This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend
What I Built
Ruko — Stop. Check before you tap. रुको.
I built Ruko as a privacy-first second opinion for people who receive suspicious messages and aren't sure what to do next.
The idea came from a simple problem: scam messages don't always look like scams. A message can look like it's from a bank, a courier company, a job recruiter, or a buyer on a marketplace. When someone is unsure, the easiest thing to do is tap the link, reply, pay, or share information.
Ruko is designed to create one small pause before that happens.
You paste a suspicious message into Ruko and it:
- checks the message using deterministic safety rules
- identifies suspicious signals such as urgency, payment requests, impersonation, and suspicious links
- shows exactly what was detected
- uses Google's open-weight Gemma model locally for context and explanation
- gives a simple, actionable next step
- refuses to send sensitive authentication messages to the AI layer
The most important part is what Ruko doesn't do.
If a message looks like it contains an OTP, PIN, password, CVV, or authentication code, Ruko's Privacy Gate stops processing before Gemma is called.
Instead, Ruko clearly says:
RUKO STOPPED HERE
This makes the privacy boundary visible instead of hiding it.
The goal is simple:
Stop. Check before you tap.
Built for a friend. Useful for everyone.
Demo
🎥 Video demo: https://drive.google.com/drive/folders/1m_k6TyTNtXnEJKM_K30DE8bilaaJysTP?usp=sharing
The demo shows three situations:
- A bank/KYC scam message being analyzed and flagged as HIGH RISK
- The X-Ray view showing the signals Ruko detected
- A private OTP message being blocked by the Privacy Gate before it reaches Gemma
Code
GitHub: https://github.com/vedant21-ctr/rukoAI
The repository contains the complete project, including:
- Next.js frontend
- FastAPI backend
- Privacy Gate
- Safe representation layer
- deterministic rule engine
- local Gemma integration
- Safety Validator
- evaluation benchmarks
- automated tests
- architecture and privacy documentation
How I Built It
Ruko is built around Gemma, Google's open-weight model, running locally through Ollama.
The architecture deliberately separates safety decisions from AI-generated explanations:
Message → Privacy Gate → Safe Representation → Rule Engine → Gemma → Safety Validator → Ruko warning
The Privacy Gate runs first.
Instead of sending the original message directly to the model, Ruko converts safe messages into a structured representation containing signals such as:
json
{
"intent": "account_warning",
"urgency": "high",
"requested_action": "verify_identity",
"payment_requested": false,
"credential_requested": false,
"url_type": "shortened",
"threat_present": true,
"sender_type": "unknown"
}
Top comments (0)