Coverage Gaps Auditor (L3 Worker)
Specialized worker identifying missing tests for critical business logic.
Purpose & Scope
- Worker in ln-630 coordinator pipeline
- Audit Coverage Gaps (Category 4: High Priority)
- Identify untested critical paths
- Classify by category (Money, Security, Data, Core Flows)
- Calculate compliance score (X/10)
Inputs (from Coordinator)
Receives contextStore with critical paths classification, codebase structure, test file list.
Domain-aware fields (NEW):
domain_mode: "domain-aware" | "global" (optional, defaults to "global")
current_domain: {name, path} when domain_mode="domain-aware"
Example contextStore (domain-aware):
{
"tech_stack": {...},
"best_practices": {...},
"testFilesMetadata": [...],
"codebase_root": "/project",
"domain_mode": "domain-aware",
"current_domain": {
"name": "orders",
"path": "src/orders"
}
}
Workflow
Parse context from contextStore
Identify critical paths in scan_path (not entire codebase)
- Scan production code in
scan_path for money/security/data keywords
- All Grep/Glob patterns use
scan_path (not codebase_root)
- Example:
Grep(pattern="payment|refund|discount", path=scan_path)
Check test coverage for each critical path
- Search ALL test files for coverage (tests may be in different location than production code)
- Match by function name, module name, or test description
Collect missing tests
- Tag each finding with
domain: domain_name (if domain-aware)
Calculate score
Return JSON with domain metadata
- Include
domain and scan_path fields (if domain-aware)
Critical Paths Classification
1. Money Flows (Priority 20+)
What: Any code handling financial transactions
Examples:
- Payment processing (
/payment, processPayment())
- Discounts/promotions (
calculateDiscount(), applyPromoCode())
- Tax calculations (
calculateTax(), getTaxRate())
- Refunds (
processRefund(), /refund)
- Invoices/billing (
generateInvoice(), createBill())
- Currency conversion (
convertCurrency())
Min Priority: 20
Why Critical: Money loss, fraud, legal compliance
2. Security Flows (Priority 20+)
What: Authentication, authorization, encryption
Examples:
- Login/logout (
/login, authenticate())
- Token refresh (
/refresh-token, refreshAccessToken())
- Password reset (
/forgot-password, resetPassword())
- Permissions/RBAC (
checkPermission(), hasRole())
- Encryption/hashing (custom crypto logic, NOT bcrypt/argon2)
- API key validation (
validateApiKey())
Min Priority: 20
Why Critical: Security breach, data leak, unauthorized access
3. Data Integrity (Priority 15+)
What: CRUD operations, transactions, validation
Examples:
- Critical CRUD (
createUser(), deleteOrder(), updateProduct())
- Database transactions (
withTransaction())
- Data validation (custom validators, NOT framework defaults)
- Data migrations (
runMigration())
- Unique constraints (
checkDuplicateEmail())
Min Priority: 15
Why Critical: Data corruption, lost data, inconsistent state
4. Core User Journeys (Priority 15+)
What: Multi-step flows critical to business
Examples:
- Registration → Email verification → Onboarding
- Search → Product details → Add to cart → Checkout
- Upload file → Process → Download result
- Submit form → Approval workflow → Notification
Min Priority: 15
Why Critical: Broken user flow = lost customers
Audit Rules
1. Identify Critical Paths
Process:
- Scan codebase for money-related keywords:
payment, refund, discount, tax, price, currency
- Scan for security keywords:
auth, login, password, token, permission, encrypt
- Scan for data keywords:
transaction, validation, migration, constraint
- Scan for user journeys: multi-step flows in routes/controllers
2. Check Test Coverage
For each critical path:
- Search test files for matching test name/description
- If NO test found → add to missing tests list
- If test found but inadequate (only positive, no edge cases) → add to gaps list
3. Categorize Gaps
Severity by Priority:
- CRITICAL: Priority 20+ (Money, Security)
- HIGH: Priority 15-19 (Data, Core Flows)
- MEDIUM: Priority 10-14 (Important but not critical)
4. Provide Justification
For each missing test:
- Explain WHY it's critical (money loss, security breach, etc.)
- Suggest test type (E2E, Integration, Unit)
- Estimate effort (S/M/L)
Scoring Algorithm
critical_paths = count of critical paths
tested_paths = count of critical paths with tests
coverage_percentage = (tested_paths / critical_paths) * 100
score = coverage_percentage / 10 // 100% coverage = 10 score
score = max(0, min(10, score))
Output Format
Global mode output:
{
"category": "Coverage Gaps",
"score": 6,
"critical_paths_total": 25,
"tested_paths": 15,
"untested_paths": 10,
"coverage_percentage": 60,
"findings": [
{
"severity": "CRITICAL",
"category": "Money",
"missing_test": "E2E: Payment with discount code",
"location": "services/payment.ts:processPayment()",
"priority": 25,
"justification": "Money calculation with discount logic — high risk of incorrect total",
"test_type": "E2E",
"effort": "M"
}
]
}
Domain-aware mode output (NEW):
{
"category": "Coverage Gaps",
"score": 7,
"domain": "orders",
"scan_path": "src/orders",
"critical_paths_total": 12,
"tested_paths": 8,
"untested_paths": 4,
"coverage_percentage": 67,
"findings": [
{
"severity": "CRITICAL",
"category": "Money",
"missing_test": "E2E: applyDiscount() with edge cases",
"location": "src/orders/services/order.ts:45",
"priority": 25,
"justification": "Discount calculation in orders domain — high risk of incorrect total",
"test_type": "E2E",
"effort": "M",
"domain": "orders"
},
{
"severity": "HIGH",
"category": "Data Integrity",
"missing_test": "Integration: orderTransaction() rollback",
"location": "src/orders/repositories/order.ts:78",
"priority": 18,
"justification": "Data corruption risk in orders domain",
"test_type": "Integration",
"effort": "M",
"domain": "orders"
}
]
}
Critical Rules
- Domain-aware scanning: If
domain_mode="domain-aware", scan ONLY scan_path production code (not entire codebase)
- Tag findings: Include
domain field in each finding when domain-aware
- Test search scope: Search ALL test files for coverage (tests may be in different location than production code)
- Match by name: Use function name, module name, or test description to match tests to production code
Definition of Done
- contextStore parsed (including domain_mode and current_domain)
- scan_path determined (domain path or codebase root)
- Critical paths identified in scan_path (Money, Security, Data, Core Flows)
- Test coverage checked for each critical path
- Missing tests collected with severity, priority, justification, domain
- Score calculated
- JSON returned to coordinator with domain metadata
Version: 3.0.0
Last Updated: 2025-12-23
1---2name: ln-634-test-coverage-auditor3description: Coverage Gaps audit worker (L3). Identifies missing tests for critical paths (Money 20+, Security 20+, Data Integrity 15+, Core Flows 15+). Returns list of untested critical business logic with priority justification.4---56# Coverage Gaps Auditor (L3 Worker)78Specialized worker identifying missing tests for critical business logic.910## Purpose & Scope1112- **Worker in ln-630 coordinator pipeline**13- Audit **Coverage Gaps** (Category 4: High Priority)14- Identify untested critical paths15- Classify by category (Money, Security, Data, Core Flows)16- Calculate compliance score (X/10)1718## Inputs (from Coordinator)1920Receives `contextStore` with critical paths classification, codebase structure, test file list.2122**Domain-aware fields (NEW):**23- `domain_mode`: `"domain-aware"` | `"global"` (optional, defaults to "global")24- `current_domain`: `{name, path}` when domain_mode="domain-aware"2526**Example contextStore (domain-aware):**27```json28{29 "tech_stack": {...},30 "best_practices": {...},31 "testFilesMetadata": [...],32 "codebase_root": "/project",33 "domain_mode": "domain-aware",34 "current_domain": {35 "name": "orders",36 "path": "src/orders"37 }38}39```4041## Workflow42431) **Parse context from contextStore**44 - Extract tech_stack, best_practices, testFilesMetadata45 - **Determine scan_path (NEW):**46 ```47 IF domain_mode == "domain-aware":48 scan_path = codebase_root + "/" + current_domain.path49 domain_name = current_domain.name50 ELSE:51 scan_path = codebase_root52 domain_name = null53 ```54552) **Identify critical paths in scan_path** (not entire codebase)56 - Scan production code in `scan_path` for money/security/data keywords57 - All Grep/Glob patterns use `scan_path` (not codebase_root)58 - Example: `Grep(pattern="payment|refund|discount", path=scan_path)`59603) **Check test coverage for each critical path**61 - Search ALL test files for coverage (tests may be in different location than production code)62 - Match by function name, module name, or test description63644) **Collect missing tests**65 - Tag each finding with `domain: domain_name` (if domain-aware)66675) **Calculate score**68696) **Return JSON with domain metadata**70 - Include `domain` and `scan_path` fields (if domain-aware)7172## Critical Paths Classification7374### 1. Money Flows (Priority 20+)7576**What:** Any code handling financial transactions7778**Examples:**79- Payment processing (`/payment`, `processPayment()`)80- Discounts/promotions (`calculateDiscount()`, `applyPromoCode()`)81- Tax calculations (`calculateTax()`, `getTaxRate()`)82- Refunds (`processRefund()`, `/refund`)83- Invoices/billing (`generateInvoice()`, `createBill()`)84- Currency conversion (`convertCurrency()`)8586**Min Priority:** 208788**Why Critical:** Money loss, fraud, legal compliance8990### 2. Security Flows (Priority 20+)9192**What:** Authentication, authorization, encryption9394**Examples:**95- Login/logout (`/login`, `authenticate()`)96- Token refresh (`/refresh-token`, `refreshAccessToken()`)97- Password reset (`/forgot-password`, `resetPassword()`)98- Permissions/RBAC (`checkPermission()`, `hasRole()`)99- Encryption/hashing (custom crypto logic, NOT bcrypt/argon2)100- API key validation (`validateApiKey()`)101102**Min Priority:** 20103104**Why Critical:** Security breach, data leak, unauthorized access105106### 3. Data Integrity (Priority 15+)107108**What:** CRUD operations, transactions, validation109110**Examples:**111- Critical CRUD (`createUser()`, `deleteOrder()`, `updateProduct()`)112- Database transactions (`withTransaction()`)113- Data validation (custom validators, NOT framework defaults)114- Data migrations (`runMigration()`)115- Unique constraints (`checkDuplicateEmail()`)116117**Min Priority:** 15118119**Why Critical:** Data corruption, lost data, inconsistent state120121### 4. Core User Journeys (Priority 15+)122123**What:** Multi-step flows critical to business124125**Examples:**126- Registration → Email verification → Onboarding127- Search → Product details → Add to cart → Checkout128- Upload file → Process → Download result129- Submit form → Approval workflow → Notification130131**Min Priority:** 15132133**Why Critical:** Broken user flow = lost customers134135## Audit Rules136137### 1. Identify Critical Paths138139**Process:**140- Scan codebase for money-related keywords: `payment`, `refund`, `discount`, `tax`, `price`, `currency`141- Scan for security keywords: `auth`, `login`, `password`, `token`, `permission`, `encrypt`142- Scan for data keywords: `transaction`, `validation`, `migration`, `constraint`143- Scan for user journeys: multi-step flows in routes/controllers144145### 2. Check Test Coverage146147**For each critical path:**148- Search test files for matching test name/description149- If NO test found → add to missing tests list150- If test found but inadequate (only positive, no edge cases) → add to gaps list151152### 3. Categorize Gaps153154**Severity by Priority:**155- **CRITICAL:** Priority 20+ (Money, Security)156- **HIGH:** Priority 15-19 (Data, Core Flows)157- **MEDIUM:** Priority 10-14 (Important but not critical)158159### 4. Provide Justification160161**For each missing test:**162- Explain WHY it's critical (money loss, security breach, etc.)163- Suggest test type (E2E, Integration, Unit)164- Estimate effort (S/M/L)165166## Scoring Algorithm167168```169critical_paths = count of critical paths170tested_paths = count of critical paths with tests171coverage_percentage = (tested_paths / critical_paths) * 100172score = coverage_percentage / 10 // 100% coverage = 10 score173score = max(0, min(10, score))174```175176## Output Format177178**Global mode output:**179```json180{181 "category": "Coverage Gaps",182 "score": 6,183 "critical_paths_total": 25,184 "tested_paths": 15,185 "untested_paths": 10,186 "coverage_percentage": 60,187 "findings": [188 {189 "severity": "CRITICAL",190 "category": "Money",191 "missing_test": "E2E: Payment with discount code",192 "location": "services/payment.ts:processPayment()",193 "priority": 25,194 "justification": "Money calculation with discount logic — high risk of incorrect total",195 "test_type": "E2E",196 "effort": "M"197 }198 ]199}200```201202**Domain-aware mode output (NEW):**203```json204{205 "category": "Coverage Gaps",206 "score": 7,207 "domain": "orders",208 "scan_path": "src/orders",209 "critical_paths_total": 12,210 "tested_paths": 8,211 "untested_paths": 4,212 "coverage_percentage": 67,213 "findings": [214 {215 "severity": "CRITICAL",216 "category": "Money",217 "missing_test": "E2E: applyDiscount() with edge cases",218 "location": "src/orders/services/order.ts:45",219 "priority": 25,220 "justification": "Discount calculation in orders domain — high risk of incorrect total",221 "test_type": "E2E",222 "effort": "M",223 "domain": "orders"224 },225 {226 "severity": "HIGH",227 "category": "Data Integrity",228 "missing_test": "Integration: orderTransaction() rollback",229 "location": "src/orders/repositories/order.ts:78",230 "priority": 18,231 "justification": "Data corruption risk in orders domain",232 "test_type": "Integration",233 "effort": "M",234 "domain": "orders"235 }236 ]237}238```239240## Critical Rules241242- **Domain-aware scanning:** If `domain_mode="domain-aware"`, scan ONLY `scan_path` production code (not entire codebase)243- **Tag findings:** Include `domain` field in each finding when domain-aware244- **Test search scope:** Search ALL test files for coverage (tests may be in different location than production code)245- **Match by name:** Use function name, module name, or test description to match tests to production code246247## Definition of Done248249- contextStore parsed (including domain_mode and current_domain)250- scan_path determined (domain path or codebase root)251- Critical paths identified in scan_path (Money, Security, Data, Core Flows)252- Test coverage checked for each critical path253- Missing tests collected with severity, priority, justification, domain254- Score calculated255- JSON returned to coordinator with domain metadata256257---258**Version:** 3.0.0259**Last Updated:** 2025-12-23