Inspiration
We approached this hackathon by brainstorming projects that could solve real world problems. With the advancement of AI, scams are getting more advanced and more frequent. Scams devastate families and they are often incredibly clever. We aimed to build a project that could help every day people detect scams or suspicious activity so that they can prevent and mitigate damages before they become serious.
What it does
When you receive a message, you can input it into one of the four categories (email, url, screenshot, phone-transcript) provided by our website. When the frontend receives the message, the backend will then compare this message with other similar cases shown on the Internet. If the inputted message is detected as suspicious, it will then list the "signals" to the user. (Signals here mean the keywords/red-flags where the input information and the sample scam information share together.) Besides, it also contains a "What to do next" section that helps the user to know how to deal with these scam information. As well, it has the backup plans if users already send the scammers the private information. In the future, we are planning to create a "google extension" version of this project so that users can access to the project more easily and more conveniently.
How we built it
We built Untitled as a web app with a React frontend and a backend. The frontend uses Vite and sends messages, URLs, or screenshots to the backend for analysis.
The backend uses explainable rules to look for warning signs in messages and URLs. For screenshots, it uses local OCR to extract text before analyzing it. The app then shows a risk assessment, the reasons behind it, and suggested next steps.
We focused on keeping the analysis cautious: the app highlights potential warning signs rather than guaranteeing that something is safe or a scam.
Challenges we ran into
Connecting the frontend to the backend: Vite started, but the analysis requests failed until we ran the API server separately. Making scam detection useful without overstating certainty. A message can have warning signs without being a confirmed scam. Reading text from screenshots reliably, since OCR can misread or miss parts of an image. Balancing privacy with useful checks. We wanted analysis to work locally and avoid storing submitted messages.
Accomplishments that we're proud of
Built a working web app that analyzes suspicious messages, URLs, and screenshots despite being all our first hackathons
Added explanations for why something may be suspicious, so users can make more informed decisions.
Included next steps and recovery guidance for people who may have clicked a link or shared sensitive information. Kept screenshot text extraction on the backend using local OCR.
What we learned
A frontend and backend are separate services, and both need to be running during development.
Scam detection should communicate uncertainty and explain its reasoning rather than promise a message is safe.
Different inputs need different approaches: rules for message and URL signals, and OCR to read screenshots.
Privacy and clear guidance are important parts of building a cybersecurity tool.
What's next for Seems Legit
Improve detection using more scam examples and feedback.
Make screenshot analysis more reliable and explain when OCR may have missed text.
Add clear privacy guidance and keep integrations optional.
Improve setup so the frontend and backend are easier to start together.
Test the app with more realistic examples, including legitimate messages that could otherwise be flagged.
Built With
- googlesafebrowingapi
- html
- javascript
- node.js
- ocr
- virustotalapi
- web
Log in or sign up for Devpost to join the conversation.