VerifyBeforePay is a working ForgeHacks prototype for the AI and Cybersecurity track. It is for someone facing a message that asks for money, a password, or a one-time code. The goal is not to declare the sender genuine. It is to make the request easier to inspect, then direct the user to a contact obtained independently. This edited walkthrough uses fictional messages and synthetic narration. Here is the built-in fictional example. The message claims to come from a bank and asks for a one-time code. The expected domain is bank dot example, supplied separately. The pasted link includes that familiar-looking name, but also an at sign. We press Examine message. The app does not open the link, send a payment, access an account, or contact the organization. The analysis keeps sender identity unverified. A small learned model returns an elevated old SMS spam signal, with a score of zero point nine eight nine for this example. That number is not a probability of fraud. Separate checks identify the actual words urgent and OTP. They show observed language, not a conclusion about the sender or the meaning of the whole message. The actual link host is fraud dot example. The bank-looking text before the at sign is user information, not the host. The app shows both that structure and the mismatch with the independently supplied domain. It then gives three actions: pause payment or disclosure, use a separately obtained contact or official app, and confirm the request through that channel before acting. Now we replace the message with a fictional request to meet after class. Its spam signal is not elevated. Sender identity still remains unverified, and the same limits and independent verification steps remain visible. No listed wording cues is not a safety certificate. The model can miss new scams and unsupported languages. Even a matching domain or HTTPS cannot prove who sent a message. Clear removes the message, expected domain, and displayed result from the interface. It is not a secure memory wipe. The browser version downloads static app files, a fixed model, and a self-hosted Python runtime. The original Python analysis then runs in browser memory. Message text is not uploaded to an inference service. The app uses no analytics or message storage, and never learns from pasted messages. The public repository explains the model and its limits. One frozen, duplicate-grouped evaluation used one thousand and twenty-three older English SMS test groups. Spam F one was zero point nine four eight, compared with zero point five six six for a fixed keyword baseline. These are not modern fraud results. Thirty-four synthetic software checks also matched native Python with the browser runtime. No model was retuned. Source, a browser demo, and this video are available without an account. The intended benefit is a clearer pause and independent check; actual user outcomes have not been measured.