# Audit Bug Patterns in status.py Recurring issues found during the 10-bug audit (2026-06-22). ## 1. Path prefix matching without separator boundary `startswith(proj_str)` matches sibling directories (e.g. `/foo/project-evil` matches `/foo/project`). Always use `startswith(proj_str + os.sep)` with exact-match fallback. ## 2. Substring verdict parsing Using `"PASS" in content` falsely matches PASS mentioned in FAIL body text. Always use structured parsing (e.g. `## Status:` line) before substring fallback. ## 3. mtime as activity proxy `.state` file mtime reflects phase transitions, not actual edit activity. Use a separate `.state.lastedit` file touched on ALLOWED `--can-edit` responses for stale-task detection. ## 4. Artifact-to-phase mapping mismatches TEST_PLAN.md is produced during `test_design`, not `implement`. Always cross-reference artifact filenames with the workflow phase that produces them. ## 5. Untracked task enforcement Tasks without `.state` files must be refused by all operational commands. Run `--upgrade` to bootstrap them.