{
  "id": 12090483,
  "title": "I Made ScamLens So My Family Could Check Suspicious Messages Without Sending Them to the Cloud",
  "url": "https://urgent.news/2026/10/05/i-made-scamlens-so-my-family-could-check-suspicious-messages-without",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-05T06:22:18.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/ritinpaul_singh/i-made-scamlens-so-my-family-could-check-suspicious-messages-without-sending-them-to-the-cloud-4c24"
  },
  "original_language": "en",
  "account": "I crafted a scam detection tool called ScamLens to help my family identify suspicious messages without sending them to the cloud. The app analyses messages and screenshots locally, providing an explanation of why it considers the message suspicious or legitimate. Crucially, it doesn't require sending the message to a cloud AI service; the analysis happens on the user's own machine.\n\nI demonstrated the app with three scenarios: a phishing message from a bank, a social engineering scam without a suspicious link, and a legitimate OTP security notification. The OTP case proved particularly valuable, as it revealed a bug in the system.\n\nThe model initially flagged the OTP as suspicious, citing urgency and instructions not to share the code. However, upon closer inspection, the security checks found no red flags. The issue stemmed from the model treating \"Valid for 5 minutes\" as a coercive request, rather than a legitimate security warning. To fix this, I added semantic fields to distinguish between different types of messages, such as whether the sender is asking for a secret, warning against revealing a secret, or simply stating OTP validity and expiration.\n\nThe fix ensured that the OTP message was correctly classified as legitimate. This real-world test highlighted the importance of local, open-source AI for security tools like ScamLens. Running the model locally through Ollama allowed the analysis to happen on the user's device, without relying on a cloud AI API. This approach also provided flexibility in combining deterministic security checks with a decision engine to produce the final verdict.\n\nThe project demonstrates the benefits of open innovation in creating security tools that handle sensitive information locally, giving users control over their data and ensuring the tool's reliability.",
  "summary": "This is my submission for the Hacktoberfest 2026 Weekend Challenge: Build for a Friend . What I Built My family gets scam messages all the time. Fake bank alerts. KYC requests. Delivery messages asking for customs fees. Messages from unknown numbers pretending to be someone we know. Even fake police or cybercrime notices threatening arrest unless money is paid immediately. Most people in my…",
  "key_points": [
    "ScamLens app analyzes messages and screenshots locally without cloud AI",
    "Demonstrated with phishing, social engineering, and legitimate OTP scenarios",
    "Fix added semantic fields to distinguish message types for accurate classification"
  ],
  "editors_take": "This development shows that locally run, open-source AI can enhance security and reliability in tools like ScamLens, giving users control over their sensitive information and data.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}