# Spec: fix-can-edit-path-prefix ## Problem `--can-edit` and `--scope-check` in `scripts/status.py` use `str(file_path).startswith(proj_str)` to verify a file is within the project directory. String `startswith` matches sibling directories: `/home/user/project-evil/file.py` matches prefix `/home/user/project`. This allows editing files outside the project boundary. Affected locations: - `scripts/status.py:951` (`--can-edit --project --file`) - `scripts/status.py:1004` (`--can-edit --task --file`, framework case) - `scripts/status.py:1010` (`--can-edit --task --file`, regular project case) - `scripts/status.py:1047` (`--scope-check`) - `scripts/status.py:1052` (`--scope-check`, framework check) ## Fix Append a trailing path separator to the prefix before comparison: ```python str(file_path).startswith(proj_str + os.sep) ``` Or use `Path.relative_to()` which correctly resolves path boundaries: ```python try: file_path.relative_to(project_dir.resolve()) except ValueError: # out of scope ``` ## Acceptance Criteria - A file in `/home/user/project-evil/` is correctly rejected as out-of-scope when project is `/home/user/project` - A file in `/home/user/project/subdir/` is correctly accepted as in-scope - Both framework and regular project cases work - Add a test in `tests/test_status.py` covering the sibling-directory edge case