Review 6 of 6 — Skeptical Product / Scope Critic

Reviewer lens: is this worth building, for one technical owner, on his own Samsung (maybe Pixel), and what is the smallest thing that proves it?

Inputs: PRD-original.md (truncated at §7) and DESIGN-DRAFT.md. Date: 2026-10-03.

Bottom line. The PRD is written like a consumer product heading for the Play Store. It carries Play-policy constraints, consumer-grade transparency settings and five numeric dimensions. The owner is one person sideloading onto his own phone. Most of the scope protects against problems he does not have.

The draft's claimed differentiator is the stateful trajectory (opener → wrong-number pivot → platform shift → investment). As of 2026 that is exactly what Google's on-device Scam Detection targets, and it is on by default for non-contacts. The genuinely unique value is narrower:

  1. Personal expected-sender context.
  2. Explanation of why.
  3. Calmer handling of low-context unknowns.
  4. A one-tap "who is this?" draft.

That is a 2-week build, not a multi-phase program. Gate it on a measured volume of unknown-sender messages before writing the classifier.


1. Is notification-only data enough?

For the narrow core value ("don't call a stranger spam just because they're a stranger"), mostly yes. For the PRD's full ambition (history-aware, multi-signal trust), no.

The estimates below are reviewer judgment, not measurements. The Phase 0 probe should replace them with real numbers.

Missing dataWhat it costsEst. share of total value lost
Outbound history ("I texted this number first")This is the single strongest legitimacy signal for a non-contact: the plumber you texted, the clinic you replied to last month. Without it, every unsaved number you have already engaged with looks like a cold stranger. The MessagingStyle tail (android.messages) sometimes includes your recent replies in the current thread, which is partial and unreliable.20–30%. The biggest loss.
Spam-folder messagesGoogle posts no notification for messages it files as spam, so the sidecar never sees them. This is the PRD's core thesis failing the other way: the worst "unknown treated as malicious" error (a legitimate stranger silently auto-filed) is invisible to the sidecar. The sidecar can only re-grade what Google already let through.10–20%, and it is the most painful 10–20%.
Full thread historyWeakens trajectory detection. It is mitigated if the sidecar keeps its own per-sender verdict history from the notifications it has seen, which the draft already proposes.5–10%
MMS images / attachmentsImage-only scams (QR codes, screenshot "invoices") get "Cannot assess". These are rare in personal SMS volume.<5%
Verified-business / RCS metadataLoses a strong positive signal for business senders. Short codes partially substitute.~5%

Net: notification-only keeps maybe 50–65% of the conceivable value. Almost all the loss is on the legitimacy side (history), not the risk side. That is backwards for this product, which exists to protect legitimacy.

Cheap recovery the PRD forbids by inheritance, not necessity. READ_SMS and READ_CALL_LOG are banned by Google Play policy, not by the OS. For an adb-installed personal app they may be grantable. Mark this verify in the spike, because hard-restricted permission allowlisting and Android 13+/15 "restricted settings" may still gate it. Two caveats:

This contradicts PRD §4.2. It is labeled as an owner decision: "the non-goal exists because of Play policy, which does not apply to a personal sideload; revisit?"

Cheap partial fix for spam-folder blindness (on-thesis, high value): if an expected sender (dentist, FedEx, new employer) is due and no matching message has arrived by the expected time, nudge: "Expected Bright Smile Dental — nothing arrived. Check Spam & blocked in Messages." That is the only way a notification-only sidecar can rescue a stranger Google filed away.


2. Competitive reality (2025–2026)

LayerWhat it does todaySource
Google Messages Scam DetectionOn-device AI flags conversational scams (job, romance-baiting / pig-butchering, "switch to another app") across SMS/MMS/RCS. On by default, only for non-contacts, English, US/UK/CA. The user can dismiss, or report and block. No explanation of why is described.https://blog.google/security/new-ai-powered-scam-detection-features/
Gemini Nano upgrade to the aboveFlagships (Pixel 10 series, Galaxy S26, select others): "more nuanced analysis" of gradual-manipulation conversations.https://9to5google.com/2026/02/25/google-messages-scam-detection-gemini/
Google Messages link / sender protectionsWarnings on links from unknown senders, an unknown-international-sender filter (to Spam & blocked), and Key Verifier for contact identity. These were announced 2024 and rolled out in stages by region.https://security.googleblog.com/2024/10/5-new-protections-on-google-messages.html and https://blog.google/technology/safety-security/how-google-protects-against-scams-2025/
Classic Google spam filterAuto-files spam to "Spam & blocked" with no notification, which is the blind spot in §1.same
Samsung Message GuardA zero-click image sandbox, not scam-text triage. Irrelevant to this problem. (Samsung's "AI spam filter" headlines refer to a Korea KCC program and do not apply to US Galaxy.) On a US Samsung the real competitor is Google Messages.https://docs.samsungknox.com/admin/fundamentals/whitepaper/samsung-knox-mobile-security/application-security/samsung-message-guard/
Carrier filtersT-Mobile network-side SMS/MMS/RCS spam fingerprinting plus Scam Shield. Verizon/AT&T similar. Reporting via 7726. These are blunt and opaque, and they kill bulk spam before it reaches the phone.https://www.t-mobile.com/scamshield
Android OSAndroid 15 redacts OTP-like notifications from untrusted listeners (RECEIVE_SENSITIVE_NOTIFICATIONS is role/signature-gated). This is good for privacy and bad for analysis completeness.https://www.androidauthority.com/android-15-sensitive-notifications-3416414

What this means for the draft's "differentiator":

Residual problem only this app solves:

  1. Personal context. "I'm expecting Carlos from The Ashford and a FedEx this week." No platform filter knows that, and it is what moves a legitimate stranger from unknown to likely legitimate. This is the product.
  2. Explanation. Google says "likely scam". The sidecar says which evidence and what it doesn't know. That matters most when Google is silent: "Unrecognized: no self-ID, no link, no ask."
  3. Tiered attention for unknowns. Google has two states, inbox or spam. Nothing gives a middle "real but low-context, look later" tier.
  4. "Who is this?" in one tap. It is small, but it is the most-used action.
  5. The expected-sender-missing nudge, as the only window into the spam folder.

Everything else in the PRD duplicates work done upstream.


3. Scope: v1 is over-scoped. The 2-week version:

Ranked by value ÷ effort:

#FeatureValueEffortVerdict
1Phase 0 probe as a volume meter (contact / non-contact / short code per week, from Person uri and title format only, no text)Kill gate1 dayKeep. Do first.
2Listener + MessagingStyle parse + "in contacts" inferred from Person uri (no READ_CONTACTS)Foundation2 daysKeep
3~15 deterministic reason codes + the 6-verdict decision table + golden corpus testsCore3 daysKeep, with verdict + codes only
4Expected-sender list (free text + optional brand/number + expiry)Highest unique value1–2 daysKeep
5Annotation notification (silent, verdict + top 2 reasons)Core UX1 dayKeep
6"Ask who this is" smsto: draftHigh, tiny0.5 dayKeep
7"Expected sender didn't arrive → check Spam" nudgeHigh, on-thesis0.5 dayKeep
8Trust sender (local list)Medium0.5 dayKeep
9Last-50 log screen (verdict + codes, no bodies)Medium (debug + trust)1 dayKeep
10Per-sender last-5 verdict history (trajectory-lite)Low–medium (overlaps Google)1 dayv1.1
11Five numeric dimensions shown in the UILow. Verdict + codes carries the meaning, and completeness collapses into "Cannot assess"2 daysCut (compute internally if needed)
12Quiet-unknowns re-notify modeHigh if right, and dangerous3–4 daysCut from v1. Its failure mode (sidecar dead, so messages from real people go silent) is the exact harm the product exists to prevent. Revisit after 30 days of annotate-mode precision data.
13Feedback-learned weight multipliersLow at n≈single-digit/week2 daysCut. Manual trust plus editing the rules file is enough for one technical user
14On-device LLM (Gemini Nano / ML Kit)Low, redundant with Google's own Nano4+ daysCut
15Calendar matching (READ_CALENDAR)Medium1–2 daysv1.1
16SQLCipher + HMAC key rotationLow for a no-body, no-INTERNET personal app1–2 daysCut. App-private storage, no bodies, no INTERNET permission is already strong
17Work-profile / managed-device handling, multi-app ingestion~0 for this owner—Cut
18Deep-link via stored contentIntent + BAL opt-inMedium1 daySimplify: smsto: fallback only

Total kept ≈ 10–11 working days. That fits 2 weeks with slack for Samsung battery-optimization fights.


4. Would becoming the default SMS app, or using Samsung APIs, change the calculus?


5. Biggest risks the project fails, most likely first

  1. Low volume makes it pointless (most likely). Carrier and Google filters remove most junk upstream. If Byron gets ~2–5 non-spam unknown-sender texts a week, the sidecar annotates a handful of notifications, the verdict is usually "Unrecognized", and he stops looking within a month. Mitigation: the probe measures volume for 14 days before any classifier work. Proceed only if non-contact, non-short-code inbound is ≥5/week (owner can tune the threshold).
  2. Redundancy with Google. On an S26 or Pixel 10, Google's Gemini detection covers the risk side. If the sidecar never catches something Google missed, the risk ledger is dead weight. Mitigation: the metric "catches Google missed" (§6). After 60 days at zero, shrink the risk side to tripwires only.
  3. Notification-access erosion. Android 15 already redacts OTP-class notifications from untrusted listeners. If Google widens the "sensitive" class (financial or account alerts), analysis completeness drops. Google Messages could also change its MessagingStyle payload in any update. Mitigation: the probe's structure log doubles as a regression alarm. Re-run it after each Messages update.
  4. Samsung process-killing. Aggressive battery management unbinds listeners, and the sidecar silently stops. This is annoying in annotate mode and dangerous in quiet mode, which is why quiet mode is cut. Mitigation: heartbeat plus a "sidecar not running" alert.
  5. Sideloading policy. Android developer verification is global in 2027+. adb installs and the "advanced flow" remain exempt, and a hobbyist limited-distribution account covers up to 20 devices. Low risk for this owner. https://android-developers.googleblog.com/2026/03/android-developer-verification-rolling-out-to-all-developers.html
  6. Google ships the unique part. "Why flagged" explanations or an unknown-senders middle tier inside Google Messages would erase differentiators 2 and 3. The personal-context ledger is the most defensible piece.

6. Success metrics for a personal tool

Keep it to six numbers, read from the local log, reviewed at day 30 (go/no-go) and day 60:

  1. Volume gate: non-contact, non-short-code inbound per week. Below 5/week, stop or shelve.
  2. Zero harmful false alarms: count of legitimate messages labeled Likely scam. Target 0 over 30 days, and any instance is a rules bug.
  3. Legitimate-stranger lift: of the strangers Byron later marks legitimate, the % the sidecar had already rated Likely legitimate (via context ledger, short code or brand). Target ≥50%. This is the "unknown is not malicious" metric.
  4. Catches Google missed: messages rated Suspicious or worse where Google Messages showed no warning. If it is 0 after 60 days, cut the risk ledger to tripwires.
  5. Spam-folder rescues: expected-sender nudges that led to finding a real message in Spam & blocked. Any nonzero count justifies the feature.
  6. Uptime: % of Google Messages notifications the sidecar processed, from the heartbeat versus the probe count. Target ≥98%.

A soft signal: does Byron open the annotation at least weekly by week 4? If not, the tool has become furniture. Kill it, or fold the expected-sender idea into something he already looks at.

← Back to the proposal