Inspiration

Callback scams weaponize the one channel people still instinctively trust: a live phone call. "This is your bank / police / courier — please call back this number" is easy to fake on a webpage, but hard to fake against the real institution's own published hotline. CALL-E made it possible to place real calls from an agent, so verification stops being "search the number on a forum" and becomes a reproducible, evidence-backed comparison. The fruit fly connectome is the perfect mascot: short-lived, disposable, single-purpose neurons that do one job and burn out — exactly how an anti-scam probe should behave.

What it does

Scam Mirror verifies a "please call this number back" scam by making the story survive a real phone call. You hand it a suspect number and the organization it claims to be, and it releases two short-lived CALL-E "flies":

  • Fly-A dials the published official hotline and asks whether the callback / verification flow actually exists.
  • Fly-B dials the suspect number and records red flags — requests for codes, passwords, transfers, remote control, crypto, or secrecy.

The two accounts are compared, and Scam Mirror returns likely_legit | likely_scam | inconclusive with a confidence score, the signals, and an evidence hash. It collects no identity and stores no full recording — only a summary and a hash.

Each fly is grounded in a real neuron from the complete male Drosophila central nervous system connectome (Janelia, CC-BY): the Giant Fiber, an escape-command neuron, and DA1_lPN, a pheromone-detecting olfactory projection neuron.

How we built it

  • A dual-fly orchestrator in Python (standard library only) drives the official @call-e/cli plan → start → status flow over CALL-E's MCP endpoint.
  • Dry-run is the default with bundled fixtures; --plan drafts both flies without dialing; --live places real calls.
  • A rule-based verdict engine does number normalization, red-flag keyword detection, and disposition ordering into confidence and signals.
  • A JSON attestation carries SHA-256 content hashes (summary kept, transcript discarded) plus a verdict hash for reproducibility.
  • Fly personas come from the real Male CNS connectome: I downloaded the 14 MB neuron-annotation Feather file, extracted real neurons, and rendered their SWC skeletons.
  • The skill is packaged per awesome-phone-call-agents requirements and opened as PR #648.

Challenges we ran into

  • CALL-E does not support China (+86) yet, so the Mandarin scenario is limited to Malaysia (+60) for now; I documented the 22 supported countries and kept the demo region-agnostic.
  • The CLI/MCP path does not accept a result schema, so confirmed_business and red_flags are derived from the returned summary/transcript instead of structured fields.
  • The target repository requires English-only repo-facing content, so the Chinese keyword list was moved out of the skill into a documented extension point.
  • Live parsing is best-effort: call statuses and response envelopes had to be handled defensively, with polling and recovery semantics.

Accomplishments that we're proud of

  • Real integration, not mock: dry-run, plan-only, and live code paths all exist, and --plan was verified against the live CALL-E service.
  • Personas grounded in real neurons with real body IDs and Virtual Fly Brain IDs, plus actual skeleton renders.
  • A minimal-disclosure attestation: verdict + summary + hashes, no recordings, no identity.
  • The skill passes the official repository validation and is live as PR #648.

What we learned

  • The safest way to verify a caller is to force their claim to survive a live comparison against the official line.
  • Plan-first and kill-switch discipline matter: never dial before a plan is confirmed, and hang up on any secret request.
  • Reproducible evidence is cheap: hash the content, keep only the hash, and the output becomes auditable.

What's next for Scam Mirror

  • Run a live dual-fly call once a supported-region number is available (or CALL-E adds China).
  • Optional LLM comparison of the two summaries (env-gated), plus a per-official-line rate limiter.
  • Webhook output and a small web UI that always renders the "advisory, not legal advice" disclaimer.
  • Multilingual red-flag packs loaded per locale, and a larger verified organization whitelist.

Built With

  • call-e
  • cns
  • mcp
Share this project:

Updates

Submission history