Inspiration
We were inspired by a simple question that millions of people face every day: "Is this message real or is it a scam?
Students receive fake internship and job offers, parents receive fake bank messages, and users receive suspicious payment requests, lottery messages, and phishing links. The problem is that these scams are becoming increasingly convincing, while most people don't have the technical knowledge to investigate them.
We wanted to build something that makes digital safety simple and accessible. Instead of expecting users to understand cybersecurity, we wanted AI to help them understand what is suspicious, why it is suspicious, and what they should do next.
That idea became ScamSaarthi— an AI-powered digital safety companion.
What it does
ScamSaarthi allows users to check suspicious messages, screenshots, job offers, payment requests, and URLs.
Users can paste a message, upload a screenshot, or submit a suspicious website. ScamSaarthi analyzes the content and provides:
- A 0–100 risk score
- Scam category and severity
- Detected suspicious signals
- Evidence behind the assessment
- Recommended actions
- Things the user should avoid
- An easy-to-understand explanation
For URLs, ScamSaarthi uses Firecrawl to investigate publicly accessible website content before sending relevant information to the AI analysis pipeline.
Featherless AI powers the core scam analysis and reasoning.
One of our key features is "Explain to My Parent". It converts technical security findings into simple language, including Hindi, so users can easily explain a suspicious message to their parents or less technical family members.
Instead of simply saying "This is a scam," ScamSaarthi follows:
Detect → Investigate → Explain → Protect
How we built it
We built ScamSaarthi as a MERN stack application using React, Node.js, Express, and MongoDB.
The frontend is built with React, Vite, Tailwind CSS, React Router, Axios, and Recharts. The backend uses Node.js, Express.js, MongoDB, Mongoose, JWT authentication, and Multer.
For AI capabilities, we integrated Featherless AI as the primary reasoning engine. We use structured prompts so the AI returns consistent information such as risk score, category, signals, evidence, and recommended actions.
We use Firecrawl API for suspicious URL investigation. When a user submits a website, Firecrawl retrieves publicly accessible content, which is then analyzed for potential scam indicators.
We also designed a hybrid risk engine rather than relying entirely on AI. Rule-based signals detect patterns such as payment requests, OTP requests, urgency, credential requests, and suspicious links, while the AI provides contextual reasoning.
Wolfram API can support numerical and analytical components where appropriate, while Render is used for deployment and Render Workflows as part of the hackathon's deployment requirements.
The overall architecture is:
User Input
↓
Text / Screenshot / URL
↓
Content Extraction
↓
Signal Detection
↓
Firecrawl Investigation (URL)
↓
Featherless AI
↓
Risk Engine
↓
Evidence + Explanation
↓
Recommended Actions
We also designed the AI pipeline to treat user-submitted messages and website content as untrusted data, helping protect against prompt injection.
Challenges we ran into
One of our biggest challenges was making AI analysis reliable and explainable.
Simply asking an AI model, "Is this a scam?" can produce inconsistent answers. We needed the system to explain its reasoning without inventing evidence. To solve this, we combined deterministic security signals with AI reasoning and structured outputs.
Another challenge was analyzing suspicious websites. Web content can contain misleading information or malicious instructions, so we had to make sure that scraped content was treated as data rather than instructions to the AI.
We also had to handle practical engineering problems such as:
- AI API failures and timeouts
- Invalid or inaccessible URLs
- Screenshot/OCR processing
- File validation
- Rate limiting
- Database errors
- Secure API key management
- Maintaining a simple interface for non-technical users
Designing a cybersecurity product that is powerful enough for technical users but simple enough for parents and elderly users was another important challenge.
Accomplishments that we're proud of
We are proud that ScamSaarthi is more than a simple AI chatbot.
The complete system combines:
Input → Extraction → Investigation → Risk Engine → AI Reasoning → Evidence → Action
Instead of giving users an unexplained "Safe" or "Scam" label, ScamSaarthi shows why something may be dangerous and provides practical next steps.
We are particularly proud of the "Explain to My Parent" feature. It takes a technically complex security assessment and turns it into language that a non-technical family member can understand.
We are also proud of integrating AI with real web investigation through Featherless AI + Firecrawl, while keeping the architecture modular and security-conscious.
Most importantly, we built ScamSaarthi around a real problem that affects everyday internet users rather than building an AI feature simply for the sake of using AI.
What we learned
This project taught us that building an AI application is much more than connecting an API to a chatbot.
We learned about:
- AI API integration
- Prompt engineering
- Structured AI outputs
- Explainable AI
- Risk scoring
- Web content extraction
- Prompt injection protection
- Secure backend architecture
- Third-party API integration
- Error handling and fallback systems
- Privacy-conscious application design
- Building a complete MERN application around AI
We also learned that AI is most valuable when it helps people make better decisions, rather than simply generating more information.
What's next for ScamSaarthi
We want ScamSaarthi to evolve from a scam analyzer into a broader digital safety companion.
Our future plans include:
- 🌐 A browser extension for real-time website protection
- 📱 A dedicated mobile application
- 🗣️ Voice-based scam analysis
- 🇮🇳 Support for more Indian languages
- 📞 Suspicious-call and voice-message analysis
- 🔎 Continuously updated scam intelligence
- 🌍 Community-powered scam reporting
- 👨👩👧 Expanded family safety features
- 🧠 Improved detection using continuously evolving scam patterns
Our long-term vision is simple:
Make safe digital decisions easier for everyone, regardless of their technical knowledge.
ScamSaarthi — Before you trust it, let ScamSaarthi check it.
Built With
- ai
- express.js
- featherless-ai
- firecrawl
- javascript
- jwt
- mongodb
- mongoose
- node.js
- phishing
- prompt-engineering
- react
- render
- render-workflows
- rest-api
- scam-detection
- tailwind-css
- vite
Log in or sign up for Devpost to join the conversation.