I Made ScamLens So My Family Could Check Suspicious Messages Without Sending Them to the Cloud
This is my submission for the Hacktoberfest 2026 Weekend Challenge: Build for a Friend . What I Built My family gets scam messages all the time. Fake bank alerts. KYC requests. Delivery messages asking for customs fees. Messages from unknown numbers pretending to be someone we know. Even fake police or cybercrime notices threatening arrest unless money is paid immediately. Most people in my…
I crafted a scam detection tool called ScamLens to help my family identify suspicious messages without sending them to the cloud. The app analyses messages and screenshots locally, providing an explanation of why it considers the message suspicious or legitimate. Crucially, it doesn't require sending the message to a cloud AI service; the analysis happens on the user's own machine.
I demonstrated the app with three scenarios: a phishing message from a bank, a social engineering scam without a suspicious link, and a legitimate OTP security notification. The OTP case proved particularly valuable, as it revealed a bug in the system.
The model initially flagged the OTP as suspicious, citing urgency and instructions not to share the code. However, upon closer inspection, the security checks found no red flags. The issue stemmed from the model treating "Valid for 5 minutes" as a coercive request, rather than a legitimate security warning. To fix this, I added semantic fields to distinguish between different types of messages, such as whether the sender is asking for a secret, warning against revealing a secret, or simply stating OTP validity and expiration.
The fix ensured that the OTP message was correctly classified as legitimate. This real-world test highlighted the importance of local, open-source AI for security tools like ScamLens. Running the model locally through Ollama allowed the analysis to happen on the user's device, without relying on a cloud AI API. This approach also provided flexibility in combining deterministic security checks with a decision engine to produce the final verdict.
The project demonstrates the benefits of open innovation in creating security tools that handle sensitive information locally, giving users control over their data and ensuring the tool's reliability.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.