This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass
What I Built
Almost the entire India runs on QR codes. From small shops to big ones, all have got one, attached somewhere or other. But just scanning the QR code was never enough. For example: A 2D QR matrix is human-unreadable. Unlike a hyperlink, victims cannot inspect the payee address, domain, or pre-filled transaction amounts before acting. Me and my friends built something useful.
We created TrailQR Raksha that is a privacy-first, offline-capable QR security guard built for street environments across West Bengal. Deterministic rules decide. Google Gemma 4 explains in English and vernacular Bengali. Zero sensitive data leaves your phone unsanitised. And Snowflake CoCo aggregates neighborhood threat patterns.
Point your phone at a QR code and it checks it for you:
- Simple rules decide whether a QR looks safe or suspicious.
- Google Gemma 4 explains why, in English and in Bengali.
- Your private details stay on your phone. Anything sensitive is cleaned before it goes anywhere.
- Snowflake CoCo spots scam patterns across neighbourhoods.
And since a QR code only exists out in the real world, you have to go outside, find one and scan it. No sitting in your room with this one :))
Demo
Honestly, you're lucky my friends deployed this. Left to me, I'd have told you to deploy it yourself. I'm a DIVA, after all. 💅
Just kidding! It's live here: qr-raksha.vercel.app. Try it yourself instead of taking our word for it.
Code
TrailQR Raksha — Check a QR Before You Pay
Kolkata — and India — runs on QR codes. Tea stalls, taxis, parking, donations, ticket counters: you scan, you pay, you move on. One sticker pasted over a shop's real QR and your payment goes to a scammer, or a "KYC verify" QR takes you to a credential phishing site. You cannot see where a QR goes until it is too late.
TrailQR Raksha is a privacy-first, offline-capable QR security guard built for street environments across West Bengal.
📑 Table of Contents
- Section 1: About the Project
- Section 2: Team Information
- Section 3: Open-Source License & Disclosures
📚 Judging & Hackathon Documentation
- 🎯 Live Judging Playbook: 3-minute pitch, live demo steps, and track defense answers.
- 📝 Official Submission Form: Ready-to-submit form with all 10…
How I Built It
- Frontend: plain HTML, CSS and JavaScript, no frameworks
-
Safety checks: simple rules that run on your device (
js/rules.js) - AI: Google Gemma 4, through the Gemini API, with an offline Ollama backup
- Data: Snowflake and Snowflake CoCo
-
Agent skill: published as an open-standard Agent Skill (
skills/qr-audit/SKILL.md)
You can add the skill to your own agent with one command:
npx skills add https://github.com/debangshuuii/QR-RAKSHA/tree/main/skills/qr-audit
Why Does Open Innovation Matter?
Okay, DIVA hat off for a minute. 😌
QR Raksha is made for someone standing at a stall in a lane with bad network, not someone sitting on fast Wi-Fi in a café. Open models made that possible:
- It works offline. Gemma 4 is open, so we could run it locally with Ollama. If the network drops, the guard stays on.
- Your data stays yours. We control exactly what leaves the phone, instead of just trusting someone else's server.
- It speaks Bengali. A warning nobody can read is useless. Plain Bengali explanations make it useful for shopkeepers, not just developers.
The rules are open too. Anyone can read them, question them and add new scam patterns. For a security tool, "read the code" beats "trust us".
One more thing: the AI never decides if a QR is safe. The rules do. Gemma only explains. We didn't want a chatbot confidently saying "looks fine!" about a scam.
Prize Categories
- Best Use of Gemma: Gemma 4 explains every scan in English and Bengali. It runs through the Gemini API, with an offline Ollama backup so it still works when the network doesn't.
- Snowflake: CoCo for neighbourhood scam patterns, plus a published Agent Skill
Team
Built with my friends, who actually believe in deploying things:
Now go touch some grass, and scan responsibly.


Top comments (1)
Post is more organized than repo right ?