# TrueTraceShorts — Digital Red Flags / Scam Self-Defense Strategy

Use this reference when the user asks for TrueTraceShorts / AutoShortsBot strategy, candidate generation, proof shorts, scoring, review packages, or manual upload packs after the May 2026 repositioning.

## Official positioning

TrueTraceShorts is no longer primarily an AI workflow / prompt engineering / automation channel.

Primary direction:

> Digital Red Flags / Scam Self-Defense for Normal People.

Core line:

> One screen. One red flag. One safer move.

Channel promise:

> I show you the one red flag before you click, pay, scan, or log in.

German explanation:

> Ein normaler Screen. Ein gefährlicher Hinweis. Eine sichere Handlung.

Internally content may be “boomer-safe” — simple, readable, concrete, family-shareable — but do **not** externally call it a Boomer channel. External framing is “Digital self-defense for normal people.”

## Audience

Normal smartphone/internet users, parents, teenagers, workers, small business owners, families, teams, and people who want to protect parents/partners/colleagues.

Psychological target:

> “This could have happened to me or my family.”

## Language rules

Final social videos currently remain English, but simple B1/B2 English:

- short sentences
- everyday words
- no nerd/security/corporate language
- no technical terms unless immediately translated

Use:

- “This message wants you to hurry.”
- “Don’t tap the link.”
- “Open the app yourself.”
- “Check it another way.”
- “If it makes you hurry, slow down.”

Avoid:

- “credential harvesting” → “stealing your login”
- “validate the communication channel” → “check it another way”
- “MFA prompt fatigue” → “a login prompt you did not start”
- “social engineering exploit” unless the video explains it in plain words

## Duration policy

Video length is not fixed. Choose the shortest length that still creates viewer understanding:

- **Simple red flag:** 25–35s.
- **Standard red flag:** 35–45s.
- **Explanation / recovery:** 45–60s.
- **TikTok monetization test / deeper lesson:** 61–90s.
- **Later longform guide:** 5–8min.

Priority order:

1. The viewer recognizes the scam/mechanism.
2. The viewer understands the red flag.
3. The viewer knows what to do next.
4. The video stays as short as possible, but not shorter than useful.

Default for new Proof Shorts: **35–45 seconds**. Direct ad monetization is not the main early goal; optimize first for **shares, saves, followers, and trust**.

## Default content structure

Every standard Proof Short should default to roughly 35–45s unless the topic is clearly simple or needs explanation:

1. **0–2s: Visible trap + hook** — normal screen and immediate risk.
2. **2–8s: Why it feels normal** — tiny fee, short deadline, polite buyer, official-looking UI, familiar sender.
3. **8–18s: One red flag** — pressure, changed payment route, off-platform move, login prompt not started, new number, call-now popup.
4. **18–32s: One safer move** — open the app yourself, verify another way, keep payment inside platform, deny prompt, close tab.
5. **32–40s: Screenshot checklist / memorable rule** — max 3 points, large font, share/save value.
6. **40–45s: Soft CTA only when useful** — save/share/follow reason.

Do not render if the concept cannot answer:

- What normal screen does the viewer see?
- What concrete red flag is visible?
- Is the problem clear in second 1 without audio?
- What could happen to the viewer?
- What is the one safer action?
- Can it be sent to parents/partner/colleagues/team?
- Does it have save/screenshot value?
- Is it useful without tech knowledge?

## Main content pillars

1. Text & Delivery Scams — package SMS, customs fee, toll fee, short links.
2. Login & Account Traps — fake bank/Microsoft/Google/Apple login, fake reset, account closure, login prompt not started.
3. Payment & Invoice Red Flags — fake invoice, changed payment route, vendor-bank change, CEO payment request, QR payment trap.
4. Marketplace & Buyer Scams — off-platform move, fake shipping link, fake escrow, overpayment.
5. Family & Emotion Scams — “Hi mom, new number”, emergency money request, grandparent/wrong-number scams, simple AI-voice warnings.
6. Fake Support / Popup Scams — infected-device popup, call support now, fake antivirus, browser lock, remote access request.
7. Password / Account Safety Basics — password reuse, password managers, MFA basics, recovery email risk.
8. Job / Side-Hustle Scams — fake recruiter, task scam, pay-to-get-paid, remote job deposit, crypto onboarding trap.

Deprioritize as main formats: AI workflow automation, prompt engineering, AI tool lists, abstract productivity, cyber news, hacker tactics, OSINT, VPN comparisons, dark-web explainers, or technical attack instructions.

## Official series logic

- `One Screen. One Red Flag.` — one normal screen, one dangerous detail, one safer move.
- `Send This To Your Parents` — very simple family-shareable videos, never patronizing.
- `Before You Click` — links, SMS, QR, login, popups.
- `Money Move Red Flags` — payment, invoice, QR, marketplace, bank route.
- `Account Trap` — login, password, MFA, fake reset, account closure.

## Visual rules

Default visual style is `screen/mockup-led`:

- phone screen
- SMS
- email
- invoice
- chat
- popup
- login
- QR situation
- marketplace chat
- screenshot checklist

Prefer deterministic renderer-owned mockups for scam screens because control matters: no real brands, logos, bank data, phone numbers, QR codes, domains, real people/firms, copied scam examples, or dangerous reusable templates.

Use AI images only when they add atmosphere or premium context and the actual scam UI/text is deterministic. Do not let AI freely invent fake invoices, bank pages, SMS, QR codes, or login pages when text/data matters.

## Scoring priorities

Add or prioritize these gates:

- viewer pain in first second
- screen clarity without audio
- red flag clarity
- safe move clarity
- family/share potential
- screenshot checklist value
- beginner language score
- mockup safety score
- no-fearmongering score
- pretty-empty-visual blocker

Hard-block if it looks good but shows no problem, uses high-level language, has no clear red flag, no safe next step, or could fit 50 other videos.

## Deterministic scam-screen render pattern

For SMS/delivery, popup, invoice, login, and marketplace screens, deterministic mockups are the default render source. For the concrete Delivery SMS Trap render pattern, see `references/deterministic-delivery-sms-proof-render.md`.

Key lessons:

- Critical scam-screen text should be renderer-owned and short enough for mobile mockups.
- Use reserved/safe fake text such as `example.com/hold`; avoid long fake links that clip or look live.
- If TTS word-boundary events are unavailable, regenerate active-word subtitles from a manual sentence-start fallback and QA the burned-in subtitle frames.
- Always inspect extracted hook and subtitle frames before delivery, not only contact sheets.

## Manual upload and review package pattern

For an approved final/proof short, prepare a manual upload pack with:

- final video path and SHA256
- platform copy for YouTube Shorts, TikTok, Instagram Reels
- hashtags/tags
- pinned comment suggestion
- analytics template with 1h/24h/72h/7d metrics
- explicit “No platform upload was performed.”

For new candidates, generate ReviewPackages only until explicitly approved. Do **not** render batches, styleframe batches, Wan/I2V/T2V, or platform API calls unless explicitly approved.

## Next candidate order from repositioning

After `digital-red-flags-fake-invoice-payment-route-30s`, the next initial candidates should be:

1. `delivery-sms-trap-35s`
   - Hook: “This delivery text is designed to make you panic.”
   - Takeaway: “If it makes you hurry, slow down.”
2. `fake-support-popup-call-now-30s`
   - Hook: “If a website tells you to call support, stop.”
   - Takeaway: “Real support does not hijack your screen.”
3. `marketplace-buyer-off-platform-30s`
   - Hook: “The buyer is not buying. They are moving you off-platform.”
   - Takeaway: “Keep the chat and payment inside the platform.”
4. `fake-qr-bank-login-page-35s`
   - Hook: “The QR code was not the problem. The page after it was.”
   - Takeaway: “If money or login is involved, open the app yourself.”
5. `password-reuse-domino-30s`
   - Hook: “One leaked password does not stay on one website.”
   - Takeaway: “One account, one password.”

## Implementation lesson

When updating AutoShortsBot strategy code, avoid breaking existing tests by removing old AI pillars/series abruptly. Keep legacy AI pillars/series as secondary compatibility entries while making Digital Red Flags the primary/default registry direction. Update tests to assert the new primary strategy, not to require deletion of all legacy paths.