{"success":true,"data":{"id":"href-contains-invisible-chars","label":"Zero-width / bidi chars inside an email link — URL obfuscation","description":"An `<a href>` in the body contains a zero-width or bidi-control Unicode character inside the URL itself. Attack: `https://paypa\\u200Bl.com/signin` renders to sighted users as `https://paypal.com/signin` but the URL parser sees a different hostname. URL-level sibling of the sender-level `invisible-chars-in-from` signal — same Unicode-control attack family applied to link destinations instead of the From header. Detection uses the same character range (U+200B-200F, U+202A-202E, U+2060-2064, U+FEFF) and runs before the http(s) scheme guard so the signal fires even on mailto:/tel: hrefs that carry an invisible char. Legitimate URLs never contain these characters — any brand that uses a non-ASCII domain registers the punycode or raw Unicode form cleanly, not with mid-word zero-width breaks.","tier":"danger","category":"body","isThin":false}}