores the role of blockchain and zero-knowledge proofs in improving evidence integrity, while raising concerns over privacy rights under ICCPR and ECHR. Findings suggest the need for legal harmonisation, streamlined evidence-sharing procedures, and enhanced forensic capabilities to strengthen cybercrime response in the tourism industry.
This paper develops a deep reinforcement learning framework for cryptocurrency portfolio management in which transaction costs are derived from the Riemannian geometry of the underlying volatility model rather than assumed constant. A Proximal Policy Optimisation agent is trained on a reward function grounded in non-equilibrium thermodynamics: we use the free-energy Bellman equation, in which transaction costs are the geodesic slippage on the Fisher information manifold of a maximum-entropy Markov-switching GARCH model, and regime-transition costs are the Wasserstein-2 distance between the calm and turbulent return distributions. A thermodynamic Carnot bound on portfolio efficiency is established and empirically validated. Five hypotheses are tested across Bitcoin, Ethereum, Ripple, Litecoin, and Bitcoin Cash over January 2017 to March 2026. The geometric-cost agent achieves statistically superior Sharpe ratios relative to flat-fee baselines on four of five assets; portfolio turnover is reduced by 56 to 83 percent relative to signal-following; the thermodynamic friction point at which the agent prefers no-trade is asset-specific and ordered by turbulent half-life; a joint topological and geometric circuit breaker reduces Maximum Drawdown by 28 to 38 percent; and ablation confirms that every component of the observation vector contributes a statistically significant performance gain. The framework requires liquid cryptocurrency markets with validated parametric volatility models; transferability to other asset classes requires upstream recalibration.
We present a production-ready framework for verifiable self-organization in networks of 768 coupled quantum oscillators (the “Crystal Brain”), integrating sixfine-tuned components: adaptive SPSA optimization with automatic plateau escape, multi-resolution Louvain community detection, non-deterministic proof seeds,normalized causal efficacy metrics, dynamic Merkle root hashing, and a semanticproof-tagging API. We map the Ising regime classification of Bhalla et al. (2026)onto a Kuramoto-type phase dynamics and demonstrate convergence to a coherentCAPTURE regime with 84.7% capture fraction. A companion octonionic atlas of 50nuclides (OctoSpec v0.4) reveals a moderate anti-correlation (r = −0.54, p < 0.001)between the Octonionic Anomaly Index and nuclear binding energy. All coherencemilestones are certified by zero-knowledge proofs generated at 80-bit security viathe ZEE200 backend and registered immutably on the ARKHE OCTRA chain.
The relationship between deterministic polynomial time (P) and polynomial space (PSPACE) is one of the foundational open problems in computational complexity theory. While proving P = PSPACE remains elusive and is widely believed to be false, the characterizations of PSPACE have yielded profound insights into modern computer science, specifically cryptography and zero-knowledge proofs. This paper surveys the landscape of PSPACE, examines the three fundamental barriers preventing resolution, and presents original systems-level experiments in C and Python that make the space-time tradeoff at the heart of the problem tangible and measurable.
Background: Healthcare organizations face unprecedented challenges in maintaining process compliance due to increasingly federated data and systems topologies, coupled with complex state, federal, and jurisdictional regulatory compliance and verification requirements. The emergence of distributed ledger technology (DLT) and artificial intelligence presents both transformative opportunities and significant compliance challenges. These emerging technologies enable computing paradigms that shift toward data locality models where computational models meet the data rather than moving sensitive patient information across organizational boundaries. This computational approach offers innovative pathways to mitigate data breach risks, while simultaneously introducing new verification complexities as the underlying technologies continue to advance: healthcare entities must cryptographically prove that operations performed on locally-held data were executed according to approved specifications while enabling selective disclosure capabilities across entity lines. However, traditional verification mechanisms lack the cryptographic guarantees necessary for these privacy-preserving, multi-entity healthcare workflows, creating substantial risks in clinical decision-making, patient privacy, and regulatory adherence. Objective: This paper introduces the ZK-PRET Business Process Prover framework that integrates Object Management Group (OMG) business process standards with zero-knowledge cryptographic verification to enable privacy-preserving healthcare process compliance across distributed systems. Methods: We developed a multi-layer architecture combining formal business process modeling, zero-knowledge proof generation, and regulatory compliance verification. The framework extends established OMG standards with cryptographic verification capabilities to achieve verifiable compliance, privacy preservation, and regulatory accountability. Implementation testing was conducted in synthetic data environments designed to represent real-world healthcare scenarios.¹ These environments enable comprehensive modeling and testing of multi-entity process orchestration patterns while maintaining privacy protections essential for healthcare research and development. All scenarios, clinical examples, and process expressions presented in this paper utilize synthetic data to ensure no real patient data, clinical records, or identifiable health information was used. Results: The ZK-PRET Business Process Prover framework demonstrates practical applicability across many healthcare domains including treatment planning, telemedicine coordination, healthcare administration, consumer health services, multi-entity clinical trials, and supply chain management. Implementation results demonstrate cryptographic verification capabilities that enable mathematical prevention of regulatory violations rather than post-hoc detection. The results demonstrate configurable privacy preservation through zero-knowledge verification and consistent proof sizes suitable for modeling complex orchestrations, while leveraging already widely used Web 2 process models, suitable for multiple runtime deployment topologies. Conclusions: Zero-knowledge healthcare process verification represents a foundational technology for regulatory compliance in distributed healthcare systems. While agentic AI systems present important opportunities for automation, the underlying requirement for verifiable process compliance through cryptographic means brings broader challenges. ZK-PRET Business Process Prover addresses these challenges in healthcare transformative flows, enabling safer deployment of autonomous systems while maintaining regulatory standards.
Abstract:The pervasive integration of digital technologies has fundamentally redefined the operational paradigms of commerce, finance, and accounting. This paper explores the multidimensional impact of Digital Transformation (DT) across these interconnected sectors, focusing on the adoption and efficacy of Artificial Intelligence (AI), Robotic Process Automation (RPA), and Blockchain technology. Through a systematic qualitative review of recent literature and industry frameworks, this study examines how traditional financial workflows are evolving into automated, data-driven ecosystems. The findings indicate that while DT significantly enhances real-time reporting, fraud detection, and transactional efficiency, organizations face substantial barriers, including high implementation costs, data security vulnerabilities, and a growing digital skills gap. The paper concludes that successful digital transformation requires not only technological investment but also a strategic realignment of organizational culture and regulatory compliance frameworks. Future research trajectories emphasize the need for standardized continuous auditing protocols and scalable decentralized finance (DeFi) architectures.
The article examines the role of digital transformation as a key factor in strengthening the economic and legal resilience of Ukrainian cities in the context of global competition, governance decentralization, and unprecedented geopolitical challenges. It is substantiated that the digitalization of municipal governance is becoming an important tool for increasing the adaptability of local economic systems, ensuring the continuity of public services, and creating a transparent legal environment for business activities. Particular attention is paid o the concept of “digital legal immunity,” which is defined as an integrated system of technological, organizational, and regulatory mechanisms aimed at ensuring the protection, autonomy, and stability of critical municipal data and information infrastructure. The study analyzes the impact of modern digital instruments, including cloud-based registries, automated electronic document management systems, blockchain solutions in property and land relations, and digital platforms for interaction between public authorities, businesses, and citizens. It is demonstrated that the implementation of such tools contributes to reducing transaction costs, lowering administrative barriers, increasing transparency in governance procedures, and minimizing corruption risks. The paper argues that the integration of digital technologies into local regulatory development programs, particularly within initiatives such as “Digital City” and “Digital Community,” helps create a predictable regulatory environment, stimulates capital circulation, and enhances the investment attractiveness of territories. Based on the analysis of digitalization practices in leading Ukrainian cities (Kryvyi Rih, Dnipro, Ternopil, Uzhhorod, Vinnytsia, Lviv, and Kharkiv), the study systematizes strategies for the capitalization of digital assets and identifies their impact on the economic and legal sustainability of urban systems. Three key levels of institutional support for digital transformation are distinguished: strategic planning and regulatory legitimization of digital initiatives; the creation of local regulatory sandboxes for testing innovative technological solutions; and the regulation of digital interaction between local authorities, residents, and business entities. It is proven that under decentralization conditions, digitalization gradually transforms the city into an autonomous digital governance entity capable of responding promptly to external challenges, mitigating the risks associated with centralized management systems, and ensuring the uninterrupted functioning of municipal services even during crisis or wartime conditions. The obtained results highlight the systemic role of digital transformation in strengthening the economic and legal resilience of Ukrainian cities and outline promising directions for further research related to the quantitative assessment of the impact of digital platforms on governance risks, investment attractiveness, and the stability of local economies.
Blockchain and decentralized finance have revolutionized the financial ecosystem while simultaneously exposing it to cryptocurrency phishing attacks. Existing phishing detection methods primarily rely on graph learning, but they face significant limitations. Static graph learning approaches fail to account for the temporal evolution of phishing patterns, while semi-dynamic methods, such as those combining static GNNs with LSTM, struggle to capture the irregular and bursty nature of blockchain transactions. Moreover, these methods overlook the diversity of Ethereum transactions, treating them as homogeneous graphs, and heavily rely on supervised learning, which requires extensive labeled data that is not readily available. These limitations reduce their adaptability to emerging phishing threats. In this paper, we present PhishEye, a fully dynamic self-supervised system that monitors on-chain transactions to detect phishing activities. PhishEye formulates Ethereum transactions as a heterogeneous temporal attributed multi-graph and incorporates a novel temporal graph contrastive learning model, which captures both temporal patterns and heterogeneous transaction types. The evaluation on a dataset of 161,658 addresses and 416,541 transactions shows that PhishEye outperforms existing methods, achieving an F1 score of 87.23% and an AUC of 98.43% for phishing transaction detection, and an F1 score of 94.19% and an AUC of 98.03% for phishing account detection. In real-world deployment from May 1, 2023 to July 31, 2024, PhishEye identified 1,803 previously unknown phishing addresses, providing early alerts that helped prevent losses exceeding 2 billion USD.
The rapid advancement of blockchain technology has given rise to Decentralized Finance (DeFi), a financial ecosystem that operates without traditional intermediaries and challenges the foundational structures of conventional banking. DeFi platforms enable peer-to-peer financial services through smart contracts, offering increased transparency, accessibility, and efficiency. This study aims to analyze the potential of DeFi to disrupt traditional banking models by examining its core mechanisms, value propositions, and structural differences from centralized financial institutions. The research seeks to assess both the opportunities and challenges posed by DeFi in reshaping financial intermediation. A qualitative analytical approach was employed, drawing on an integrative review of peer-reviewed literature, industry reports, and documented DeFi case examples. Data were analyzed through thematic synthesis to compare DeFi functionalities with traditional banking operations, focusing on governance, risk management, and financial inclusion. The findings indicate that DeFi introduces innovative financial models that reduce transaction costs, expand access to financial services, and enhance operational transparency. The study concludes that DeFi represents a transformative yet complementary force rather than a complete replacement for traditional banking. Its future impact will depend on regulatory adaptation, technological maturity, and institutional integration.
Evaluating the true forecasting ability of AI agents requires environments that are resistant to environments resistant to overfitting, free from centralized trust, and grounded in incentive-compatible scoring. Existing benchmarks either rely on static datasets vulnerable to training-data contamination, or measure trading PnL -- a metric conflating predictive accuracy with timing, sizing, and risk appetite. We introduce Foresight Arena, the first permissionless, on-chain benchmark for evaluating AI forecasting agents on real-world prediction markets. Agents submit probabilistic forecasts on binary Polymarket markets via a commit-reveal protocol enforced by Solidity smart contracts on Polygon PoS; outcomes are resolved trustlessly through the Gnosis Conditional Token Framework. Performance is measured by the Brier Score and a novel Alpha Score -- proper scoring rules that incentivize honest probability reporting and isolate predictive edge over market consensus. We provide a formal analysis: closed-form variance for per-market Alpha, the connection to Murphy's classical Brier decomposition, and a power analysis characterizing the number of rounds required to reliably distinguish agents of different skill levels. We show that detecting a true edge of $α^* = 0.02$ at 80% power requires approximately 350 resolved binary predictions (50 rounds of 7 markets), while $α^* = 0.01$ requires four times more. We complement these analytical results with a deterministic, seed-controlled simulation study calibrated to literature-reported Brier-score ranges, illustrating how Murphy decomposition distinguishes well-calibrated agents from market-tracking agents that fail through reduced resolution. Live results from the deployed benchmark will be reported in a future revision. All smart contracts and evaluation infrastructure are open-source.
An agent skill is a configuration package that equips an LLM-driven agent with a concrete capability, such as reading email, executing shell commands, or signing blockchain transactions. Each skill is a hybrid artifact-a structured half declares executable interfaces, while a prose half dictates when and how those interfaces fire-and the prose is reinterpreted probabilistically on every invocation. Conventional static analyzers parse the structured half but ignore the prose; LLM-based tools read the prose but cannot reproducibly prove that a tainted input reaches a high-impact sink. We present Semia, a static auditor for agent skills. Semia lifts each skill into the Skill Description Language (SDL), a Datalog fact base that captures LLM-triggered actions, prose-defined conditions, and human-in-the-loop checkpoints. Synthesizing a fact base that is both structurally sound and semantically faithful to the original prose is the central challenge; we address it with Constraint-Guided Representation Synthesis (CGRS), a propose-verify-evaluate loop that refines LLM candidates until convergence. Security properties (e.g., indirect injection, secret leakage, confused deputies, unguarded sinks, etc.) over an agent skill can then be reduced to Datalog reachability queries. We evaluate Semia on 13,728 real-world skills from public marketplaces. Semia renders all of them auditable and finds that more than half carry at least one critical semantic risk. On a stratified sample of 541 expert-labeled skills, Semia achieves 97.7% recall and an F1 of 90.6%, substantially outperforming signature-based scanners and LLM baselines.
Abstract This paper presents two offline, on-premise NLP proof-of-concept assistants built on a shared architecture for internal knowledge access in the Central Bank of Bosnia and Herzegovina: (i) a semantic document search tool for internal Word/PDF repositories and (ii) an HR chatbot that applies retrieval-augmented generation (RAG) over indexed HR policies and procedures. Rather than proposing a novel NLP method, the paper contributes by documenting a reusable offline architecture for institutional AI assistants in a security-constrained central banking environment and by providing pilot evidence on how established semantic retrieval and RAG techniques can be adapted to strict requirements of confidentiality, data sovereignty, and governance. The semantic search assistant combines exact phrase matching with embedding-based retrieval and hybrid re-ranking, while the HR chatbot generates source-grounded answers using locally hosted language models under explicit governance constraints, including B/H/S-only output, strict fallback behaviour, and transparent display of retrieved passages. Pilot results indicate that hybrid retrieval offers the most reliable performance across representative internal queries, while the HR chatbot demonstrates the feasibility of document-grounded employee support under offline institutional constraints. The findings provide preliminary evidence that offline NLP assistants can improve access to internal institutional knowledge while remaining compatible with the security and operational risk requirements typical of central banking environments.