Get scammed here, not out there.

Your phone rings: "Hi, this is Daniel from your bank's fraud department." You answer. He pushes. You read him the code. The Call Autopsy then pins the timestamped line where you should have hung up, names the pressure tactics, and gives you a safer script for next time. Then you try again.

Play the live app · Watch the 2:05 narrated and captioned demo

Inspiration

Knowing "never share the code" and following that rule while a confident stranger rushes you are different skills. Pilots practise emergencies in a simulator. Scam Call Dojo applies that practice-first approach to the calls students and their families encounter: fake internships, gift-card requests, parcel fees and family emergencies.

What it does

Six fictional, branching scenarios range from white belt to black belt. Answer by typing, quick reply, or optional voice. Resist and the caller escalates; share a code or agree to pay and the simulation ends as Scammed.

Optional Coach mode highlights red flags as they happen. Afterward, the Call Autopsy shows a Resistance Score and belt, the hang-up moment, time spent on the line after it, your good and risky moves, and a masked transcript with the trigger words highlighted. A copyable safety card makes the lesson easy to share. Independent-verification credit requires a trusted source separate from the caller; asking the caller to email or calling the caller back does not earn it. The score is bounded, pattern-based training feedback, not a measured estimate of real-world skill.

How it was built

Vite and TypeScript power a static GitHub Pages app, with no backend or account required. The core uses 24 transparent detection rules and a scripted CallSession state machine. There is no LLM deciding the outcome: identical inputs receive identical feedback, and each flag points to the words that triggered it.

The repository's 73-test Vitest suite covers detection, false-positive guards, first-reply leaks, redaction, branching, scoring, highlighting, deAPI request format and full-interface recording lifecycle regressions. A clean install, type checks and the production build passed. Separate review exercised repeated typed/spoken replies, cancelled permissions, recording cleanup and stale callbacks with mocked media and network services.

Typing and captions work without a microphone or API key. The interface includes keyboard shortcuts, screen-reader live regions, visible focus states, reduced motion and mobile layouts.

Optional voice integration

Text-only is the default and has no microphone control. Optional browser dictation may send audio to the browser vendor's speech service; the app explains this and asks before capture. Browser/OS caller voices are not guaranteed to run locally. A bring-your-own-key deAPI adapter requests Kokoro preset-voice speech and WhisperLargeV3 transcription, with a recipient-specific opt-in before use. The key is held only in sessionStorage and sent to deAPI, never bundled in the public app. Voice cloning is not used. Recording belongs to one call: hang-up, Back and Retry stop its tracks and discard unfinished audio, and late results cannot become a later call's reply. These paths were tested with mocks; no live sponsor-service validation is claimed.

Challenges

A naive detector confused "Oh no! What do you need?" with refusal and "I'm going to send you the money" with hanging up. Narrower patterns, punctuation normalization, conflict resolution and regression tests made the feedback more useful.

The hang-up moment also needed a clear rule: the first critical request for a code, password or payment, or enough combined pressure. The app explains that choice instead of presenting an unexplained score.

Accomplishments and lessons

The replay loop turns a mistake into a concrete next attempt. Transparent, timestamped evidence is more useful than a generic warning. The prototype demonstrates that experience without real calls, payment, accounts or a model API.

What's next

More languages, larger-text and slower modes, classroom practice and moderated fictional scenario contributions.

Build-window and AI disclosure

This new repository was built during LovHack Season 3, beginning September 27, 2026. No code, designs or content were reused from earlier projects. Third-party components include Vite, TypeScript, Vitest, browser audio/speech APIs and the optional deAPI API; icons are inline SVG.

AI coding tools were used to write, test and review code and copy. Devin audited the app, repaired detector bugs and produced screenshots and the earlier automated captioned demo. The current 2:05 demo records the working 24-rule/73-test build, including its Call Autopsy and independent-verification retry. It adds captions and locally generated Kokoro Heart narration; no live deAPI service was used for this narration. All callers, companies and details are fictional; the app never places calls or sends texts. Digit runs are masked in the transcript. It is an educational simulation, not a guarantee of scam detection or prevention.

Built With

Share this project:

Updates

Submission history