DEV Community

Satyam Kumar
Satyam Kumar

Posted on

InternShield β€” Think Before You Apply πŸ›‘οΈ

Hacktoberfest Weekend Challenge: Build for a Friend Submission 🀝

``
This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend

What I Built
Every semester, thousands of students receive internship offers that look legitimate β€” professional email, fancy job description, remote work β€” but turn out to be scams. My friend was nearly defrauded by a "startup" that asked for a β‚Ή5,000 "equipment deposit" before the first day. That story stuck with me.

InternShield is an open-source, AI-powered internship investigation assistant built specifically for students who encounter suspicious job or internship opportunities online.

You paste in a job description or a URL, and InternShield runs a full safety investigation and produces an evidence-backed risk report β€” not a simple "FAKE" or "REAL" verdict, but a breakdown of every red flag, unverifiable claim, and positive signal it detected, so the student can make an informed decision.

Key capabilities:

πŸ” Dual-path analysis β€” a deterministic rule engine + a local open-weight LLM (Ollama) cross-check each other
🎯 Risk Score Gauge β€” color-coded 0–100 score with a verdict: Safe / Needs Verification / High Risk
🚩 Explainable Evidence Cards β€” every flag has a plain-English reason, not just a label
πŸ”— URL investigation β€” fetches and parses job listing pages with SSRF protection
πŸ€– Runs 100% locally β€” no data sent to closed APIs, no cost, no privacy risk
Demo
πŸ”— GitHub Repo: https://github.com/satyam-257/Internshield

Run it locally in 3 steps:

bash

1. Start the backend

cd backend && pip install -r requirements.txt
uvicorn app.main:app --host 127.0.0.1 --port 8000

2. Start the frontend

cd frontend && npm install && npm run dev

3. Open http://localhost:5173

The app ships with 3 pre-built demo scenarios you can trigger instantly:

βœ… Verified legitimate internship (Google SWE)
⚠️ Suspicious listing (vague role, upfront fees, WhatsApp-only contact)
🚩 High-risk scam (deposit required, no company info, salary too good to be true)
Code

InternShield πŸ›‘οΈ

"Think before you apply."
An open-source AI-powered internship investigation assistant for students who encounter suspicious job opportunities, recruiters, and training offers online.

Hacktoberfest 2026 License: MIT FastAPI React Ollama


πŸ“Œ Problem

College students searching for internships online frequently encounter questionable job listings, unsolicited WhatsApp offers, suspicious recruiter emails, and third-party application forms.

Students commonly face:

  • Upfront registration or training fees masked as "refundable security deposits"
  • Free public email accounts (e.g. @gmail.com) claiming to represent major corporations
  • Direct selection guarantees with "NO INTERVIEW REQUIRED"
  • Urgency tactics ("today only", "only 10 seats remaining") intended to force hasty payments
  • Requests for sensitive personal or financial credentials (OTPs, bank account logins, UPI PINs)
  • Unrealistic compensation promises for trivial daily hours

Students often lack an accessible, objective tool to evaluate whether an opportunity deserves their trust before they share personal information or hand over money.


🀝 Built-For-A-Friend Story

InternShield was created for a college student and close friend navigating…

Architecture at a glance:

User Input (text or URL)
β”‚
β–Ό
url_fetcher.py ← SSRF-protected page scraper
β”‚
β–Ό
extractor.py ← Pulls company name, role, salary, contact, etc.
β”‚
β”Œβ”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β–Ό β–Ό
rule_engine.py llm_client.py
(deterministic flags) (Ollama local LLM)
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β–Ό
aggregator.py ← Merges scores + evidence
β”‚
β–Ό
JSON Risk Report
β”‚
β–Ό
React Frontend UI
Tech Stack:

Backend: Python Β· FastAPI Β· httpx Β· BeautifulSoup4
AI Inference: Ollama (qwen2.5:0.5b β€” runs on any laptop)
Frontend: React Β· Vite Β· Tailwind CSS v4
No database. No auth. No cloud dependencies.
How I Built It
The core insight was that a hybrid approach beats a pure LLM approach for safety-critical tools.

The Rule Engine (Deterministic)
risk_engine.py checks for well-known scam patterns:

Upfront payment requests (deposits, training fees)
Vague or missing company identity
Salary figures that are statistically impossible for the role/location
WhatsApp/personal email as the only contact method
Missing HTTPS on company website
Mismatched domain-to-company-name signals
Each rule contributes a weighted score and produces a human-readable evidence string.

The Local LLM (Open-Weight)
llm_client.py sends the extracted job details to Ollama running qwen2.5:0.5b (a 500M parameter open-weight model that runs on CPU in under 2 seconds). It's prompted to return structured JSON:

json

{
"risk_score": 72,
"summary": "...",
"red_flags": [...],
"positive_signals": [...]
}
A short 4-second timeout + safe JSON parsing ensures the UI never hangs if Ollama is unavailable β€” it gracefully falls back to the rule engine alone.

Why not GPT-4 / Claude?
Because students shouldn't have to pay per query, share sensitive job listings with third-party APIs, or rely on rate-limited cloud services. The open-weight model runs on a 5-year-old laptop with 8GB RAM. That matters for the people this tool is built for.

Why Does Open Innovation Matter?
InternShield wouldn't exist in its current form with a closed API stack.

Privacy: Students paste internship descriptions that may contain personal context β€” their name, college, city. With a local LLM, none of that ever leaves the machine.

Cost: The target users are students β€” many can't afford $20/month API subscriptions. Ollama + qwen2.5:0.5b is free, forever.

Trust: A safety tool that sends your data to a black-box API to decide if something is "safe" is deeply ironic. Open-weight models let anyone audit what's being run.

Customization: The rule engine and LLM prompt are fully open. A college student council could fork this, add their region's known scam patterns, and deploy it for their campus β€” no vendor lock-in, no permission required.

Open innovation turned a weekend project into something genuinely deployable and trustworthy for the people who need it most.

My Agent Session
Built with the help of an AI coding agent that:

Scaffolded the full FastAPI + React project structure
Wrote and debugged the SSRF-protected URL fetcher
Designed the dual-path analysis pipeline
Iterated on the risk scoring weights against real scam patterns
Debugged UTF-8 encoding issues on Windows for β‚Ή symbol rendering
Set up the git repository and pushed the final code
Prize Categories
Ollama β€” built entirely on local open-weight inference via Ollama
General Open-Source AI β€” uses open-weight models, open-source frameworks throughout
Built with ❀️ for every student who almost clicked "Apply" on something that didn't feel right.

Top comments (0)