# Second Look: I Built a Scam Checker for My Mom After She Sent Me a ₹10k Payment Screenshot

> Source: <https://dev.to/rishabh_shukla_9c92e5c2c8/-second-look-i-built-a-scam-checker-for-my-mom-after-she-sent-me-a-10k-payment-screenshot-4lc4>
> Published: 2026-10-03 14:30:23+00:00

*This is a submission for the [Hacktoberfest Weekend Challenge: Build for a Friend](https://dev.to/challenges/hacktoberfest-weekend-2026-10-01)*

**A small AI safety layer for the people in our families who get asked to "just click this once."**

I built **Second Look** for my mom.

The idea started from a situation that feels very familiar in a lot of Indian families.

She gets a suspicious message.

She isn't sure whether it is real.

And the first thing she does is send it to me.

**"Is this genuine?"**

So I thought about what that interaction could look like in a worst-case scenario.

Imagine opening WhatsApp and seeing a screenshot of a **₹10,000 payment**.

The message underneath says:

*"Your bank KYC has expired. Your account will be blocked today. Verify immediately using the link below."*

There is a link.

There is a transaction reference.

There is a familiar-looking bank name.

And there is one thing the message is really good at creating:

**Urgency.**

The screenshot used with this post is the real one that my mom talked about

The important part isn't the exact ₹10k amount.

It's the question that comes after seeing something like that:

**"Should I click this?"**

That's the question I wanted to make easier to answer.

I didn't want to build another cybersecurity dashboard filled with technical indicators that only security professionals understand.

I wanted something my mom could actually use.

So I built **Second Look**.

Second Look is a small **AI-powered scam checker** that lets a user paste a suspicious SMS or WhatsApp message, or upload a screenshot, and get a clear, understandable verdict.

The application gives three simple outcomes:

Strong indicators of fraud or social engineering were detected.

The message contains suspicious elements and should be verified before taking action.

Nothing strongly suspicious was identified from the information available.

But the verdict itself isn't the important part.

Second Look also explains:

**Why does this look suspicious?**

**What should I do next?**

**What should I avoid doing?**

And if the person still isn't comfortable making that decision alone, they can use:

**"Send to my family"**

to share the result with someone they trust.

So the experience becomes:

```
Suspicious Message
        │
        ▼
   Second Look
        │
        ▼
 Understand the Risk
        │
        ▼
   What To Do Next
        │
        ├────────────────┐
        ▼                ▼
   Take Action       Ask Family
```

I didn't want AI to replace the person you trust.

I wanted it to make the first check faster and easier.

Scam messages are often effective precisely because they don't look obviously fake.

They create pressure.

They use familiar language.

They mention things people recognize:

A person receiving one of these messages doesn't necessarily need a lesson in cybersecurity.

They need an answer to a much simpler question:

**"What is happening, and what should I do right now?"**

That's how I approached Second Look.

Instead of giving the user:

"This message exhibits characteristics of credential harvesting and social engineering."

the application should explain the situation in plain language.

Something closer to:

**This message is creating urgency and asking you to verify your account through a link. Don't click it. Contact your bank through its official website or app instead.**

That difference matters.

The model isn't there just to classify.

It is there to **explain**.

Second Look accepts both **text and screenshots**.

That's important because suspicious content doesn't always arrive as clean, copyable text.

Sometimes it's an SMS.

Sometimes it's a WhatsApp message.

Sometimes someone sends you a screenshot and says:

"Look at this."

So the pipeline looks like this:

```
                         ┌────────────────────┐
                         │        USER        │
                         └──────────┬─────────┘
                                    │
                    ┌───────────────┴───────────────┐
                    │                               │
                    ▼                               ▼
              Paste Text                    Upload Screenshot
                    │                               │
                    └───────────────┬───────────────┘
                                    │
                                    ▼
                         ┌─────────────────────┐
                         │   Privacy Layer     │
                         │                     │
                         │ Card / PAN / Aadhaar│
                         │ / Account Redaction │
                         └──────────┬──────────┘
                                    │
                                    ▼
                           ┌──────────────────┐
                           │      Gemma       │
                           │  Multimodal AI   │
                           └─────────┬────────┘
                                     │
                                     ▼
                        ┌────────────────────────┐
                        │ Scam / Risk Analysis   │
                        │                        │
                        │ + Explanation          │
                        │ + Recommended Action   │
                        └───────────┬────────────┘
                                    │
                    ┌───────────────┼───────────────┐
                    │               │               │
                    ▼               ▼               ▼
                 🚨 Scam       ⚠️ Be Careful    ✅ Looks OK
                    │               │               │
                    └───────────────┼───────────────┘
                                    │
                                    ▼
                         ┌────────────────────┐
                         │  What should I do? │
                         └──────────┬─────────┘
                                    │
                       ┌────────────┴────────────┐
                       │                         │
                       ▼                         ▼
                   Read Aloud             Send to Family
```

The important architectural decision is that **privacy comes before model inference**.

That was deliberate.

The messages we're dealing with can contain extremely sensitive information.

A bank message might contain:

So before anything reaches the model, Second Look redacts sensitive identifiers.

The application specifically handles things such as:

The basic idea is:

```
Raw Message
     │
     ▼
Sensitive Data Redaction
     │
     ▼
Sanitized Message
     │
     ▼
Gemma
     │
     ▼
Verdict + Explanation
```

The model should get enough context to understand what is happening without unnecessarily receiving sensitive financial information.

That was a product requirement from the beginning, not something I wanted to bolt on later.

The core model powering Second Look is **Gemma**, Google's open-weight model.

I specifically wanted to build around an open model instead of making the entire application dependent on one closed API.

Second Look uses an **OpenAI-compatible interface**, which makes the model backend replaceable.

That gives the application two paths:

```
                         Second Look
                              │
                              ▼
                 OpenAI-Compatible Interface
                              │
                   ┌──────────┴──────────┐
                   │                     │
                   ▼                     ▼
              Hosted Gemma          Local Ollama
                                         │
                                         ▼
                                     Gemma 3 4B
```

The local path is especially interesting because it gives the application a route toward **private local inference**.

Second Look can run with **Ollama** and Gemma locally.

```
ollama pull gemma3:4b
```

Then configure:

```
LLM_BASE_URL=http://localhost:11434/v1
LLM_API_KEY=
LLM_MODEL=gemma3:4b
```

And run the application locally:

```
python -m venv .venv
.venv\Scripts\activate
source .venv/bin/activate
```

Then:

```
pip install -r requirements.txt
uvicorn app:app --reload
```

Open:

```
http://localhost:8000
```

The important part is that **the application code doesn't need to be rewritten** just because the model moves from a hosted endpoint to a local Ollama instance.

One of the things I really wanted was screenshot support.

Because people don't always copy suspicious messages.

Sometimes the entire interaction is an image.

So Second Look supports:

```
Text
 │
 ▼
Gemma
```

and:

```
Screenshot
 │
 ▼
Multimodal Gemma
 │
 ▼
Analysis
```

This makes the system much closer to how people actually encounter suspicious content.

The application is tuned around scam patterns that are particularly relevant to users in India.

Some examples include:

The application can also surface the **1930 cyber-fraud helpline** when appropriate.

This is not intended to be a universal cybercrime classifier.

It's meant to be a **first layer of decision support** before someone clicks, pays, shares credentials, or follows instructions from a suspicious message.

There was another problem I didn't want to ignore:

**Language.**

Security advice isn't very useful if the person receiving it has to translate it first.

Second Look supports responses in **12 languages**, including:

The selected language is remembered.

So a user doesn't need to keep configuring the application every time they check another message.

The idea is simple:

**Digital safety advice should be understandable in the language you actually use.**

There is also a small accessibility feature that turned out to be useful.

The application can read the verdict aloud using the browser's built-in speech engine.

So instead of reading a long explanation on a phone screen:

```
Check Message
      │
      ▼
Get Verdict
      │
      ▼
Listen to Explanation
      │
      ▼
Take Action
```

No separate paid speech API is required.

This is probably my favourite feature.

Because the answer isn't always:

"AI says Scam."

and the user immediately knows exactly what to do.

Sometimes they are still unsure.

And that's completely reasonable.

So Second Look has a:

button.

It can use WhatsApp or the device's native share sheet to send a short explanation to someone the user trusts.

That changes the workflow from:

**"Send me the original message and I'll check it."**

to:

**"Run a Second Look first."**

And if the person still wants another human opinion, the family is one tap away.

```
Suspicious Message
        │
        ▼
   Second Look
        │
        ▼
 AI Explanation
        │
   ┌────┴────┐
   │         │
   ▼         ▼
Understood  Unsure
               │
               ▼
        Send to Family
```

I didn't want AI to isolate the user from the people they trust.

I wanted it to make that interaction easier.

Second Look can optionally use **MongoDB Atlas** for a family view of recent checks.

There is an important privacy distinction here:

**The application stores verdicts, not the original messages.**

So the family view can show recent results without turning the database into a permanent archive of private SMS and WhatsApp conversations.

```
                         ┌──────────────────┐
                         │       USER       │
                         └─────────┬────────┘
                                   │
                    Text / Image / Screenshot
                                   │
                                   ▼
                         ┌──────────────────┐
                         │     FastAPI      │
                         └─────────┬────────┘
                                   │
                                   ▼
                        ┌────────────────────┐
                        │ Privacy Redaction  │
                        └─────────┬──────────┘
                                  │
                                  ▼
                         ┌──────────────────┐
                         │      Gemma       │
                         │ Multimodal Model │
                         └────────┬─────────┘
                                  │
                                  ▼
                       ┌─────────────────────┐
                       │ Risk + Explanation  │
                       └──────────┬──────────┘
                                  │
              ┌───────────────────┼───────────────────┐
              │                   │                   │
              ▼                   ▼                   ▼
           Verdict             Actions           Explanation
              │                   │                   │
              └───────────────────┼───────────────────┘
                                  │
                                  ▼
                         ┌──────────────────┐
                         │    Frontend      │
                         │  HTML/CSS/JS     │
                         └────────┬─────────┘
                                  │
                 ┌────────────────┼─────────────────┐
                 │                │                 │
                 ▼                ▼                 ▼
             Read Aloud      Family Share      Recent Checks
                                                (Optional DB)
```

I could have built a much bigger application.

More dashboards.

More graphs.

More technical indicators.

More complicated scoring.

But that wasn't the point.

The person using Second Look isn't trying to become a cybersecurity analyst.

They're trying to answer:

**"Can I trust this?"**

So I kept the core interaction intentionally simple.

```
Upload
  ↓
Check
  ↓
Understand
  ↓
Act
```

The complexity stays behind the interface.

This project is where open innovation becomes more than just a buzzword.

The messages we're analyzing can be incredibly private.

A bank notification.

A WhatsApp conversation.

A screenshot containing someone's financial information.

A suspicious UPI request.

Those aren't the kinds of things I want to blindly send to an unknown server.

Using an open-weight model gives Second Look another architecture:

```
Private Message
      │
      ▼
Second Look
      │
      ▼
Local Gemma
      │
      ▼
Result
```

The application can therefore move toward local inference when privacy requires it.

That's something I value much more than simply saying:

**"We used AI."**

Open innovation also gives us control over the architecture.

The model can change.

The inference provider can change.

The deployment can change.

The rest of the application doesn't need to be rebuilt from scratch.

One of the biggest things I learned while building Second Look is that **a model output is not a product**.

A model can say:

"This looks like phishing."

But the user still has questions:

**Why?**

**What should I avoid?**

**What should I do instead?**

**Can I ask someone I trust?**

That's why the product is built around the entire decision-support flow rather than just the classification itself.

```
Detection
   ↓
Explanation
   ↓
Recommended Action
   ↓
Human Support
```

The AI is one component.

The experience around it is the actual product.

Building Second Look taught me something I wasn't expecting.

The hardest part wasn't integrating a model.

It wasn't building the FastAPI backend.

It wasn't getting screenshots into the pipeline.

The hardest part was deciding **what the user actually needs to see**.

A security system can technically identify something as suspicious and still fail the person using it.

Because knowing:

**"This is suspicious."**

is not the same as knowing:

**"What should I do now?"**

That distinction influenced almost every part of Second Look.

Second Look was built with AI-assisted development throughout the process.

The agent helped with architecture exploration, implementation, debugging, integrating the model workflow, and iterating on the user experience.

[**Add your DevRelay agent session link here**]

The first version of Second Look started with something very ordinary.

My mom gets a suspicious message.

She isn't sure whether it is real.

She sends it to me.

I check it.

I reply:

**"Don't click it."**

Then the next suspicious message comes.

And we do the same thing again.

That made me realise something.

I was effectively acting as a **human Second Look** every time.

So I turned that interaction into the product.

Now the first step doesn't have to be:

**"Send this to my son."**

It can be:

**"Let me take a Second Look."**

And when the answer still isn't enough, the family is still there.

That was important to me.

Because I don't want the AI to become the person my mom trusts instead of me.

I want it to become the small tool that helps her decide **when she should stop and ask**.

The name came from the behaviour I wanted to encourage.

Not:

**Trust the AI.**

Not:

**Ignore everything.**

Just:

**Take a second look before you act.**

Because sometimes that extra ten seconds is enough to notice:

The product is called **Second Look** for exactly that reason.

Right now, Second Look focuses on suspicious SMS messages, WhatsApp messages, and screenshots.

But I want to push the same idea further.

Imagine being able to right-click something suspicious on the web and ask:

**"Second Look?"**

Imagine taking a screenshot of an unfamiliar payment request and getting an explanation immediately.

Imagine a parent receiving a message in Hindi and being able to hear the explanation instead of reading it.

Imagine a family having a lightweight safety layer where parents can ask for help without having to understand cybersecurity terminology.

The larger idea isn't just scam detection.

It's a **personal digital safety layer for people who don't want to become cybersecurity experts just to use the internet safely.**

I didn't build Second Look to prove that Gemma can classify scam messages.

I built it because I don't want the people I care about to feel like they have to understand cybersecurity before they can safely use a phone.

The ideal outcome isn't:

**"My mom trusts Second Look."**

It's:

**"My mom knows when to pause, understands why something looks suspicious, and knows who to ask when she's unsure."**

The AI is simply there to help create that pause.

[**[https://second-look-b2nu.onrender.com/](https://second-look-b2nu.onrender.com/)*]

**https://github.com/Fumer057/second-look**

```
python -m venv .venv
.venv\Scripts\activate
source .venv/bin/activate
pip install -r requirements.txt
uvicorn app:app --reload
http://localhost:8000
ollama pull gemma3:4b
LLM_BASE_URL=http://localhost:11434/v1
LLM_API_KEY=
LLM_MODEL=gemma3:4b
```

Second Look includes a Render deployment configuration.

You can deploy directly from the repository:

Then configure the required model API environment variable for hosted inference.

Second Look is intentionally small enough to understand and extend.

Contributions are welcome around:

The goal is to keep improving the system around the actual user problem rather than turning it into a generic AI demo.

**MIT**

A scam doesn't need to fool a cybersecurity expert.

It only needs to convince someone to act before they think.

So I wanted to add one tiny step in between:

```
Message
   ↓
Pause
   ↓
Second Look
   ↓
Understand
   ↓
Decide
```

**Before you click, take a Second Look.**

**Render,Gemma,ElevenLabs**
