# Implementation: fix-can-edit-path-prefix ## Changes - **scripts/status.py** `cmd_can_edit()` (5 locations): Replaced `str(file_path).startswith(proj_str)` with `str(file_path).startswith(proj_str + os.sep) or str(file_path) == proj_str` to prevent sibling-directory bypass. Same fix applied to `auto_str` (framework directory) checks. - Line ~986: `--can-edit --project --file` scope check - Line ~1039: `--can-edit --task --file` framework case - Line ~1045: `--can-edit --task --file` regular project case - Line ~1082: `--scope-check` project check - Line ~1087: `--scope-check` framework check ## Test - `tests/test_status.py::TestCanEditPathPrefix` — 3 tests: sibling directory rejected by scope-check, subdirectory accepted by scope-check, sibling directory rejected by can-edit --task --file.