Inspiration Scams work because they create urgency, fear, and confusion—especially through familiar channels such as SMS, email, payment requests, and messaging apps. I wanted to build a practical safety tool that does more than label content “safe” or “unsafe.” Plumbline shows people the exact signals that made a message suspicious and gives them a clear next step.
What it does Plumbline lets users paste a suspicious SMS, email, link, or payment request and receive: A clear risk score and verdict The precise phrases, URLs, sender patterns, urgency tactics, and payment cues that triggered the result An explanation in plain language A safe recommended action, such as avoiding a link, independently verifying a sender, blocking the contact, or reporting the message
The core verdict is deterministic: it uses local rules, makes zero network calls, and returns results in under 300 ms. An optional AI explainer turns the findings into a more natural narrative. When no API key is configured, Plumbline transparently falls back to a deterministic template and identifies the source as ai.source: "deterministic".
How I built it We designed Plumbline around an explainability-first rules engine. Instead of asking an opaque model to decide whether something is a scam, the engine evaluates identifiable patterns such as: Urgency and threat language: “act now,” “account will be closed,” or “final warning” Impersonation signals: banks, delivery companies, government agencies, employers, or support teams Credential-harvesting prompts: requests for passwords, OTPs, PINs, card details, or login verification Suspicious links: shortened URLs, misleading domains, IP-address URLs, encoded links, and unusual URL structures Payment-pressure tactics: gift cards, crypto payments, wire transfers, “clearance fees,” and upfront deposits Emotional manipulation: fear, secrecy, unexpected prizes, or too-good-to-be-true offers Each triggered rule contributes to a transparent score and produces evidence that can be shown directly to the user. We then map the score and context to an actionable verdict, rather than leaving users with an abstract warning.
Challenges we ran into The hardest problem was balancing sensitivity with usefulness. A detector that flags every urgent message is noisy; one that requires many signals may miss real scams. We addressed this by combining weighted signals and contextual rules rather than relying on a single keyword. We also had to make explanations understandable without overstating certainty. A suspicious message is not always proven fraud, so Plumbline distinguishes between risk indicators and definitive claims. Its guidance focuses on safe behavior: do not click, do not pay, and verify independently through an official channel. Another challenge was keeping the product private and fast. By making the primary analysis fully local and deterministic, we avoided sending potentially sensitive messages to external services and made the tool reliable even without an AI API key.
Accomplishments that I am proud of Built a working scam-analysis flow that produces a verdict, score, evidence, and recommended action. Made every risk decision traceable to specific user-visible signals. Kept the core detection engine private, deterministic, and network-free. Designed a graceful AI fallback so the product remains useful without external model access. Focused on actionability: users leave with a concrete, safer next step rather than only a warning label.
What I learned I learned that explainability is not just a technical feature—it is a trust feature. People are more likely to follow a warning when they can see why it was triggered and recognize the manipulation tactic in the message. I also learned that deterministic rules are powerful for common scam patterns. They are fast, testable, auditable, and easier to improve through real examples. AI is most valuable as a communication layer that explains findings clearly, not as the sole authority deciding whether a user should trust a message.
What’s next for Plumbline Next, I want to expand Plumbline’s rule coverage for region-specific scam patterns, mobile-money and payment fraud, job scams, marketplace scams, impersonation campaigns, and account-takeover attempts.
I also plan to add: A privacy-preserving browser extension for checking suspicious links before opening them Screenshot and OCR support for scam messages shared as images More granular confidence and evidence scoring User reporting and feedback loops to improve rules without collecting sensitive message content Localization for more languages and locally relevant payment and telecom scams A developer-friendly API and embeddable verification widget for fintechs, marketplaces, support teams, and community platforms
Built With
- api
- css
- deterministic
- engine
- local-first
- node.js
- openai
- parsing
- react
- regex
- rule
- tailwind
- typescript
- url
- vite
Log in or sign up for Devpost to join the conversation.