<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Akash Jha</title>
    <description>The latest articles on DEV Community by Akash Jha (@akashjha518).</description>
    <link>https://dev.to/akashjha518</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4156796%2F06e205fb-276e-49d7-995d-2723ad56778f.png</url>
      <title>DEV Community: Akash Jha</title>
      <link>https://dev.to/akashjha518</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/akashjha518"/>
    <language>en</language>
    <item>
      <title>I Built CyberBuddy: A Local AI Cybersecurity Assistant for Non-Technical Users</title>
      <dc:creator>Akash Jha</dc:creator>
      <pubDate>Mon, 05 Oct 2026 06:14:42 +0000</pubDate>
      <link>https://dev.to/akashjha518/i-built-cyberbuddy-a-local-ai-cybersecurity-assistant-for-non-technical-users-5028</link>
      <guid>https://dev.to/akashjha518/i-built-cyberbuddy-a-local-ai-cybersecurity-assistant-for-non-technical-users-5028</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkg0wr4ytwcu97wqgsc78.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkg0wr4ytwcu97wqgsc78.png" alt="CyberBuddy analyzing a suspicious phishing message with AI-powered risk assessment and security guidance." width="800" height="450"&gt;&lt;/a&gt;&lt;br&gt;
Have you ever received a message saying:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"URGENT! Your bank account will be blocked. Verify your account immediately."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Or clicked a link and wondered:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Is this website actually safe?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For someone with a cybersecurity background, these messages can contain obvious warning signs. But for a non-technical person, understanding those warning signs isn't always easy.&lt;br&gt;
That's the problem I wanted to solve with CyberBuddy.&lt;br&gt;
CyberBuddy is a local AI-powered cybersecurity assistant that helps non-technical users understand suspicious messages and URLs and decide what they should do next.&lt;br&gt;
This project was built for the Hacktoberfest Weekend Challenge: Build for a Friend.&lt;/p&gt;
&lt;h2&gt;
  
  
  The Problem
&lt;/h2&gt;

&lt;p&gt;Cybersecurity advice is often written for technical users.&lt;br&gt;
Terms like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;phishing&lt;/li&gt;
&lt;li&gt;credential harvesting&lt;/li&gt;
&lt;li&gt;suspicious indicators&lt;/li&gt;
&lt;li&gt;malicious URLs&lt;/li&gt;
&lt;li&gt;account takeover&lt;/li&gt;
&lt;li&gt;social engineering&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;can be confusing to someone who doesn't work in cybersecurity.&lt;/p&gt;

&lt;p&gt;A person receiving a suspicious message doesn't necessarily need a complicated security report.&lt;br&gt;
They need answers to simple questions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Is this suspicious?&lt;/li&gt;
&lt;li&gt;Why does it look suspicious?&lt;/li&gt;
&lt;li&gt;What should I avoid doing?&lt;/li&gt;
&lt;li&gt;What should I do next?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That's where CyberBuddy comes in.&lt;/p&gt;
&lt;h2&gt;
  
  
  Meet CyberBuddy
&lt;/h2&gt;

&lt;p&gt;CyberBuddy is designed around a simple idea:&lt;br&gt;
Give people understandable security guidance without requiring them to understand cybersecurity terminology.&lt;/p&gt;

&lt;p&gt;The current MVP supports two types of analysis:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Suspicious Message Analyzer&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A user can paste a suspicious email or message.&lt;br&gt;
For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;URGENT! Your bank account will be blocked.
Please provide your OTP immediately at
https://example.com/login
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;CyberBuddy analyzes the message and identifies indicators such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;urgent or pressure-based language&lt;/li&gt;
&lt;li&gt;credential requests&lt;/li&gt;
&lt;li&gt;financial information requests&lt;/li&gt;
&lt;li&gt;account access threats&lt;/li&gt;
&lt;li&gt;URLs&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It then calculates a risk level and score.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Suspicious URL Analyzer&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Users can also enter a URL directly.&lt;br&gt;
For example:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;http://192.168.1.10/login
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;CyberBuddy can identify indicators such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;HTTP instead of HTTPS&lt;/li&gt;
&lt;li&gt;IP address used instead of a domain&lt;/li&gt;
&lt;li&gt;security-sensitive keywords such as login&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The URL is then assigned a risk score based on the detected indicators.&lt;/p&gt;
&lt;h2&gt;
  
  
  How CyberBuddy Works
&lt;/h2&gt;

&lt;p&gt;One of the most important design decisions I made was to separate security analysis from AI explanation.&lt;br&gt;
The architecture looks like this:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;              User Input
                  │
                  ▼
        ┌─────────────────────┐
        │ Deterministic       │
        │ Security Analysis   │
        └──────────┬──────────┘
                   │
                   ▼
        ┌─────────────────────┐
        │ Evidence Detection  │
        └──────────┬──────────┘
                   │
                   ▼
        ┌─────────────────────┐
        │ Risk Assessment     │
        │ + Risk Score        │
        └──────────┬──────────┘
                   │
                   ▼
        ┌─────────────────────┐
        │ Gemma 3 4B          │
        │ Local AI            │
        └──────────┬──────────┘
                   │
                   ▼
        ┌─────────────────────┐
        │ Simple Explanation  │
        │ + Safe Actions      │
        └─────────────────────┘
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;The important part is:&lt;br&gt;
Gemma does not decide the security risk.&lt;/p&gt;

&lt;p&gt;The deterministic CyberBuddy analyzers and risk engines are responsible for detecting indicators and calculating the risk.&lt;br&gt;
Gemma receives that existing analysis and explains it in simple language.&lt;br&gt;
This makes the AI an explanation layer, rather than the authority making the security decision.&lt;/p&gt;
&lt;h2&gt;
  
  
  Why I Used Gemma 3 4B
&lt;/h2&gt;

&lt;p&gt;For the AI component, I chose Gemma 3 4B running locally through Ollama.&lt;br&gt;
The reason was simple: I wanted CyberBuddy's AI functionality to work locally without requiring an external API key.&lt;/p&gt;

&lt;p&gt;The setup is:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;CyberBuddy
     │
     ▼
Ollama
     │
     ▼
Gemma 3 4B
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Gemma receives the structured security analysis generated by CyberBuddy.&lt;br&gt;
For example:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Risk: CRITICAL
Risk Score: 95
Possible Attack: Phishing

Indicators:
- Urgent language
- Credential request
- Account access threat
- Suspicious URL
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Gemma then turns that technical information into something a normal user can understand.&lt;br&gt;
For example:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;This message is highly suspicious because it creates urgency, requests sensitive information, and threatens account access. Do not click the link or provide your OTP or password.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The model runs locally, so the AI explanation doesn't require sending the analysis to a third-party AI API.&lt;/p&gt;
&lt;h2&gt;
  
  
  Example: Message Analysis
&lt;/h2&gt;

&lt;p&gt;Here's an example of the message analyzer detecting a phishing-style message.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv7uas13ujmn99v9qquvf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv7uas13ujmn99v9qquvf.png" alt="CyberBuddy analyzing a suspicious message and detecting a critical phishing risk." width="800" height="465"&gt;&lt;/a&gt;&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;URGENT! Your bank account will be blocked.
Please provide your OTP immediately at
https://example.com/login
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;CyberBuddy produced:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjja6x0tzs9cwu2b3be0n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjja6x0tzs9cwu2b3be0n.png" alt="CyberBuddy detecting a critical phishing risk with AI-powered security analysis and safe-action guidance." width="800" height="465"&gt;&lt;/a&gt;&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Risk: CRITICAL
Risk Score: 95/100
Possible Attack: Phishing
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;It also detected multiple indicators:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Urgent or pressure-based language
Credential or verification information requested
Financial or payment information requested
Account access threat detected
URL detected
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;The recommended actions include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Don't click the link until it has been verified.&lt;/li&gt;
&lt;li&gt;Don't provide passwords, OTPs, PINs, or verification codes.&lt;/li&gt;
&lt;li&gt;Don't share banking or card information.&lt;/li&gt;
&lt;li&gt;Verify the warning through the organization's official website or application.
Gemma then explains these findings in simple language.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flld2y2h2pogvzzhpquxs.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flld2y2h2pogvzzhpquxs.png" alt="CyberBuddy AI explaining a critical phishing risk and providing safe, practical guidance.” dev-to-uploads.s3.us-east-2.amazonaws.com" width="800" height="465"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Example: URL Analysis
&lt;/h2&gt;

&lt;p&gt;CyberBuddy can also analyze a URL independently.&lt;br&gt;
For example:&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpj89z4mx6jezqy2nc7lv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpj89z4mx6jezqy2nc7lv.png" alt="CyberBuddy analyzing a suspicious URL and identifying a medium security risk." width="800" height="465"&gt;&lt;/a&gt;&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;http://192.168.1.10/login
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;The result was:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Risk: MEDIUM
Risk Score: 40/100

Hostname: 192.168.1.10
Protocol: HTTP
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Detected indicators:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxo93in6qmmb33pc9mqy4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxo93in6qmmb33pc9mqy4.png" alt="CyberBuddy AI explaining a medium-risk URL and its detected security indicators" width="800" height="465"&gt;&lt;/a&gt;&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;URL does not use HTTPS
IP address used instead of a domain name
Security-sensitive keyword detected: login
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Gemma then explains why these indicators matter and provides practical guidance.&lt;br&gt;
The goal isn't to tell the user:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"This website is definitely malicious."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Instead, CyberBuddy explains:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"These indicators suggest that the website may not be trustworthy. Be cautious and avoid entering sensitive information until the website has been independently verified."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That's an important distinction.&lt;/p&gt;
&lt;h2&gt;
  
  
  Fail-Safe AI Design
&lt;/h2&gt;

&lt;p&gt;Another design decision was making the AI component optional.&lt;br&gt;
If Ollama isn't running, CyberBuddy's deterministic analysis should still work.&lt;br&gt;
The architecture therefore behaves like this:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Ollama available
       │
       ▼
Risk Analysis → Gemma → Explanation
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;But if Ollama is unavailable:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Ollama unavailable
       │
       ▼
Risk Analysis → Normal Result
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;The application doesn't depend entirely on the AI model to function.&lt;br&gt;
This also keeps the security analysis predictable.&lt;/p&gt;
&lt;h2&gt;
  
  
  Technology Stack
&lt;/h2&gt;

&lt;p&gt;CyberBuddy currently uses:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Python
FastAPI
JavaScript
HTML
CSS
Ollama
Gemma 3 4B
Pytest
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;Backend&lt;/strong&gt;&lt;br&gt;
The backend is built with FastAPI.&lt;br&gt;
It provides endpoints for:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;POST /api/analyze/message
POST /api/analyze/url
GET  /health
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;Frontend&lt;/strong&gt;&lt;br&gt;
The frontend is a lightweight HTML/CSS/JavaScript interface.&lt;br&gt;
Users can switch between:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Message
URL
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;and receive the analysis directly in the browser.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Testing&lt;/strong&gt;&lt;br&gt;
The project currently has automated tests covering:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;message analysis&lt;/li&gt;
&lt;li&gt;message risk engine&lt;/li&gt;
&lt;li&gt;URL analysis&lt;/li&gt;
&lt;li&gt;URL risk engine
Current test result:
&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;=============================== test session starts ================================
platform win32 -- Python 3.10.11, pytest-9.1.1, pluggy-1.6.0
rootdir: B:\Hacktoberfest\Cyberbuddy
plugins: anyio-4.15.1
collected 39 items                                                                  

tests\test_message_analyzer.py ..............                                 [ 35%]
tests\test_risk_engine.py .....                                               [ 48%]
tests\test_url_analyzer.py ..............                                     [ 84%]
tests\test_url_risk_engine.py ......                                          [100%]

================================ 39 passed in 0.15s ================================
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;h2&gt;
  
  
  Building for a Non-Technical User
&lt;/h2&gt;

&lt;p&gt;The most important part of this project wasn't just adding AI.&lt;/p&gt;

&lt;p&gt;It was thinking about how a non-technical person would use it.&lt;/p&gt;

&lt;p&gt;A security tool can detect dozens of technical indicators, but displaying all of them without context doesn't necessarily help someone.&lt;/p&gt;

&lt;p&gt;CyberBuddy therefore tries to translate:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Technical Evidence
       ↓
Simple Explanation
       ↓
Practical Action
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Credential request detected
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;becomes:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"The message is asking for sensitive information such as a password or OTP. Legitimate organizations generally shouldn't ask you to provide these through suspicious links or messages."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The goal is to make security guidance easier to understand and act upon.&lt;/p&gt;
&lt;h2&gt;
  
  
  What I Learned
&lt;/h2&gt;

&lt;p&gt;Building CyberBuddy taught me several things beyond simply connecting an AI model to an application.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. AI shouldn't always be the decision-maker&lt;/strong&gt;&lt;br&gt;
For security-related applications, deterministic rules can provide a predictable foundation while AI can make the results easier to understand.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Local AI is practical&lt;/strong&gt;&lt;br&gt;
Running Gemma through Ollama made it possible to add an AI explanation layer without requiring an external API.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. User experience matters&lt;/strong&gt;&lt;br&gt;
A technically accurate security result isn't enough if the person using the application doesn't understand what it means.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Testing matters even for small projects&lt;/strong&gt;&lt;br&gt;
The project currently has:&lt;br&gt;
&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;39 automated tests
39 passing
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;This helped me make changes while ensuring the existing analyzers continued to work.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;5. Building for a real person changes how you think&lt;/strong&gt;&lt;br&gt;
Instead of asking:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"What cybersecurity feature can I add?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I started asking:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"What would actually help someone when they receive a suspicious message?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That changed the direction of the project.&lt;/p&gt;
&lt;h2&gt;
  
  
  What's Next?
&lt;/h2&gt;

&lt;p&gt;CyberBuddy is currently an MVP, so there is plenty of room for improvement.&lt;br&gt;
Some things I'd like to explore next:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Security alert/log analysis&lt;/li&gt;
&lt;li&gt;More sophisticated URL detection&lt;/li&gt;
&lt;li&gt;Additional phishing indicators&lt;/li&gt;
&lt;li&gt;Better AI response formatting&lt;/li&gt;
&lt;li&gt;More automated tests&lt;/li&gt;
&lt;li&gt;SOC-oriented alert explanations&lt;/li&gt;
&lt;li&gt;MITRE ATT&amp;amp;CK mapping for relevant security indicators&lt;/li&gt;
&lt;li&gt;More accessible UI for non-technical users&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal is to gradually turn CyberBuddy from a simple analyzer into a more useful personal cybersecurity assistant.&lt;/p&gt;
&lt;h2&gt;
  
  
  Try CyberBuddy
&lt;/h2&gt;

&lt;p&gt;The project is available on GitHub:&lt;/p&gt;


&lt;div class="ltag-github-readme-tag"&gt;
  &lt;div class="readme-overview"&gt;
    &lt;h2&gt;
      &lt;img src="https://assets.dev.to/assets/github-logo-5a155e1f9a670af7944dd5e12375bc76ed542ea80224905ecaf878b9157cdefc.svg" alt="GitHub logo"&gt;
      &lt;a href="https://github.com/akashjha518" rel="noopener noreferrer"&gt;
        akashjha518
      &lt;/a&gt; / &lt;a href="https://github.com/akashjha518/CyberBuddy" rel="noopener noreferrer"&gt;
        CyberBuddy
      &lt;/a&gt;
    &lt;/h2&gt;
    &lt;h3&gt;
      CyberBuddy is an AI-powered cybersecurity assistant that helps non-technical users analyze suspicious messages and URLs, assess security risks, and understand threats through local Gemma 3 4B AI running with Ollama.
    &lt;/h3&gt;
  &lt;/div&gt;
  &lt;div class="ltag-github-body"&gt;
    
&lt;div id="readme" class="md"&gt;&lt;div class="markdown-heading"&gt;
&lt;h1 class="heading-element"&gt;🛡️ CyberBuddy&lt;/h1&gt;
&lt;/div&gt;

&lt;div class="markdown-heading"&gt;
&lt;h3 class="heading-element"&gt;AI-Powered Cybersecurity Assistant for Non-Technical Users&lt;/h3&gt;
&lt;/div&gt;

&lt;p&gt;CyberBuddy is a local, AI-powered cybersecurity assistant designed to help non-technical users understand and respond to suspicious messages and URLs.&lt;/p&gt;

&lt;p&gt;Instead of requiring cybersecurity knowledge, CyberBuddy analyzes potentially dangerous content, identifies security indicators, assigns a risk level, and explains the result in simple language.&lt;/p&gt;

&lt;p&gt;The project uses deterministic security analysis for risk assessment and &lt;strong&gt;Gemma 3 4B&lt;/strong&gt;, running locally through &lt;strong&gt;Ollama&lt;/strong&gt;, as an AI explanation layer.&lt;/p&gt;




&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;🚀 Why CyberBuddy?&lt;/h2&gt;
&lt;/div&gt;

&lt;p&gt;Cybersecurity warnings are often difficult for non-technical users to understand.&lt;/p&gt;

&lt;p&gt;A suspicious message may contain:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Urgent requests&lt;/li&gt;
&lt;li&gt;Phishing links&lt;/li&gt;
&lt;li&gt;Requests for passwords or OTPs&lt;/li&gt;
&lt;li&gt;Fake account warnings&lt;/li&gt;
&lt;li&gt;Financial requests&lt;/li&gt;
&lt;li&gt;Suspicious URLs&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;CyberBuddy provides a simple workflow:&lt;/p&gt;

&lt;div class="snippet-clipboard-content notranslate position-relative overflow-auto"&gt;&lt;pre class="notranslate"&gt;&lt;code&gt;Suspicious Message / URL
          ↓
   Security Analysis
          ↓
    Risk Assessment
          ↓
      Evidence
          ↓
    Gemma 3 4B AI
          ↓
 Simple Explanation
          ↓
    Safe Actions
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;✨ Features&lt;/h2&gt;

&lt;/div&gt;

&lt;div class="markdown-heading"&gt;
&lt;h3 class="heading-element"&gt;📩 Suspicious Message Analyzer&lt;/h3&gt;

&lt;/div&gt;

&lt;p&gt;Analyze suspicious emails, SMS messages, and…&lt;/p&gt;&lt;/div&gt;


&lt;/div&gt;
&lt;br&gt;
  &lt;div class="gh-btn-container"&gt;&lt;a class="gh-btn" href="https://github.com/akashjha518/CyberBuddy" rel="noopener noreferrer"&gt;View on GitHub&lt;/a&gt;&lt;/div&gt;
&lt;br&gt;
&lt;/div&gt;
&lt;br&gt;


&lt;p&gt;To run the project locally, you'll need Python, Ollama, and Gemma 3 4B.&lt;br&gt;
The basic AI setup is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ollama pull gemma3:4b
ollama run gemma3:4b
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then start the CyberBuddy backend:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;uvicorn backend.main:app --reload --port 8000
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Open the frontend and start analyzing suspicious messages or URLs.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;Cybersecurity doesn't have to be understandable only to cybersecurity professionals.&lt;br&gt;
Sometimes the most useful security tool is one that simply answers:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Here's why this looks suspicious, and here's what you should do next."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That's what I wanted CyberBuddy to provide.&lt;br&gt;
I'm excited to build on this project and continue exploring how local open-weight AI can make cybersecurity guidance more accessible to everyday users.&lt;br&gt;
Thanks to the Hacktoberfest Weekend Challenge: Build for a Friend for encouraging developers to build something around a genuine problem faced by someone else.&lt;/p&gt;

</description>
      <category>hf26challenge</category>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>gemma</category>
    </item>
  </channel>
</rss>
