{
  "id": "MSG-101",
  "slug": "msg-101",
  "title": "Links must not be intended to deceive or cause harm",
  "statement": "Embedded links must not be designed to mislead the recipient or deliver harm.",
  "rationale": "Phishing and malware delivery are Severity-0 findings carrying \"cease all messaging\", and the audit scope explicitly includes the landing page and any downloaded artifact — not just the SMS body. This is judged on intent and presentation, not on the URL string.",
  "layer": "MESSAGE_CONTENT",
  "layerSlug": "message-content",
  "object": "campaign.sample[] + link destinations",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "HARD_STOP",
  "authorities": [
    "CTIA",
    "T-Mobile",
    "Twilio",
    "TCR"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Remove any link whose presentation misrepresents where it leads or what it does. Link text and destination must match.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/message-content/msg-101/",
  "markdown": "https://ekas.io/rules/10dlc/message-content/msg-101.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
