{ "$defs": { "DetectedTactic": { "additionalProperties": false, "description": "One detected manipulation tactic with its verbatim evidence span.", "properties": { "tactic": { "$ref": "#/$defs/TacticId" }, "evidence": { "description": "Verbatim substring of the input message that triggered this tactic.", "minLength": 1, "title": "Evidence", "type": "string" }, "explanation": { "description": "Calm, plain-language sentence(s) a non-technical person can act on.", "minLength": 1, "title": "Explanation", "type": "string" } }, "required": [ "tactic", "evidence", "explanation" ], "title": "DetectedTactic", "type": "object" }, "SafeAction": { "description": "Fixed list of recommended safe actions.\n\nThe model must pick one of these; it can never compose free-text advice\nthat points back at the scammer's own channel. End-user wording lives in\nthe demo/report layer; these are stable machine-readable ids.", "enum": [ "call_bank_official_number", "do_not_click_link", "verify_via_official_app_or_site", "call_family_member_known_number", "do_not_share_codes_or_credentials", "do_not_send_money", "ignore_and_delete", "report_to_authorities", "check_sender_address", "no_action_needed" ], "title": "SafeAction", "type": "string" }, "TacticId": { "description": "Fixed tactic taxonomy ids (taxonomy.yaml v1).", "enum": [ "urgency_pressure", "authority_impersonation", "payment_redirect", "credential_phishing", "courier_customs_fee", "prize_lottery", "investment_too_good", "romance_advance_fee", "family_emergency_impersonation", "tech_support", "link_obfuscation", "refund_overpayment", "subscription_trap" ], "title": "TacticId", "type": "string" }, "Verdict": { "description": "Three-level verdict. Deliberately not a probability (CLAUDE.md section 2).", "enum": [ "scam_likely", "suspicious", "no_indicators" ], "title": "Verdict", "type": "string" } }, "additionalProperties": false, "description": "Complete model output for one input message.", "properties": { "verdict": { "$ref": "#/$defs/Verdict" }, "tactics": { "description": "Detected tactics; empty when verdict is no_indicators.", "items": { "$ref": "#/$defs/DetectedTactic" }, "title": "Tactics", "type": "array" }, "explanation": { "description": "Overall plain-language explanation of the verdict.", "minLength": 1, "title": "Explanation", "type": "string" }, "recommended_action": { "$ref": "#/$defs/SafeAction" } }, "required": [ "verdict", "explanation", "recommended_action" ], "title": "ScamGuardOutput", "type": "object" }