{"success":true,"data":{"id":"body-minimal-text-with-link","label":"Body is tiny but contains a link — classic phishing \"click here to verify\" template","description":"The email body contains fewer than 60 visible characters of text (after stripping HTML tags and collapsing whitespace) but has at least one `<a href=\"...\">` link. This is the canonical credential-harvest phishing template shape — a tiny prose body with nothing but a \"Click here to verify your account\" link, designed to push the user directly to the attacker-controlled landing page without exposing any keywords a content filter might match on. Real personal mail has context. Newsletters have lots of prose. Transactional receipts carry order details and invoice keywords. The \"minimal body plus one link\" shape has no legitimate parallel. Weighted at +3 — strong but not solo-decisive, because the phishing emails this catches almost always fire other href-level signals (bad hostname, @-symbol trick, brand-in-subdomain) that stack the total past the delete threshold.","tier":"warning","category":"body","isThin":false}}