Inspiration
Scam messages in India, like fake bank KYC alerts, UPI refund tricks and "digital arrest" calls, push people to act within minutes. Most tools only say "scam" or "not scam." Victims also find reporting slow and confusing. We wanted something that explains why a message is dangerous, tells you what to do next, and fights back.
What it does
Paste an SMS, WhatsApp message, email or call transcript. ScamTrap returns:
- a risk verdict and score
- the exact warning signs it found, quoted from the message
- the closest known scam pattern
- clear next steps
- a complaint draft for cybercrime.gov.in and helpline 1930
For likely scams, a decoy agent plays a fictional, confused victim, keeps a scammer talking, and extracts details such as links, UPI IDs, phone numbers and bank accounts into an evidence pack. In this demo, the decoy only talks to a built-in simulated scammer, never a real person.
How we built it
- Backend: Python and FastAPI
- Detection: regex warning-sign rules plus TF-IDF retrieval over a library of 8 scam patterns
- AI: an optional LLM (Llama via Groq) writes plain-language explanations and the decoy's replies. Scammer text is treated as untrusted input in the prompt, and decoy replies are filtered so they can never contain numbers, handles or links. The loop is capped at 3 turns.
- Front end: a single HTML page on GitHub Pages; backend on Render
Challenges we ran into
Keeping the decoy safe was the hardest part: it must never reveal real data, follow instructions hidden in scam messages, or contact real people. We also had to balance catching scams against false alarms on normal bank and payment alerts. Deploying the backend on a free tier took some debugging, including a Python version problem.
Accomplishments that we're proud of
- A complete flow from message to verdict, next steps and a ready-to-send complaint
- A decoy agent with built-in safety limits that produces an evidence pack
- Honest testing: two hand-written test sets, 24/24 on the first (written alongside the rules) and 28/30 on the second, with the 2 false alarms listed in the README instead of hidden
What we learned
Explaining a verdict matters more than the score. Safety limits have to be part of the design from the start, not added at the end. A small, rule-based system with retrieval can be useful and easy to inspect, though it is brittle against new wording.
What works and what doesn't
Works: verdict, warning signs, pattern match, complaint draft, decoy against a simulated scammer, evidence extraction.
Doesn't (yet):
- The simulated scammer follows a fixed, KYC-themed script whatever scam you paste in.
- Detection is rule-based, so new wording can slip past it.
- Email inbox intake is not built.
- The test sets are small and hand-written, so they are sanity checks, not a benchmark.
The free server may take about 30 seconds to wake up on the first request.
AI use
This project was built with the help of an AI assistant (Claude). The optional runtime LLM is Llama via Groq.
What's next for ScamTrap
Email inbox intake, a wider scam library, more varied simulated scammers, and an independent accuracy test.
Log in or sign up for Devpost to join the conversation.