devchallenge #weekendchallenge #hf26challenge
Hacktoberfest Weekend Challenge: Build for a Friend 🤝**
This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend
What I Built
I built ScamCheck for a friend who regularly receives suspicious bank, KYC, delivery, payment and account-warning messages and usually asks me:
GitHub: github.com/ansh-rajpoot/scamcheck
"Is this real or a scam?"
The problem is that simply asking an AI chatbot isn't enough.
A chatbot can confidently say "this looks like a scam", but that doesn't tell you why, what can actually be verified, or what is still unknown.
So I built something different.
ScamCheck investigates the message and shows the evidence.
Paste a suspicious SMS, WhatsApp message, email, or URL and ScamCheck breaks it into:
suspicious signals it directly observed
organizations and claims mentioned in the message
URLs and domains
external evidence found through web search
things that could not be verified
safe next steps
The AI doesn't get to invent evidence or blindly decide the answer.
How it works
DEMO
- The result looks more like a security investigation than a chatbot:
- Suspicious signals found
- Observed: "Your account will be blocked today"
- Observed: OTP requested
- Claimed organization: SBI
- External evidence: relevant official/public source
- Unverified: sender identity
- Recommended action: don't share the OTP; verify through the organization's official website/app instead.
There is deliberately no arbitrary "87% scam" score.
Evidence should be explainable, not a number invented by an LLM.
Why Local AI?
Scam messages can contain extremely sensitive information:
**
- - bank details
- - account suffixes
- - phone numbers
- - transaction information
- - names
- - addresses
- - payment information **
ScamCheck uses **Gemma 3 4B **through Ollama, so the AI analysis can run locally on the user's machine.
The entire private message doesn't need to be sent to an AI API just to understand it.
When external verification is useful, ScamCheck sends a minimal search query rather than the complete private message.
That's the part of open-weight AI that mattered to me: the user can actually keep the core analysis at home.
_**Why not just use an LLM?
Because an LLM shouldn't be trusted with facts it can determine more reliably using normal code.
**_
For example:
"Enter your OTP immediately"
can be detected deterministically.
So can:
Gemma is then used for the parts where language understanding is useful:
extracting claims
identifying claimed organizations
understanding requested actions
structuring the investigation
External search provides another layer of evidence.
The final report keeps those sources separate.
The Friend Test
The real test isn't whether ScamCheck produces a clever AI response.
It's whether my friend can paste a suspicious message and understand:
"What exactly is suspicious here, what was actually verified, and what should I do next?"
That's what I built it for.
Tech Stack
*Python
FastAPI
HTML/CSS/JavaScript
Ollama
Gemma 3 4B
SerpApi
*
The application runs locally, with the browser communicating with a local FastAPI server.
Open Source AI
The core AI runs through an open-weight model rather than requiring a proprietary hosted model for the analysis.
That means the model can be:
run locally
swapped for another open model
inspected and controlled by the developer
used without sending every private message to a third-party AI API
For a tool dealing with potentially sensitive messages, that difference matters.
What I Learned
The biggest lesson was that AI should not be the entire security system.
The useful architecture turned out to be:
deterministic code + local AI + external evidence
rather than:
send everything to an LLM and trust its verdict.
That made ScamCheck both more explainable and more useful.
Limitations
ScamCheck cannot guarantee that a message is legitimate or fraudulent.
External search results are evidence, not absolute proof.
It also does not automatically access WhatsApp, Gmail, Telegram, or other private accounts, and it does not automatically open suspicious URLs.
The goal is to help a person investigate safely—not pretend that an AI can know everything.
Prize Categories
Gemma — Best Use of Gemma
SerpApi — Best Use of SerpApi

Top comments (1)
Would love to hear your suggestions on this! What features or improvements do you think I should add next? Feel free to point out anything that could be better 👀