guardianshield-scam-interception

byaabhii 2

SYSTEM ROLE & PERSONA Act as a Lead Mobile Security Engineer and Principal Backend Architect. Your task is to write production-ready, highly robust, and secure code for a system called GuardianShield. PROJECT OVERVIEW GuardianShield is an autonomous on-device scam interception platform for elderly users. It detects social engineering (impersonation, OTP harvesting, urgency) in real-time on Android devices and physically interrupts fraudulent transactions using extreme OS-level UI takeovers. It also features a "Caregiver Circuit Breaker" that allows a family member to remotely kill an active transaction on the senior's device via a low-latency cloud relay. THE THREE SYSTEM COMPONENTS & TECH STACK Elderly Victim Android App: Kotlin, Coroutines, Jetpack, ONNX Runtime Mobile, Android Accessibility APIs, WindowManager, Notifications API. Caregiver Android App: Kotlin, Firebase Cloud Messaging (FCM), OkHttp. Cloud Relay Server: Go (Golang), Gorilla WebSockets, Firebase Admin SDK. COMPONENT 1: THE ELDERLY ANDROID APP (THE EDGE GUARDIAN) 1. On-Device Edge ML Pipeline Requirement: Do NOT send text or audio to the cloud. Process everything locally using onnxruntime-android. Details: Write a lightweight, on-device WordPiece Tokenizer in Kotlin that loads from vocab.txt (handling [CLS], [SEP], [UNK], [PAD]). Max sequence length is 64. Write an OnnxScamClassifier class that takes the tokenized input_ids and attention_mask, feeds them into scam_classifier_int8.ort using OnnxTensor, and calculates a Softmax probability to identify threats (e.g., OTP_HARVESTING, AUTHORITY_IMPERSONATION). Ensure all native ONNX tensors are properly closed to prevent memory leaks outside the JVM GC. 2. Accessibility Service (The Node Scanner & Interceptor) Requirement: Create ScamGuardianAccessibilityService extending AccessibilityService. Details: Manifest/XML: Must bind to android.permission.BIND_ACCESSIBILITY_SERVICE and configure accessibilityEventTypes="typeWindowStateChanged|typeWindowContentChanged". Logic: Crawl rootInActiveWindow (depth limited to avoid memory churn) for targeted packages (e.g., com.google.android.dialer, net.one97.paytm). Look for regex/string matches combining urgency + financial keywords. Remote Kill Execution: Listen for a WebSocket callback command (LOCK_NOW). When received, execute performGlobalAction(GLOBAL_ACTION_HOME) and GLOBAL_ACTION_LOCK_SCREEN (API 28+). 3. The Unblockable UI Intervention (Anti-Tapjacking Fallback) Requirement: Banking apps use setHideOverlayWindows(true) and FLAG_SECURE, blocking normal floating windows. Details: Build two UI fallbacks: ScamOverlayManager: A standard floating overlay using TYPE_ACCESSIBILITY_OVERLAY for non-secure apps. Must include a "Hold 3s to Dismiss" button to introduce cognitive friction. EmergencyInterventionActivity: For protected banking apps. Uses USE_FULL_SCREEN_INTENT. Notification Dispatcher: Write a FullScreenAlertDispatcher that triggers the Full-Screen Intent. It must use a high-importance NotificationChannel with AudioAttributes.USAGE_ALARM to bypass Android's "Do Not Disturb" (DND) modes. COMPONENT 2: THE GO CLOUD RELAY (THE CIRCUIT BREAKER) 1. Stateless WebSocket & FCM Backend Requirement: Write a single main.go file using Gorilla WebSockets and Firebase Admin SDK. Details: Data Contracts (Optional fields support): Use omitempty and pointers for optional JSON fields. type AlertPayload struct { SessionID string `json:"session_id"` ElderlyDeviceID string `json:"device_id"` CaregiverFCM string `json:"caregiver_fcm_token,omitempty"` ThreatCategory string `json:"threat_category"` } Endpoints: GET /ws?device_id=XYZ: Upgrades to WebSocket, stores the active connection in a concurrency-safe map[string]*websocket.Conn protected by a sync.RWMutex. POST /api/v1/alert/raise: Receives threat payload from the senior's app and dispatches a High-Priority FCM Data Message to the caregiver. POST /api/v1/alert/respond: Receives LOCK_NOW from the caregiver, looks up the WebSocket connection by device_id, and immediately pushes the { "command": "LOCK_NOW" } JSON down the socket. COMPONENT 3: THE CAREGIVER APP 1. Push Notification Receiver & Action Dispatcher Requirement: Receive high-priority threat alerts and provide a 1-tap kill switch. Details: Implement FirebaseMessagingService. When an alert arrives, construct a NotificationCompat with PRIORITY_MAX and an embedded action button ("🛑 KILL TRANSACTION NOW"). Wire the action button to a BroadcastReceiver (RemoteLockActionReceiver) that executes an asynchronous OkHttp POST request back to the Go relay's /api/v1/alert/respond endpoint with the LOCK_NOW action. INSTRUCTIONS FOR YOUR OUTPUT Please generate the complete codebase step-by-step. First Output: Provide the AndroidManifest.xml and the build.gradle.kts files for the Android projects, plus the Go go.mod file. Second Output: Write the Kotlin ONNX ML Pipeline and Tokenizer. Third Output: Write the Kotlin Accessibility Service and Full-Screen Intent UI logic. Fourth Output: Write the entire Go backend relay. Fifth Output: Write the Caregiver App FCM logic. Make sure the code includes thorough comments explaining the platform workarounds (e.g., bypassing setHideOverlayWindows, intent flags for waking the screen, and coroutine scopes). Focus on extreme stability and low-latency execution.

No preview

Comments (0)

No comments yet. Be the first!

Project Tasks

16 planning tasks
Page design: Paused — add credits to continue
#1

Generate system requirement document

1m 10s0.2 cr used
Done
#2

Generate personas & user flows

0m 6s0.2 cr used
Done
#7

Create flow for Elderly User (Protected Senior)

0m 5sCredits in parent
Done
#8

Create flow for Caregiver (Family Circuit Breaker)

0m 5sCredits in parent
Done
#9

Landing

0m 35sCredits in subtasks
Paused
#16

Landing / Threat Dial

1.6 cr needed
Paused
#17

Landing / Interception Flow

1.6 cr needed
Paused
#18

Landing / Entry Actions

1.6 cr needed
Paused
#10

Sign Up

Credits in subtasks
Backlog
#11

Login

Credits in subtasks
Backlog
#12

Protection

Credits in subtasks
Backlog
#13

Intervention

Credits in subtasks
Backlog
#14

Alerts

Credits in subtasks
Backlog
#15

Circuit Breaker

Credits in subtasks
Backlog
#5

Architecture

0.2 cr needed
Paused
#6

Workspace task plan

0.2 cr needed
Paused

No completed page designs yet.

Completed design pages will appear here when they are ready to preview.

Landing: Open caregiver console
Sign Up: Select caregiver role
Sign Up: Create account
Login: Sign in
Alerts: 1. Review alert context
Circuit Breaker: 2. Review session context
Circuit Breaker: 3. Tap kill transaction now
Circuit Breaker: 4. Retry LOCK_NOW
Circuit Breaker: 5. Confirm remote lock
Alerts: 6. Refresh alert list

No completed page designs yet.

Completed design pages will appear here when they are ready to preview.

Landing: Open caregiver console
Sign Up: Select caregiver role
Sign Up: Create account
Login: Sign in
Alerts: 1. Review alert context
Circuit Breaker: 2. Review session context
Circuit Breaker: 3. Tap kill transaction now
Circuit Breaker: 4. Retry LOCK_NOW
Circuit Breaker: 5. Confirm remote lock
Alerts: 6. Refresh alert list