{"success":true,"data":{"id":"csrf-form-in-email","label":"External form with auto-submit targeting third-party domain (CSRF)","description":"Email HTML contains a <form> with an action pointing to an external domain AND has auto-submit indicators (onload, document.forms, submit(), autosubmit, or hidden inputs). The form action domain differs from the sender domain. This compound signal detects CSRF attacks where opening the email triggers actions on third-party sites using the victim's session cookies. Requires 2+ conditions: external form action, auto-submit indicators, sender domain mismatch.","tier":"danger","category":"other","isThin":false}}