{"slug": "second-look-i-built-a-scam-checker-for-my-mom-after-she-sent-me-a-10k-payment", "title": "Second Look: I Built a Scam Checker for My Mom After She Sent Me a ₹10k Payment Screenshot", "summary": "A developer built Second Look, an AI-powered scam checker that lets users paste suspicious SMS or WhatsApp messages or upload screenshots to receive a plain-language verdict on whether a message shows signs of fraud or social engineering. The tool returns three outcomes — strong fraud indicators, suspicious elements requiring verification, or nothing strongly suspicious — and explains why a message looks risky, what to do next, and what to avoid, with a \"Send to my family\" option for sharing results with a trusted contact. The project was created so a family member could quickly answer the question \"Should I click this?\" without needing cybersecurity expertise.", "body_md": "*This is a submission for the [Hacktoberfest Weekend Challenge: Build for a Friend](https://dev.to/challenges/hacktoberfest-weekend-2026-10-01)*\n\n**A small AI safety layer for the people in our families who get asked to \"just click this once.\"**\n\nI built **Second Look** for my mom.\n\nThe idea started from a situation that feels very familiar in a lot of Indian families.\n\nShe gets a suspicious message.\n\nShe isn't sure whether it is real.\n\nAnd the first thing she does is send it to me.\n\n**\"Is this genuine?\"**\n\nSo I thought about what that interaction could look like in a worst-case scenario.\n\nImagine opening WhatsApp and seeing a screenshot of a **₹10,000 payment**.\n\nThe message underneath says:\n\n*\"Your bank KYC has expired. Your account will be blocked today. Verify immediately using the link below.\"*\n\nThere is a link.\n\nThere is a transaction reference.\n\nThere is a familiar-looking bank name.\n\nAnd there is one thing the message is really good at creating:\n\n**Urgency.**\n\nThe screenshot used with this post is the real one that my mom talked about\n\nThe important part isn't the exact ₹10k amount.\n\nIt's the question that comes after seeing something like that:\n\n**\"Should I click this?\"**\n\nThat's the question I wanted to make easier to answer.\n\nI didn't want to build another cybersecurity dashboard filled with technical indicators that only security professionals understand.\n\nI wanted something my mom could actually use.\n\nSo I built **Second Look**.\n\nSecond Look is a small **AI-powered scam checker** that lets a user paste a suspicious SMS or WhatsApp message, or upload a screenshot, and get a clear, understandable verdict.\n\nThe application gives three simple outcomes:\n\nStrong indicators of fraud or social engineering were detected.\n\nThe message contains suspicious elements and should be verified before taking action.\n\nNothing strongly suspicious was identified from the information available.\n\nBut the verdict itself isn't the important part.\n\nSecond Look also explains:\n\n**Why does this look suspicious?**\n\n**What should I do next?**\n\n**What should I avoid doing?**\n\nAnd if the person still isn't comfortable making that decision alone, they can use:\n\n**\"Send to my family\"**\n\nto share the result with someone they trust.\n\nSo the experience becomes:\n\n```\nSuspicious Message\n        │\n        ▼\n   Second Look\n        │\n        ▼\n Understand the Risk\n        │\n        ▼\n   What To Do Next\n        │\n        ├────────────────┐\n        ▼                ▼\n   Take Action       Ask Family\n```\n\nI didn't want AI to replace the person you trust.\n\nI wanted it to make the first check faster and easier.\n\nScam messages are often effective precisely because they don't look obviously fake.\n\nThey create pressure.\n\nThey use familiar language.\n\nThey mention things people recognize:\n\nA person receiving one of these messages doesn't necessarily need a lesson in cybersecurity.\n\nThey need an answer to a much simpler question:\n\n**\"What is happening, and what should I do right now?\"**\n\nThat's how I approached Second Look.\n\nInstead of giving the user:\n\n\"This message exhibits characteristics of credential harvesting and social engineering.\"\n\nthe application should explain the situation in plain language.\n\nSomething closer to:\n\n**This message is creating urgency and asking you to verify your account through a link. Don't click it. Contact your bank through its official website or app instead.**\n\nThat difference matters.\n\nThe model isn't there just to classify.\n\nIt is there to **explain**.\n\nSecond Look accepts both **text and screenshots**.\n\nThat's important because suspicious content doesn't always arrive as clean, copyable text.\n\nSometimes it's an SMS.\n\nSometimes it's a WhatsApp message.\n\nSometimes someone sends you a screenshot and says:\n\n\"Look at this.\"\n\nSo the pipeline looks like this:\n\n```\n                         ┌────────────────────┐\n                         │        USER        │\n                         └──────────┬─────────┘\n                                    │\n                    ┌───────────────┴───────────────┐\n                    │                               │\n                    ▼                               ▼\n              Paste Text                    Upload Screenshot\n                    │                               │\n                    └───────────────┬───────────────┘\n                                    │\n                                    ▼\n                         ┌─────────────────────┐\n                         │   Privacy Layer     │\n                         │                     │\n                         │ Card / PAN / Aadhaar│\n                         │ / Account Redaction │\n                         └──────────┬──────────┘\n                                    │\n                                    ▼\n                           ┌──────────────────┐\n                           │      Gemma       │\n                           │  Multimodal AI   │\n                           └─────────┬────────┘\n                                     │\n                                     ▼\n                        ┌────────────────────────┐\n                        │ Scam / Risk Analysis   │\n                        │                        │\n                        │ + Explanation          │\n                        │ + Recommended Action   │\n                        └───────────┬────────────┘\n                                    │\n                    ┌───────────────┼───────────────┐\n                    │               │               │\n                    ▼               ▼               ▼\n                 🚨 Scam       ⚠️ Be Careful    ✅ Looks OK\n                    │               │               │\n                    └───────────────┼───────────────┘\n                                    │\n                                    ▼\n                         ┌────────────────────┐\n                         │  What should I do? │\n                         └──────────┬─────────┘\n                                    │\n                       ┌────────────┴────────────┐\n                       │                         │\n                       ▼                         ▼\n                   Read Aloud             Send to Family\n```\n\nThe important architectural decision is that **privacy comes before model inference**.\n\nThat was deliberate.\n\nThe messages we're dealing with can contain extremely sensitive information.\n\nA bank message might contain:\n\nSo before anything reaches the model, Second Look redacts sensitive identifiers.\n\nThe application specifically handles things such as:\n\nThe basic idea is:\n\n```\nRaw Message\n     │\n     ▼\nSensitive Data Redaction\n     │\n     ▼\nSanitized Message\n     │\n     ▼\nGemma\n     │\n     ▼\nVerdict + Explanation\n```\n\nThe model should get enough context to understand what is happening without unnecessarily receiving sensitive financial information.\n\nThat was a product requirement from the beginning, not something I wanted to bolt on later.\n\nThe core model powering Second Look is **Gemma**, Google's open-weight model.\n\nI specifically wanted to build around an open model instead of making the entire application dependent on one closed API.\n\nSecond Look uses an **OpenAI-compatible interface**, which makes the model backend replaceable.\n\nThat gives the application two paths:\n\n```\n                         Second Look\n                              │\n                              ▼\n                 OpenAI-Compatible Interface\n                              │\n                   ┌──────────┴──────────┐\n                   │                     │\n                   ▼                     ▼\n              Hosted Gemma          Local Ollama\n                                         │\n                                         ▼\n                                     Gemma 3 4B\n```\n\nThe local path is especially interesting because it gives the application a route toward **private local inference**.\n\nSecond Look can run with **Ollama** and Gemma locally.\n\n```\nollama pull gemma3:4b\n```\n\nThen configure:\n\n```\nLLM_BASE_URL=http://localhost:11434/v1\nLLM_API_KEY=\nLLM_MODEL=gemma3:4b\n```\n\nAnd run the application locally:\n\n```\npython -m venv .venv\n.venv\\Scripts\\activate\nsource .venv/bin/activate\n```\n\nThen:\n\n```\npip install -r requirements.txt\nuvicorn app:app --reload\n```\n\nOpen:\n\n```\nhttp://localhost:8000\n```\n\nThe important part is that **the application code doesn't need to be rewritten** just because the model moves from a hosted endpoint to a local Ollama instance.\n\nOne of the things I really wanted was screenshot support.\n\nBecause people don't always copy suspicious messages.\n\nSometimes the entire interaction is an image.\n\nSo Second Look supports:\n\n```\nText\n │\n ▼\nGemma\n```\n\nand:\n\n```\nScreenshot\n │\n ▼\nMultimodal Gemma\n │\n ▼\nAnalysis\n```\n\nThis makes the system much closer to how people actually encounter suspicious content.\n\nThe application is tuned around scam patterns that are particularly relevant to users in India.\n\nSome examples include:\n\nThe application can also surface the **1930 cyber-fraud helpline** when appropriate.\n\nThis is not intended to be a universal cybercrime classifier.\n\nIt's meant to be a **first layer of decision support** before someone clicks, pays, shares credentials, or follows instructions from a suspicious message.\n\nThere was another problem I didn't want to ignore:\n\n**Language.**\n\nSecurity advice isn't very useful if the person receiving it has to translate it first.\n\nSecond Look supports responses in **12 languages**, including:\n\nThe selected language is remembered.\n\nSo a user doesn't need to keep configuring the application every time they check another message.\n\nThe idea is simple:\n\n**Digital safety advice should be understandable in the language you actually use.**\n\nThere is also a small accessibility feature that turned out to be useful.\n\nThe application can read the verdict aloud using the browser's built-in speech engine.\n\nSo instead of reading a long explanation on a phone screen:\n\n```\nCheck Message\n      │\n      ▼\nGet Verdict\n      │\n      ▼\nListen to Explanation\n      │\n      ▼\nTake Action\n```\n\nNo separate paid speech API is required.\n\nThis is probably my favourite feature.\n\nBecause the answer isn't always:\n\n\"AI says Scam.\"\n\nand the user immediately knows exactly what to do.\n\nSometimes they are still unsure.\n\nAnd that's completely reasonable.\n\nSo Second Look has a:\n\nbutton.\n\nIt can use WhatsApp or the device's native share sheet to send a short explanation to someone the user trusts.\n\nThat changes the workflow from:\n\n**\"Send me the original message and I'll check it.\"**\n\nto:\n\n**\"Run a Second Look first.\"**\n\nAnd if the person still wants another human opinion, the family is one tap away.\n\n```\nSuspicious Message\n        │\n        ▼\n   Second Look\n        │\n        ▼\n AI Explanation\n        │\n   ┌────┴────┐\n   │         │\n   ▼         ▼\nUnderstood  Unsure\n               │\n               ▼\n        Send to Family\n```\n\nI didn't want AI to isolate the user from the people they trust.\n\nI wanted it to make that interaction easier.\n\nSecond Look can optionally use **MongoDB Atlas** for a family view of recent checks.\n\nThere is an important privacy distinction here:\n\n**The application stores verdicts, not the original messages.**\n\nSo the family view can show recent results without turning the database into a permanent archive of private SMS and WhatsApp conversations.\n\n```\n                         ┌──────────────────┐\n                         │       USER       │\n                         └─────────┬────────┘\n                                   │\n                    Text / Image / Screenshot\n                                   │\n                                   ▼\n                         ┌──────────────────┐\n                         │     FastAPI      │\n                         └─────────┬────────┘\n                                   │\n                                   ▼\n                        ┌────────────────────┐\n                        │ Privacy Redaction  │\n                        └─────────┬──────────┘\n                                  │\n                                  ▼\n                         ┌──────────────────┐\n                         │      Gemma       │\n                         │ Multimodal Model │\n                         └────────┬─────────┘\n                                  │\n                                  ▼\n                       ┌─────────────────────┐\n                       │ Risk + Explanation  │\n                       └──────────┬──────────┘\n                                  │\n              ┌───────────────────┼───────────────────┐\n              │                   │                   │\n              ▼                   ▼                   ▼\n           Verdict             Actions           Explanation\n              │                   │                   │\n              └───────────────────┼───────────────────┘\n                                  │\n                                  ▼\n                         ┌──────────────────┐\n                         │    Frontend      │\n                         │  HTML/CSS/JS     │\n                         └────────┬─────────┘\n                                  │\n                 ┌────────────────┼─────────────────┐\n                 │                │                 │\n                 ▼                ▼                 ▼\n             Read Aloud      Family Share      Recent Checks\n                                                (Optional DB)\n```\n\nI could have built a much bigger application.\n\nMore dashboards.\n\nMore graphs.\n\nMore technical indicators.\n\nMore complicated scoring.\n\nBut that wasn't the point.\n\nThe person using Second Look isn't trying to become a cybersecurity analyst.\n\nThey're trying to answer:\n\n**\"Can I trust this?\"**\n\nSo I kept the core interaction intentionally simple.\n\n```\nUpload\n  ↓\nCheck\n  ↓\nUnderstand\n  ↓\nAct\n```\n\nThe complexity stays behind the interface.\n\nThis project is where open innovation becomes more than just a buzzword.\n\nThe messages we're analyzing can be incredibly private.\n\nA bank notification.\n\nA WhatsApp conversation.\n\nA screenshot containing someone's financial information.\n\nA suspicious UPI request.\n\nThose aren't the kinds of things I want to blindly send to an unknown server.\n\nUsing an open-weight model gives Second Look another architecture:\n\n```\nPrivate Message\n      │\n      ▼\nSecond Look\n      │\n      ▼\nLocal Gemma\n      │\n      ▼\nResult\n```\n\nThe application can therefore move toward local inference when privacy requires it.\n\nThat's something I value much more than simply saying:\n\n**\"We used AI.\"**\n\nOpen innovation also gives us control over the architecture.\n\nThe model can change.\n\nThe inference provider can change.\n\nThe deployment can change.\n\nThe rest of the application doesn't need to be rebuilt from scratch.\n\nOne of the biggest things I learned while building Second Look is that **a model output is not a product**.\n\nA model can say:\n\n\"This looks like phishing.\"\n\nBut the user still has questions:\n\n**Why?**\n\n**What should I avoid?**\n\n**What should I do instead?**\n\n**Can I ask someone I trust?**\n\nThat's why the product is built around the entire decision-support flow rather than just the classification itself.\n\n```\nDetection\n   ↓\nExplanation\n   ↓\nRecommended Action\n   ↓\nHuman Support\n```\n\nThe AI is one component.\n\nThe experience around it is the actual product.\n\nBuilding Second Look taught me something I wasn't expecting.\n\nThe hardest part wasn't integrating a model.\n\nIt wasn't building the FastAPI backend.\n\nIt wasn't getting screenshots into the pipeline.\n\nThe hardest part was deciding **what the user actually needs to see**.\n\nA security system can technically identify something as suspicious and still fail the person using it.\n\nBecause knowing:\n\n**\"This is suspicious.\"**\n\nis not the same as knowing:\n\n**\"What should I do now?\"**\n\nThat distinction influenced almost every part of Second Look.\n\nSecond Look was built with AI-assisted development throughout the process.\n\nThe agent helped with architecture exploration, implementation, debugging, integrating the model workflow, and iterating on the user experience.\n\n[**Add your DevRelay agent session link here**]\n\nThe first version of Second Look started with something very ordinary.\n\nMy mom gets a suspicious message.\n\nShe isn't sure whether it is real.\n\nShe sends it to me.\n\nI check it.\n\nI reply:\n\n**\"Don't click it.\"**\n\nThen the next suspicious message comes.\n\nAnd we do the same thing again.\n\nThat made me realise something.\n\nI was effectively acting as a **human Second Look** every time.\n\nSo I turned that interaction into the product.\n\nNow the first step doesn't have to be:\n\n**\"Send this to my son.\"**\n\nIt can be:\n\n**\"Let me take a Second Look.\"**\n\nAnd when the answer still isn't enough, the family is still there.\n\nThat was important to me.\n\nBecause I don't want the AI to become the person my mom trusts instead of me.\n\nI want it to become the small tool that helps her decide **when she should stop and ask**.\n\nThe name came from the behaviour I wanted to encourage.\n\nNot:\n\n**Trust the AI.**\n\nNot:\n\n**Ignore everything.**\n\nJust:\n\n**Take a second look before you act.**\n\nBecause sometimes that extra ten seconds is enough to notice:\n\nThe product is called **Second Look** for exactly that reason.\n\nRight now, Second Look focuses on suspicious SMS messages, WhatsApp messages, and screenshots.\n\nBut I want to push the same idea further.\n\nImagine being able to right-click something suspicious on the web and ask:\n\n**\"Second Look?\"**\n\nImagine taking a screenshot of an unfamiliar payment request and getting an explanation immediately.\n\nImagine a parent receiving a message in Hindi and being able to hear the explanation instead of reading it.\n\nImagine a family having a lightweight safety layer where parents can ask for help without having to understand cybersecurity terminology.\n\nThe larger idea isn't just scam detection.\n\nIt's a **personal digital safety layer for people who don't want to become cybersecurity experts just to use the internet safely.**\n\nI didn't build Second Look to prove that Gemma can classify scam messages.\n\nI built it because I don't want the people I care about to feel like they have to understand cybersecurity before they can safely use a phone.\n\nThe ideal outcome isn't:\n\n**\"My mom trusts Second Look.\"**\n\nIt's:\n\n**\"My mom knows when to pause, understands why something looks suspicious, and knows who to ask when she's unsure.\"**\n\nThe AI is simply there to help create that pause.\n\n[**[https://second-look-b2nu.onrender.com/](https://second-look-b2nu.onrender.com/)*]\n\n**https://github.com/Fumer057/second-look**\n\n```\npython -m venv .venv\n.venv\\Scripts\\activate\nsource .venv/bin/activate\npip install -r requirements.txt\nuvicorn app:app --reload\nhttp://localhost:8000\nollama pull gemma3:4b\nLLM_BASE_URL=http://localhost:11434/v1\nLLM_API_KEY=\nLLM_MODEL=gemma3:4b\n```\n\nSecond Look includes a Render deployment configuration.\n\nYou can deploy directly from the repository:\n\nThen configure the required model API environment variable for hosted inference.\n\nSecond Look is intentionally small enough to understand and extend.\n\nContributions are welcome around:\n\nThe goal is to keep improving the system around the actual user problem rather than turning it into a generic AI demo.\n\n**MIT**\n\nA scam doesn't need to fool a cybersecurity expert.\n\nIt only needs to convince someone to act before they think.\n\nSo I wanted to add one tiny step in between:\n\n```\nMessage\n   ↓\nPause\n   ↓\nSecond Look\n   ↓\nUnderstand\n   ↓\nDecide\n```\n\n**Before you click, take a Second Look.**\n\n**Render,Gemma,ElevenLabs**", "url": "https://wpnews.pro/news/second-look-i-built-a-scam-checker-for-my-mom-after-she-sent-me-a-10k-payment", "canonical_source": "https://dev.to/rishabh_shukla_9c92e5c2c8/-second-look-i-built-a-scam-checker-for-my-mom-after-she-sent-me-a-10k-payment-screenshot-4lc4", "published_at": "2026-10-03 14:30:23+00:00", "updated_at": "2026-10-03 14:37:58.679410+00:00", "lang": "en", "topics": ["ai-products", "ai-tools", "artificial-intelligence", "ai-safety"], "entities": ["Second Look", "WhatsApp", "Hacktoberfest"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/second-look-i-built-a-scam-checker-for-my-mom-after-she-sent-me-a-10k-payment", "markdown": "https://wpnews.pro/news/second-look-i-built-a-scam-checker-for-my-mom-after-she-sent-me-a-10k-payment.md", "text": "https://wpnews.pro/news/second-look-i-built-a-scam-checker-for-my-mom-after-she-sent-me-a-10k-payment.txt", "jsonld": "https://wpnews.pro/news/second-look-i-built-a-scam-checker-for-my-mom-after-she-sent-me-a-10k-payment.jsonld"}}