<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Tasha · DataSec Chronicles</title>
    <description>The latest articles on DEV Community by Tasha · DataSec Chronicles (@data_secchronicles).</description>
    <link>https://dev.to/data_secchronicles</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F239818%2Fb22d5cf6-8479-4113-9f15-cbff48cd7a5b.JPG</url>
      <title>DEV Community: Tasha · DataSec Chronicles</title>
      <link>https://dev.to/data_secchronicles</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/data_secchronicles"/>
    <language>en</language>
    <item>
      <title>Does This Belong Here? I Built a Phishing Checker for the People I Love</title>
      <dc:creator>Tasha · DataSec Chronicles</dc:creator>
      <pubDate>Sat, 03 Oct 2026 16:04:20 +0000</pubDate>
      <link>https://dev.to/data_secchronicles/does-this-belong-here-i-built-a-phishing-checker-for-the-people-i-love-3ei7</link>
      <guid>https://dev.to/data_secchronicles/does-this-belong-here-i-built-a-phishing-checker-for-the-people-i-love-3ei7</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a submission for the &lt;a href="https://dev.to/challenges/hacktoberfest-weekend-2026-10-01"&gt;Hacktoberfest Weekend Challenge: Build for a Friend&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Built
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;"Does This Belong Here?"&lt;/strong&gt; — a friendly phishing checker for the people in my life who still get spam.&lt;/p&gt;

&lt;p&gt;I built it for my mom and my husband. They both know the basic rule — &lt;em&gt;don't click suspicious links&lt;/em&gt; — but nobody ever explained the &lt;em&gt;why&lt;/em&gt;, and the why is the part that actually protects you in the moment. When a real scam email lands, dressed up to look urgent and official, the rule evaporates, and the panic takes over.&lt;/p&gt;

&lt;p&gt;This tool closes that gap.&lt;/p&gt;

&lt;p&gt;You paste in an email or text that feels off, and it walks you through it the way a security analyst would — in plain English, no jargon. It gives a one-line verdict, a short list of the red flags it spotted &lt;em&gt;and why each one matters&lt;/em&gt; (the threat behind it), and one calm next step.&lt;/p&gt;

&lt;p&gt;Every answer ends with the question that keeps you safe:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Does this belong here?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It's not trying to make anyone a security expert. It's trying to hand them the &lt;em&gt;instinct&lt;/em&gt; — the same "does this belong here?" question a SOC analyst asks on every alert, pointed at their own inbox.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I handed it to my husband. Here's what happened.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is the part I care about most, because the challenge is &lt;em&gt;Build for a Friend&lt;/em&gt; — so I actually gave it to one.&lt;/p&gt;

&lt;p&gt;I set it up and let my husband loose on it with a real email. He copied a whole message, pasted it into the box... and then tried to &lt;em&gt;click the box&lt;/em&gt;, expecting something to happen.&lt;/p&gt;

&lt;p&gt;I had to point him to the "Check it for me" button.&lt;/p&gt;

&lt;p&gt;Noted. 😂&lt;/p&gt;

&lt;p&gt;It was a real, humbling piece of UX feedback. Building for non-technical people means watching exactly where they get stuck, and he found my blind spot in about ten seconds.&lt;/p&gt;

&lt;p&gt;Then the "Thinking like an analyst..." screen came up, and when the verdict appeared, he was genuinely a little surprised it had actually &lt;em&gt;read and understood&lt;/em&gt; the email.&lt;/p&gt;

&lt;p&gt;He went through the breakdown, agreed with every red flag it found... and said:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Good job."&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That was the whole goal in one sentence.&lt;/p&gt;

&lt;p&gt;Not "wow, impressive AI" — just a regular person reading a plain-English explanation of a suspicious email and &lt;em&gt;trusting it enough to agree.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;That's the tool working.&lt;/p&gt;

&lt;h2&gt;
  
  
  Demo
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Try it live:&lt;/strong&gt; 👉 &lt;a href="https://labs.datasecchronicles.com/tools/does-this-belong-here/" rel="noopener noreferrer"&gt;labs.datasecchronicles.com/tools/does-this-belong-here&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The app itself runs in your browser — there's no DataSec Labs backend, and I don't store your message or API key.&lt;/p&gt;

&lt;p&gt;To use the live version, you'll need a free Google AI Studio API key. Your message is sent directly from your browser to Google's Gemma API for analysis.&lt;/p&gt;

&lt;p&gt;Because Gemma is open-weight, this same concept can also evolve into a fully local version where analysis happens on your own machine instead of sending the message to a cloud API.&lt;/p&gt;

&lt;h2&gt;
  
  
  Code
&lt;/h2&gt;


&lt;div class="ltag-github-readme-tag"&gt;
  &lt;div class="readme-overview"&gt;
    &lt;h2&gt;
      &lt;img src="https://assets.dev.to/assets/github-logo-5a155e1f9a670af7944dd5e12375bc76ed542ea80224905ecaf878b9157cdefc.svg" alt="GitHub logo"&gt;
      &lt;a href="https://github.com/Tash925" rel="noopener noreferrer"&gt;
        Tash925
      &lt;/a&gt; / &lt;a href="https://github.com/Tash925/does-this-belong-here" rel="noopener noreferrer"&gt;
        does-this-belong-here
      &lt;/a&gt;
    &lt;/h2&gt;
    &lt;h3&gt;
      A friendly phishing checker built with Gemma (open-weight AI) — plain-language scam detection for non-technical people. #Hacktoberfest
    &lt;/h3&gt;
  &lt;/div&gt;
  &lt;div class="ltag-github-body"&gt;
    
&lt;div id="readme" class="md"&gt;&lt;div class="markdown-heading"&gt;
&lt;h1 class="heading-element"&gt;🛡️ Does This Belong Here?&lt;/h1&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;A friendly phishing checker for the people in your life who still get spam.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Paste in an email or text that feels off, and it walks you through it the way a security analyst would — in plain English, no jargon. One-line verdict, the red flags it spotted &lt;em&gt;and why each one matters&lt;/em&gt;, and one calm next step. Every answer ends with the question that keeps you safe: &lt;strong&gt;"Does this belong here?"&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Built with &lt;a href="https://ai.google.dev/gemma" rel="nofollow noopener noreferrer"&gt;Gemma&lt;/a&gt;, Google's open-weight model, for the &lt;a href="https://dev.to/challenges/hacktoberfest-weekend-2026-10-01" rel="nofollow"&gt;Hacktoberfest 2026 "Build for a Friend" Weekend Challenge&lt;/a&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Part of &lt;a href="https://www.datasecchronicles.com" rel="nofollow noopener noreferrer"&gt;DataSec Chronicles&lt;/a&gt; — storm to SOC, finding what doesn't belong.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;Why I built it&lt;/h2&gt;
&lt;/div&gt;
&lt;p&gt;My mom knows not to click the link. My husband does too. Most people have picked up the &lt;em&gt;don'ts&lt;/em&gt; — but nobody ever explained the &lt;em&gt;why&lt;/em&gt;, and the why is the part that actually protects you when…&lt;/p&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class="gh-btn-container"&gt;&lt;a class="gh-btn" href="https://github.com/Tash925/does-this-belong-here" rel="noopener noreferrer"&gt;View on GitHub&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;It's a single self-contained HTML file — one page, no build step, no backend. The whole thing is HTML, CSS, and a little JavaScript, deliberately low-code so the &lt;em&gt;idea&lt;/em&gt; and the &lt;em&gt;writing&lt;/em&gt; carry it.&lt;/p&gt;

&lt;h2&gt;
  
  
  How I Built It
&lt;/h2&gt;

&lt;p&gt;The core is &lt;strong&gt;Gemma, Google's open-weight model&lt;/strong&gt;, doing the actual analysis.&lt;/p&gt;

&lt;p&gt;The app:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Takes the suspicious message the user pastes in.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Sends it to Gemma with a carefully written system prompt that tells it to act as a warm, plain-spoken helper for a non-technical person — give a verdict, name the red flags &lt;em&gt;with the reason each one matters&lt;/em&gt;, and never shame the person for asking.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Returns a clean, structured answer anyone can act on.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The interesting engineering wasn't the plumbing — it was the &lt;strong&gt;prompt&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Getting an open model to explain phishing the way a kind, patient expert would took real iteration, especially getting it to &lt;em&gt;stop showing its reasoning scratch work&lt;/em&gt; and just hand over the finished answer.&lt;/p&gt;

&lt;p&gt;I also made the app query which models my key can actually use and automatically pick an available Gemma, so it doesn't break when model names change out from under it — which they did, mid-build.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Does Open Innovation Matter?
&lt;/h2&gt;

&lt;p&gt;Because of &lt;em&gt;whose data this is.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The whole point of this tool is to check a &lt;strong&gt;real email&lt;/strong&gt; — which often contains personal details, names, account references, and private information.&lt;/p&gt;

&lt;p&gt;The live version currently sends that message directly from the user's browser to Google's Gemma API for analysis. DataSec Labs doesn't receive or store it.&lt;/p&gt;

&lt;p&gt;But building around an open-weight model creates another possibility: &lt;strong&gt;local-first analysis.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The same idea could run with Gemma entirely on the user's own computer through something like Ollama. In that version, the suspicious email wouldn't need to leave the person's machine at all.&lt;/p&gt;

&lt;p&gt;That's especially important for a tool designed for people who may already be vulnerable to scams.&lt;/p&gt;

&lt;p&gt;Open innovation gives developers the option to move beyond "paste your private information into someone else's cloud" and build tools where users can retain much more control over their own data.&lt;/p&gt;

&lt;p&gt;For a small, personal safety tool like this, that isn't just an interesting technical option.&lt;/p&gt;

&lt;p&gt;It's part of what makes open models worth building with.&lt;/p&gt;

&lt;h2&gt;
  
  
  Prize Categories
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Best Use of Gemma&lt;/strong&gt; — Gemma (Google's open-weight model) is the engine doing all the phishing analysis.&lt;/p&gt;

&lt;h2&gt;
  
  
  I'd Love Your Feedback
&lt;/h2&gt;

&lt;p&gt;I built this because knowing the rule &lt;em&gt;"don't click suspicious links"&lt;/em&gt; and recognizing why something is suspicious in the moment are two different things.&lt;/p&gt;

&lt;p&gt;If you try &lt;strong&gt;Does This Belong Here?&lt;/strong&gt;, I'd love to hear what you think — especially if there's something that could make it easier for a non-technical person to use.&lt;/p&gt;

&lt;p&gt;And if you have questions about the build, Gemma, or what I learned testing it with my husband, leave them in the comments. 💜&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Built as part of&lt;/em&gt; &lt;a href="https://www.datasecchronicles.com/" rel="noopener noreferrer"&gt;&lt;em&gt;DataSec Chronicles&lt;/em&gt;&lt;/a&gt; &lt;em&gt;— storm to SOC, finding what doesn't belong. 💜&lt;/em&gt;&lt;/p&gt;

</description>
      <category>devchallenge</category>
      <category>weekendchallenge</category>
      <category>hf26challenge</category>
    </item>
  </channel>
</rss>
