SYSTEM ROLE & PERSONA Act as a Lead Mobile Security Engineer and Principal Backend Architect. Your task is to write production-ready, highly robust, and secure code for a system called GuardianShield. PROJECT OVERVIEW GuardianShield is an autonomous on-device scam interception platform for elderly users. It detects social engineering (impersonation, OTP harvesting, urgency) in real-time on Android devices and physically interrupts fraudulent transactions using extreme OS-level UI takeovers. It also features a "Caregiver Circuit Breaker" that allows a family member to remotely kill an active transaction on the senior's device via a low-latency cloud relay. THE THREE SYSTEM COMPONENTS & TECH STACK Elderly Victim Android App: Kotlin, Coroutines, Jetpack, ONNX Runtime Mobile, Android Accessibility APIs, WindowManager, Notifications API. Caregiver Android App: Kotlin, Firebase Cloud Messaging (FCM), OkHttp. Cloud Relay Server: Go (Golang), Gorilla WebSockets, Firebase Admin SDK. COMPONENT 1: THE ELDERLY ANDROID APP (THE EDGE GUARDIAN) 1. On-Device Edge ML Pipeline Requirement: Do NOT send text or audio to the cloud. Process everything locally using onnxruntime-android. Details: Write a lightweight, on-device WordPiece Tokenizer in Kotlin that loads from vocab.txt (handling [CLS], [SEP], [UNK], [PAD]). Max sequence length is 64. Write an OnnxScamClassifier class that takes the tokenized input_ids and attention_mask, feeds them into scam_classifier_int8.ort using OnnxTensor, and calculates a Softmax probability to identify threats (e.g., OTP_HARVESTING, AUTHORITY_IMPERSONATION). Ensure all native ONNX tensors are properly closed to prevent memory leaks outside the JVM GC. 2. Accessibility Service (The Node Scanner & Interceptor) Requirement: Create ScamGuardianAccessibilityService extending AccessibilityService. Details: Manifest/XML: Must bind to android.permission.BIND_ACCESSIBILITY_SERVICE and configure accessibilityEventTypes="typeWindowStateChanged|typeWindowContentChanged". Logic: Crawl rootInActiveWindow (depth limited to avoid memory churn) for targeted packages (e.g., com.google.android.dialer, net.one97.paytm). Look for regex/string matches combining urgency + financial keywords. Remote Kill Execution: Listen for a WebSocket callback command (LOCK_NOW). When received, execute performGlobalAction(GLOBAL_ACTION_HOME) and GLOBAL_ACTION_LOCK_SCREEN (API 28+). 3. The Unblockable UI Intervention (Anti-Tapjacking Fallback) Requirement: Banking apps use setHideOverlayWindows(true) and FLAG_SECURE, blocking normal floating windows. Details: Build two UI fallbacks: ScamOverlayManager: A standard floating overlay using TYPE_ACCESSIBILITY_OVERLAY for non-secure apps. Must include a "Hold 3s to Dismiss" button to introduce cognitive friction. EmergencyInterventionActivity: For protected banking apps. Uses USE_FULL_SCREEN_INTENT. Notification Dispatcher: Write a FullScreenAlertDispatcher that triggers the Full-Screen Intent. It must use a high-importance NotificationChannel with AudioAttributes.USAGE_ALARM to bypass Android's "Do Not Disturb" (DND) modes. COMPONENT 2: THE GO CLOUD RELAY (THE CIRCUIT BREAKER) 1. Stateless WebSocket & FCM Backend Requirement: Write a single main.go file using Gorilla WebSockets and Firebase Admin SDK. Details: Data Contracts (Optional fields support): Use omitempty and pointers for optional JSON fields. type AlertPayload struct { SessionID string `json:"session_id"` ElderlyDeviceID string `json:"device_id"` CaregiverFCM string `json:"caregiver_fcm_token,omitempty"` ThreatCategory string `json:"threat_category"` } Endpoints: GET /ws?device_id=XYZ: Upgrades to WebSocket, stores the active connection in a concurrency-safe map[string]*websocket.Conn protected by a sync.RWMutex. POST /api/v1/alert/raise: Receives threat payload from the senior's app and dispatches a High-Priority FCM Data Message to the caregiver. POST /api/v1/alert/respond: Receives LOCK_NOW from the caregiver, looks up the WebSocket connection by device_id, and immediately pushes the { "command": "LOCK_NOW" } JSON down the socket. COMPONENT 3: THE CAREGIVER APP 1. Push Notification Receiver & Action Dispatcher Requirement: Receive high-priority threat alerts and provide a 1-tap kill switch. Details: Implement FirebaseMessagingService. When an alert arrives, construct a NotificationCompat with PRIORITY_MAX and an embedded action button ("đ KILL TRANSACTION NOW"). Wire the action button to a BroadcastReceiver (RemoteLockActionReceiver) that executes an asynchronous OkHttp POST request back to the Go relay's /api/v1/alert/respond endpoint with the LOCK_NOW action. INSTRUCTIONS FOR YOUR OUTPUT Please generate the complete codebase step-by-step. First Output: Provide the AndroidManifest.xml and the build.gradle.kts files for the Android projects, plus the Go go.mod file. Second Output: Write the Kotlin ONNX ML Pipeline and Tokenizer. Third Output: Write the Kotlin Accessibility Service and Full-Screen Intent UI logic. Fourth Output: Write the entire Go backend relay. Fifth Output: Write the Caregiver App FCM logic. Make sure the code includes thorough comments explaining the platform workarounds (e.g., bypassing setHideOverlayWindows, intent flags for waking the screen, and coroutine scopes). Focus on extreme stability and low-latency execution.
Sign in to leave a comment
Architecture diagrams will be automatically generated when the Project Manager creates tasks for your project.
No completed page designs yet.
Completed design pages will appear here when they are ready to preview.
No completed page designs yet.
Completed design pages will appear here when they are ready to preview.
No comments yet. Be the first!