Inspiration

Online scams and phishing attacks are becoming increasingly common. Many people receive suspicious messages, fake offers, and deceptive website links but struggle to identify them before taking action. We were inspired to build ScamShield AI to make digital safety easier and help people recognize potential threats before they become victims. Our goal is to make scam awareness accessible, simple, and practical for everyone.

What it does

ScamShield AI is an AI-powered digital safety web application that helps users analyze suspicious messages, website URLs, and screenshots.

  • Message Analysis: Examines text messages for potential scam indicators, including urgency, suspicious prizes, OTP-related requests, and account-verification demands.
  • URL Analysis: Detects suspicious website patterns, deceptive domains, IP-address hosts, and other potential warning signs using rule-based analysis.
  • Screenshot Analysis: Uses Google Gemini Vision to interpret screenshots of suspicious messages, with Tesseract OCR available as a fallback for text extraction.
  • Risk Assessment: Provides a numerical risk score and a risk classification to help users understand potential threats.
  • Explainable Results: Highlights suspicious indicators and explains why submitted content may be risky.
  • Recent History: Keeps up to 20 recent analysis records in browser session storage.

ScamShield AI helps users make informed decisions before clicking suspicious links or sharing sensitive information.

How we built it

We built ScamShield AI using Python and Flask for the backend, with HTML, CSS, and JavaScript for the frontend. We integrated Google's Gemini 2.5 Flash through the official Google Gen AI SDK to support AI-assisted analysis of suspicious content and screenshots.

For URL analysis, we implemented static checks using Python URL parsing, IP address validation, and heuristic rules. Pillow helps handle and validate uploaded images, while Tesseract OCR provides a fallback for extracting text from screenshots.

We designed a dark, cybersecurity-inspired interface with risk indicators, analysis results, and recent history. The Gemini API key is configured on the server through an environment variable rather than being exposed in frontend code.

We used Git and GitHub for version control and prepared the application for deployment.

Challenges we ran into

One of our main challenges was analyzing different types of suspicious content through a single application. Text messages, URLs, and screenshots require different processing approaches.

Other challenges included:

  • Identifying meaningful scam indicators without treating every unusual message as fraudulent.
  • Designing understandable risk scores and explanations.
  • Handling image uploads and providing an OCR fallback.
  • Keeping API credentials secure on the server.
  • Developing URL heuristics that recognize suspicious patterns without claiming to verify live websites.
  • Testing different inputs and handling unexpected or invalid data.
  • Creating a user-friendly interface while maintaining a strong cybersecurity theme.

These challenges taught us the importance of combining AI-assisted analysis with clear rules, validation, and realistic expectations.

Accomplishments that we're proud of

  • Built a working prototype that supports message, URL, and screenshot analysis.
  • Integrated Google Gemini AI for AI-assisted content and image interpretation.
  • Implemented rule-based URL analysis without relying on live website crawling.
  • Developed a risk-assessment interface with explanations of suspicious indicators.
  • Added image handling and an OCR fallback.
  • Kept the Gemini API key out of frontend code.
  • Implemented temporary browser-side analysis history.
  • Achieved a reported test result of 51 passing tests in our last recorded test run.
  • Prepared the project for presentation at ForgeHacks 2026.

We are proud to have developed a practical cybersecurity project focused on helping people become more aware of potential online scams.

What we learned

Building ScamShield AI helped us understand how AI can be combined with traditional programming techniques to solve real-world problems.

We learned:

  • How to build a web application using Python and Flask.
  • How to integrate Google's Gemini AI into an application.
  • How to process screenshots and extract text from images.
  • How to analyze URLs using parsing, IP validation, and heuristic rules.
  • Why API keys must be protected using server-side environment variables.
  • How to write tests for different inputs and unexpected situations.
  • Why explainable results and user-friendly interfaces matter in cybersecurity.
  • Why a risk score should be treated as an assessment rather than a guarantee.

Most importantly, we learned that responsible cybersecurity tools should communicate both their capabilities and their limitations honestly.

What's next for ScamShield

Our next goal is to make ScamShield AI more reliable, useful, and accessible.

Planned improvements include:

  • Threat Intelligence: Integrate reputable threat-intelligence sources to check known malicious domains.
  • Regional Language Support: Expand scam analysis to Hindi, Marathi, and other Indian languages.
  • Browser Extension: Help users assess suspicious links while browsing.
  • Improved Detection: Evaluate the system on a documented dataset and improve its handling of false positives and false negatives.
  • Real-Time Warnings: Introduce carefully validated warnings for known malicious links.
  • Enhanced User Experience: Improve mobile responsiveness, accessibility, and result explanations.
  • Privacy and Security: Continue improving secure image handling, API protection, and data-minimization practices.

Our long-term vision is to develop ScamShield into a trustworthy digital safety assistant that helps people recognize potential threats and make safer decisions online.

ScamShield AI — Detect the scam. Understand the risk. Stay protected.

Built With

Share this project:

Updates

Submission history