{"success":true,"data":{"id":"subject-urgency-bracket","label":"Subject starts with bracketed urgency word — `[URGENT]` / `[ALERT]` / `[ACTION REQUIRED]` marketing fingerprint","description":"The subject line starts with a bracketed urgency word — `[URGENT]`, `[ALERT]`, `[CRITICAL]`, `[WARNING]`, `[ATTENTION]`, `[IMPORTANT]`, `[ACTION REQUIRED]`, `[FINAL NOTICE]`, `[RESPOND IMMEDIATELY]`, or `[TIME SENSITIVE]`. The canonical \"scary marketing notification\" shape used by phishing kits and aggressive promo blasters. Distinct from the iter ~190 `urgency-bait:*` substring check because the bracket structure itself is attacker-shaped: real corporate \"action required\" emails use prose prefixes (\"Action required: please verify...\"), while project-tagged emails use lowercase or mixed-case tags (`[announce]`, `[PROJECT-123]`) — devs do not all-caps their project tags. The allowlist is intentionally narrow: only urgency words that have no legitimate-tag use, and the regex requires the FULL `^\\[(WORD)\\]` shape at the start so partial matches inside the subject body do not fire. Weighted at +3, pairs with other urgency / phishing signals without solo-deciding because legit ops alerts (PagerDuty, Datadog, Sentry) occasionally use this exact shape.","tier":"warning","category":"subject","isThin":false}}