{"success":true,"data":{"id":"body-claims-attachment-but-none","label":"Body mentions an attachment but the email has none — phishing primer for the next link click","description":"The email body contains a phrase indicating an attachment is expected — \"see attached\", \"find attached\", \"please find attached\", \"ver adjunto\", \"ci-joint\", \"im anhang\", \"in allegato\", \"em anexo\", \"se bifogad\", and similar across 7 languages — but the actual attachments array is empty. Classic phishing primer: the misleading prose tells the user to expect a file, then the next link in the body (which the user clicks expecting it to be the attachment download) goes to a credential-harvest landing page. Real businesses either attach the file or use direct prose (\"your invoice is below\"); the explicit \"see attached\" disconnect is essentially diagnostic of the prime-then-redirect attack pattern. Weighted at +3 — not solo-decisive because some legitimate newsletters reference attachments inline before linking to a real product page, but pairs strongly with `body-minimal-text-with-link` (iter 452) and `href-text-domain-mismatch` (iter 223) when both fire.","tier":"warning","category":"body","isThin":false}}