This is a submission for the Hacktoberfest Open-Source AI Challenge: Touch Grass
What We Built
QR codes are everywhere in India. Tea stalls, local shops, restaurants — you name it. Scan, pay, leave. Easy!
But have you ever wondered what's actually hiding behind that tiny square? You can't read a QR code with your eyes, and a wrong scan can lead to a suspicious link or an unexpected payment request.
So, along with my friend @apparely, we built TrailQR Raksha to make QR scanning a little safer.
It's a privacy-first, offline-capable QR security tool designed with everyday users in mind, especially in West Bengal.
- Rule-based checks look for suspicious QR payloads.
- Google Gemma 4 explains the results in English and Bengali.
- Privacy first: Sensitive data is sanitized before external transmission.
- Snowflake + CoCo help analyze neighborhood-level scam patterns.
The best part? The AI explains the result, but the rules make the security assessment. We don't want a chatbot giving a scammer a five-star review. 💀
And since this is the Touch Grass challenge, go outside and find a QR code to test. Your laptop wallpaper doesn't count.
Demo
Try it yourself: qr-raksha.vercel.app
This is how we have build it
- Frontend: HTML, CSS, and vanilla JavaScript.
-
Security: Deterministic checks in
js/rules.js. - AI: Gemma 4 through the Gemini API, with an Ollama offline fallback.
- Analytics: Snowflake and CoCo.
- Agent Skill: An open-standard skill for QR auditing.
Want to try the skill?
npx skills add [https://github.com/debangshuuii/QR-RAKSHA/tree/main/skills/qr-audit](https://github.com/debangshuuii/QR-RAKSHA/tree/main/skills/qr-audit)
## Team


Top comments (0)