SYSTEM ROLE & PERSONA
Act as a Lead Mobile Security Engineer and Principal Backend Architect. Your task is to write production-ready, highly robust, and secure code for a system called GuardianShield.
PROJECT OVERVIEW
GuardianShield is an autonomous on-device scam interception platform for elderly users. It detects social engineering (impersonation, OTP harvesting, urgency) in real-time on Android devices and physically interrupts fraudulent transactions using extreme OS-level UI takeovers. It also features a "Caregiver Circuit Breaker" that allows a family member to remotely kill an active transaction on the senior's device via a low-latency cloud relay.
THE THREE SYSTEM COMPONENTS & TECH STACK
Elderly Victim Android App: Kotlin, Coroutines, Jetpack, ONNX Runtime Mobile, Android Accessibility APIs, WindowManager, Notifications API.
Caregiver Android App: Kotlin, Firebase Cloud Messaging (FCM), OkHttp.
Cloud Relay Server: Go (Golang), Gorilla WebSockets, Firebase Admin SDK.
COMPONENT 1: THE ELDERLY ANDROID APP (THE EDGE GUARDIAN)
1. On-Device Edge ML Pipeline
Requirement: Do NOT send text or audio to the cloud. Process everything locally using onnxruntime-android.
Details:
Write a lightweight, on-device WordPiece Tokenizer in Kotlin that loads from vocab.txt (handling [CLS], [SEP], [UNK], [PAD]). Max sequence length is 64.
Write an OnnxScamClassifier class that takes the tokenized input_ids and attention_mask, feeds them into scam_classifier_int8.ort using OnnxTensor, and calculates a Softmax probability to identify threats (e.g., OTP_HARVESTING, AUTHORITY_IMPERSONATION).
Ensure all native ONNX tensors are properly closed to prevent memory leaks outside the JVM GC.
2. Accessibility Service (The Node Scanner & Interceptor)
Requirement: Create ScamGuardianAccessibilityService extending AccessibilityService.
Details:
Manifest/XML: Must bind to android.permission.BIND_ACCESSIBILITY_SERVICE and configure accessibilityEventTypes="typeWindowStateChanged|typeWindowContentChanged".
Logic: Crawl rootInActiveWindow (depth limited to avoid memory churn) for targeted packages (e.g., com.google.android.dialer, net.one97.paytm). Look for regex/string matches combining urgency + financial keywords.
Remote Kill Execution: Listen for a WebSocket callback command (LOCK_NOW). When received, execute performGlobalAction(GLOBAL_ACTION_HOME) and GLOBAL_ACTION_LOCK_SCREEN (API 28+).
3. The Unblockable UI Intervention (Anti-Tapjacking Fallback)
Requirement: Banking apps use setHideOverlayWindows(true) and FLAG_SECURE, blocking normal floating windows.
Details:
Build two UI fallbacks:
ScamOverlayManager: A standard floating overlay using TYPE_ACCESSIBILITY_OVERLAY for non-secure apps. Must include a "Hold 3s to Dismiss" button to introduce cognitive friction.
EmergencyInterventionActivity: For protected banking apps. Uses USE_FULL_SCREEN_INTENT.
Notification Dispatcher: Write a FullScreenAlertDispatcher that triggers the Full-Screen Intent. It must use a high-importance NotificationChannel with AudioAttributes.USAGE_ALARM to bypass Android's "Do Not Disturb" (DND) modes.
COMPONENT 2: THE GO CLOUD RELAY (THE CIRCUIT BREAKER)
1. Stateless WebSocket & FCM Backend
Requirement: Write a single main.go file using Gorilla WebSockets and Firebase Admin SDK.
Details:
Data Contracts (Optional fields support): Use omitempty and pointers for optional JSON fields.
type AlertPayload struct {
SessionID string `json:"session_id"`
ElderlyDeviceID string `json:"device_id"`
CaregiverFCM string `json:"caregiver_fcm_token,omitempty"`
ThreatCategory string `json:"threat_category"`
}
Endpoints:
GET /ws?device_id=XYZ: Upgrades to WebSocket, stores the active connection in a concurrency-safe map[string]*websocket.Conn protected by a sync.RWMutex.
POST /api/v1/alert/raise: Receives threat payload from the senior's app and dispatches a High-Priority FCM Data Message to the caregiver.
POST /api/v1/alert/respond: Receives LOCK_NOW from the caregiver, looks up the WebSocket connection by device_id, and immediately pushes the { "command": "LOCK_NOW" } JSON down the socket.
COMPONENT 3: THE CAREGIVER APP
1. Push Notification Receiver & Action Dispatcher
Requirement: Receive high-priority threat alerts and provide a 1-tap kill switch.
Details:
Implement FirebaseMessagingService.
When an alert arrives, construct a NotificationCompat with PRIORITY_MAX and an embedded action button ("🛑 KILL TRANSACTION NOW").
Wire the action button to a BroadcastReceiver (RemoteLockActionReceiver) that executes an asynchronous OkHttp POST request back to the Go relay's /api/v1/alert/respond endpoint with the LOCK_NOW action.
INSTRUCTIONS FOR YOUR OUTPUT
Please generate the complete codebase step-by-step.
First Output: Provide the AndroidManifest.xml and the build.gradle.kts files for the Android projects, plus the Go go.mod file.
Second Output: Write the Kotlin ONNX ML Pipeline and Tokenizer.
Third Output: Write the Kotlin Accessibility Service and Full-Screen Intent UI logic.
Fourth Output: Write the entire Go backend relay.
Fifth Output: Write the Caregiver App FCM logic.
Make sure the code includes thorough comments explaining the platform workarounds (e.g., bypassing setHideOverlayWindows, intent flags for waking the screen, and coroutine scopes). Focus on extreme stability and low-latency execution.
No preview
Comments (0)
No comments yet. Be the first!
Sign in to leave a comment
Project Tasks
16 planning tasks
Page design: Paused — add credits to continue
#1
Generate system requirement document
1m 10s0.2 cr used
Done
#2
Generate personas & user flows
0m 6s0.2 cr used
Done
#7
Create flow for Elderly User (Protected Senior)
0m 5sCredits in parent
Done
#8
Create flow for Caregiver (Family Circuit Breaker)
0m 5sCredits in parent
Done
#9
Landing
0m 35sCredits in subtasks
Paused
#16
Landing / Threat Dial
1.6 cr needed
Paused
#17
Landing / Interception Flow
1.6 cr needed
Paused
#18
Landing / Entry Actions
1.6 cr needed
Paused
#10
Sign Up
Credits in subtasks
Backlog
#11
Login
Credits in subtasks
Backlog
#12
Protection
Credits in subtasks
Backlog
#13
Intervention
Credits in subtasks
Backlog
#14
Alerts
Credits in subtasks
Backlog
#15
Circuit Breaker
Credits in subtasks
Backlog
#5
Architecture
0.2 cr needed
Paused
#6
Workspace task plan
0.2 cr needed
Paused
No completed page designs yet.
Completed design pages will appear here when they are ready to preview.
No completed page designs yet.
Completed design pages will appear here when they are ready to preview.
No comments yet. Be the first!