Inspiration Scams are becoming increasingly convincing. Fraudulent messages can imitate banks, delivery services, recruiters, and people we trust. Most scam detectors simply label a message as safe or dangerous without explaining why. We wanted to build something that helps people understand suspicious messages, recognise manipulation tactics, and make more informed decisions before clicking links, sharing OTPs, or sending money.

What it does ScamShield is an AI-powered security analyst that analyses suspicious messages, URLs, and screenshots to produce an explainable threat report. It combines a deterministic security rule engine with Google's Gemini AI to identify suspicious patterns, assess risk, explain possible attack paths, and recommend practical next steps. Instead of providing only a verdict, ScamShield helps users understand:

  • What makes a message suspicious.
  • How a potential scam could work.
  • What actions to avoid and how to verify a claim.
  • How to recognise similar scams in the future. ScamShield is designed to explain risk indicators rather than claim definitive proof of malicious activity.

How we built it ScamShield was built using Next.js, React, TypeScript, and Google's Gemini through the @google/genai SDK. The analysis pipeline starts with input validation and deterministic security checks. A rule engine detects patterns such as urgency, credential requests, payment requests, and brand impersonation. A URL analyzer checks link structure without visiting or opening submitted URLs. Gemini adds semantic analysis to identify social-engineering tactics and explain the context. A risk engine combines the findings into a structured threat report, including a risk score, detected signals, a possible attack chain, and recommended actions. The AI layer runs server-side, and the deterministic engine can still generate reports when Gemini is unavailable. Zod validation, rate limiting, and privacy-conscious storage are also part of the implementation.

Challenges we ran into One of our main challenges was making AI-generated security analysis useful without allowing it to become the sole source of truth. We needed a scoring system that was explainable, consistent, and not dependent entirely on an AI response. We addressed this by building a deterministic rule engine, separating rule-based findings from AI analysis, validating structured AI output, and implementing a fallback mode. Another challenge was handling suspicious URLs safely. ScamShield analyses URL structure without visiting the submitted link, avoiding the risks of automatically opening potentially malicious websites.

Accomplishments that we're proud of We're proud to have built more than a basic AI chatbot wrapper. ScamShield has its own rule-based detection engine, URL structural analyzer, brand impersonation heuristics, and risk-scoring system. It produces reports that explain detected indicators, outline possible attack paths, and offer actionable safety recommendations. The deterministic analysis layer also allows the application to remain functional when the AI provider is unavailable.

What we learned Building ScamShield taught us that applying AI to security requires more than generating convincing explanations. Results need to be validated, risk scores need to be traceable to evidence, and limitations must be communicated clearly. We learned how to integrate a server-side AI provider, build deterministic security checks, validate structured outputs, and design a user experience that makes technical security information understandable to everyday users.

What's next for ScamShield We plan to improve detection across more languages, expand the library of scam patterns, strengthen URL analysis, and continue refining the educational simulator. Future improvements may include additional ways to report suspicious content, improved analysis history, and broader accessibility so more people can understand and respond to digital threats.

Built With

Share this project:

Updates

Submission history