Paths: File paths (shared/, references/, ../ln-*) are relative to skills repo root. If not found at CWD, locate this SKILL.md directory and go up one level for repo root.
Coverage Gaps Auditor (L3 Worker)
Specialized worker identifying missing tests for critical business logic.
Purpose & Scope
- Worker in ln-630 coordinator pipeline
- Audit Coverage Gaps (Category 4: High Priority)
- Identify untested critical paths
- Classify by category (Money, Security, Data, Core Flows)
- Calculate compliance score (X/10)
Inputs (from Coordinator)
MANDATORY READ: Load shared/references/audit_worker_core_contract.md.
Receives contextStore with: tech_stack, testFilesMetadata, codebase_root, output_dir.
Domain-aware: Supports domain_mode + current_domain (see audit_output_schema.md#domain-aware-worker-output).
Workflow
MANDATORY READ: Load shared/references/two_layer_detection.md for detection methodology.
Parse context — extract fields, determine scan_path (domain-aware if specified)
ELSE:
scan_path = codebase_root
domain_name = null
Identify critical paths in scan_path (not entire codebase)
- Scan production code in
scan_path for money/security/data keywords
- All Grep/Glob patterns use
scan_path (not codebase_root)
- Example:
Grep(pattern="payment|refund|discount", path=scan_path)
Check test coverage for each critical path (Layer 1)
- Search ALL test files for coverage (tests may be in different location than production code)
- Match by function name, module name, or test description
3b) Context Analysis (Layer 2 — MANDATORY): For each gap candidate, ask:
- Is this function already covered by E2E/integration test? → downgrade to LOW
- Is this a helper function with <10 lines called from tested code? → skip
- Is keyword match a false positive (e.g.,
paymentIcon() is UI, not payment logic)? → skip
Collect missing tests
- Tag each finding with
domain: domain_name (if domain-aware)
Calculate Score: Count violations by severity, calculate compliance score (X/10)
Write Report: Build full markdown report in memory per shared/templates/audit_worker_report_template.md, write to {output_dir}/634-coverage-gaps.md (or {output_dir}/634-coverage-gaps-{domain}.md if domain-aware) in single Write call
Return Summary: Return minimal summary to coordinator (see Output Format)
Critical Paths Classification
1. Money Flows (Priority 20+)
What: Any code handling financial transactions
Examples:
- Payment processing (
/payment, processPayment())
- Discounts/promotions (
calculateDiscount(), applyPromoCode())
- Tax calculations (
calculateTax(), getTaxRate())
- Refunds (
processRefund(), /refund)
- Invoices/billing (
generateInvoice(), createBill())
- Currency conversion (
convertCurrency())
Min Priority: 20
Why Critical: Money loss, fraud, legal compliance
2. Security Flows (Priority 20+)
What: Authentication, authorization, encryption
Examples:
- Login/logout (
/login, authenticate())
- Token refresh (
/refresh-token, refreshAccessToken())
- Password reset (
/forgot-password, resetPassword())
- Permissions/RBAC (
checkPermission(), hasRole())
- Encryption/hashing (custom crypto logic, NOT bcrypt/argon2)
- API key validation (
validateApiKey())
Min Priority: 20
Why Critical: Security breach, data leak, unauthorized access
3. Data Integrity (Priority 15+)
What: CRUD operations, transactions, validation
Examples:
- Critical CRUD (
createUser(), deleteOrder(), updateProduct())
- Database transactions (
withTransaction())
- Data validation (custom validators, NOT framework defaults)
- Data migrations (
runMigration())
- Unique constraints (
checkDuplicateEmail())
Min Priority: 15
Why Critical: Data corruption, lost data, inconsistent state
4. Core User Journeys (Priority 15+)
What: Multi-step flows critical to business
Examples:
- Registration → Email verification → Onboarding
- Search → Product details → Add to cart → Checkout
- Upload file → Process → Download result
- Submit form → Approval workflow → Notification
Min Priority: 15
Why Critical: Broken user flow = lost customers
Audit Rules
1. Identify Critical Paths
Process:
- Scan codebase for money-related keywords:
payment, refund, discount, tax, price, currency
- Scan for security keywords:
auth, login, password, token, permission, encrypt
- Scan for data keywords:
transaction, validation, migration, constraint
- Scan for user journeys: multi-step flows in routes/controllers
2. Check Test Coverage
For each critical path:
- Search test files for matching test name/description
- If NO test found → add to missing tests list
- If test found but inadequate (only positive, no edge cases) → add to gaps list
3. Categorize Gaps
Severity by Priority:
- CRITICAL: Priority 20+ (Money, Security)
- HIGH: Priority 15-19 (Data, Core Flows)
- MEDIUM: Priority 10-14 (Important but not critical)
- Downgrade when: Function already covered by E2E test → LOW. Helper with <10 lines called from tested code → skip
4. Provide Justification
For each missing test:
- Explain WHY it's critical (money loss, security breach, etc.)
- Suggest test type (E2E, Integration, Unit)
- Estimate effort (S/M/L)
Scoring Algorithm
MANDATORY READ: Load shared/references/audit_worker_core_contract.md and shared/references/audit_scoring.md.
Severity mapping by Priority:
- Priority 20+ (Money, Security) missing test → CRITICAL
- Priority 15-19 (Data Integrity, Core Flows) missing test → HIGH
- Priority 10-14 (Important) missing test → MEDIUM
- Priority <10 (Nice-to-have) → LOW
Output Format
MANDATORY READ: Load shared/references/audit_worker_core_contract.md and shared/templates/audit_worker_report_template.md.
Write report to {output_dir}/634-coverage-gaps.md (global) or {output_dir}/634-coverage-gaps-{domain}.md (domain-aware) with category: "Coverage Gaps" and checks: money_flow_coverage, security_flow_coverage, data_integrity_coverage, core_journey_coverage.
Return summary to coordinator:
Report written: docs/project/.audit/ln-630/{YYYY-MM-DD}/634-coverage-gaps.md
Score: X.X/10 | Issues: N (C:N H:N M:N L:N)
Critical Rules
MANDATORY READ: Load shared/references/audit_worker_core_contract.md.
- Domain-aware scanning: If
domain_mode="domain-aware", scan ONLY scan_path production code (not entire codebase)
- Tag findings: Include
domain field in each finding when domain-aware
- Test search scope: Search ALL test files for coverage (tests may be in different location than production code)
- Match by name: Use function name, module name, or test description to match tests to production code
Definition of Done
MANDATORY READ: Load shared/references/audit_worker_core_contract.md.
- contextStore parsed successfully (including output_dir, domain_mode, current_domain)
- scan_path determined (domain path or codebase root)
- Critical paths identified in scan_path (Money, Security, Data, Core Flows)
- Test coverage checked for each critical path
- Missing tests collected with severity, priority, justification, domain
- Score calculated using penalty algorithm
- Report written to
{output_dir}/634-coverage-gaps.md or 634-coverage-gaps-{domain}.md (atomic single Write call)
- Summary returned to coordinator
Reference Files
- Audit output schema:
shared/references/audit_output_schema.md
Version: 3.0.0
Last Updated: 2025-12-23
1---2name: ln-634-test-coverage-auditor3description: Identifies missing tests for critical paths (Money 20+, Security 20+, Data Integrity 15+, Core Flows 15+). Returns list of untested critical business logic with priority justification.4license: MIT5---67> **Paths:** File paths (`shared/`, `references/`, `../ln-*`) are relative to skills repo root. If not found at CWD, locate this SKILL.md directory and go up one level for repo root.89# Coverage Gaps Auditor (L3 Worker)1011Specialized worker identifying missing tests for critical business logic.1213## Purpose & Scope1415- **Worker in ln-630 coordinator pipeline**16- Audit **Coverage Gaps** (Category 4: High Priority)17- Identify untested critical paths18- Classify by category (Money, Security, Data, Core Flows)19- Calculate compliance score (X/10)2021## Inputs (from Coordinator)2223**MANDATORY READ:** Load `shared/references/audit_worker_core_contract.md`.2425Receives `contextStore` with: `tech_stack`, `testFilesMetadata`, `codebase_root`, `output_dir`.2627**Domain-aware:** Supports `domain_mode` + `current_domain` (see `audit_output_schema.md#domain-aware-worker-output`).2829## Workflow3031**MANDATORY READ:** Load `shared/references/two_layer_detection.md` for detection methodology.32331) **Parse context** — extract fields, determine `scan_path` (domain-aware if specified)34 ELSE:35 scan_path = codebase_root36 domain_name = null37 ```38392) **Identify critical paths in scan_path** (not entire codebase)40 - Scan production code in `scan_path` for money/security/data keywords41 - All Grep/Glob patterns use `scan_path` (not codebase_root)42 - Example: `Grep(pattern="payment|refund|discount", path=scan_path)`43443) **Check test coverage for each critical path (Layer 1)**45 - Search ALL test files for coverage (tests may be in different location than production code)46 - Match by function name, module name, or test description473b) **Context Analysis (Layer 2 — MANDATORY):** For each gap candidate, ask:48 - Is this function already covered by E2E/integration test? → **downgrade to LOW**49 - Is this a helper function with <10 lines called from tested code? → **skip**50 - Is keyword match a false positive (e.g., `paymentIcon()` is UI, not payment logic)? → **skip**51524) **Collect missing tests**53 - Tag each finding with `domain: domain_name` (if domain-aware)54555) **Calculate Score:** Count violations by severity, calculate compliance score (X/10)56576) **Write Report:** Build full markdown report in memory per `shared/templates/audit_worker_report_template.md`, write to `{output_dir}/634-coverage-gaps.md` (or `{output_dir}/634-coverage-gaps-{domain}.md` if domain-aware) in single Write call58597) **Return Summary:** Return minimal summary to coordinator (see Output Format)6061## Critical Paths Classification6263### 1. Money Flows (Priority 20+)6465**What:** Any code handling financial transactions6667**Examples:**68- Payment processing (`/payment`, `processPayment()`)69- Discounts/promotions (`calculateDiscount()`, `applyPromoCode()`)70- Tax calculations (`calculateTax()`, `getTaxRate()`)71- Refunds (`processRefund()`, `/refund`)72- Invoices/billing (`generateInvoice()`, `createBill()`)73- Currency conversion (`convertCurrency()`)7475**Min Priority:** 207677**Why Critical:** Money loss, fraud, legal compliance7879### 2. Security Flows (Priority 20+)8081**What:** Authentication, authorization, encryption8283**Examples:**84- Login/logout (`/login`, `authenticate()`)85- Token refresh (`/refresh-token`, `refreshAccessToken()`)86- Password reset (`/forgot-password`, `resetPassword()`)87- Permissions/RBAC (`checkPermission()`, `hasRole()`)88- Encryption/hashing (custom crypto logic, NOT bcrypt/argon2)89- API key validation (`validateApiKey()`)9091**Min Priority:** 209293**Why Critical:** Security breach, data leak, unauthorized access9495### 3. Data Integrity (Priority 15+)9697**What:** CRUD operations, transactions, validation9899**Examples:**100- Critical CRUD (`createUser()`, `deleteOrder()`, `updateProduct()`)101- Database transactions (`withTransaction()`)102- Data validation (custom validators, NOT framework defaults)103- Data migrations (`runMigration()`)104- Unique constraints (`checkDuplicateEmail()`)105106**Min Priority:** 15107108**Why Critical:** Data corruption, lost data, inconsistent state109110### 4. Core User Journeys (Priority 15+)111112**What:** Multi-step flows critical to business113114**Examples:**115- Registration → Email verification → Onboarding116- Search → Product details → Add to cart → Checkout117- Upload file → Process → Download result118- Submit form → Approval workflow → Notification119120**Min Priority:** 15121122**Why Critical:** Broken user flow = lost customers123124## Audit Rules125126### 1. Identify Critical Paths127128**Process:**129- Scan codebase for money-related keywords: `payment`, `refund`, `discount`, `tax`, `price`, `currency`130- Scan for security keywords: `auth`, `login`, `password`, `token`, `permission`, `encrypt`131- Scan for data keywords: `transaction`, `validation`, `migration`, `constraint`132- Scan for user journeys: multi-step flows in routes/controllers133134### 2. Check Test Coverage135136**For each critical path:**137- Search test files for matching test name/description138- If NO test found → add to missing tests list139- If test found but inadequate (only positive, no edge cases) → add to gaps list140141### 3. Categorize Gaps142143**Severity by Priority:**144- **CRITICAL:** Priority 20+ (Money, Security)145- **HIGH:** Priority 15-19 (Data, Core Flows)146- **MEDIUM:** Priority 10-14 (Important but not critical)147- **Downgrade when:** Function already covered by E2E test → LOW. Helper with <10 lines called from tested code → skip148149### 4. Provide Justification150151**For each missing test:**152- Explain WHY it's critical (money loss, security breach, etc.)153- Suggest test type (E2E, Integration, Unit)154- Estimate effort (S/M/L)155156## Scoring Algorithm157158**MANDATORY READ:** Load `shared/references/audit_worker_core_contract.md` and `shared/references/audit_scoring.md`.159160**Severity mapping by Priority:**161- Priority 20+ (Money, Security) missing test → CRITICAL162- Priority 15-19 (Data Integrity, Core Flows) missing test → HIGH163- Priority 10-14 (Important) missing test → MEDIUM164- Priority <10 (Nice-to-have) → LOW165166## Output Format167168**MANDATORY READ:** Load `shared/references/audit_worker_core_contract.md` and `shared/templates/audit_worker_report_template.md`.169170Write report to `{output_dir}/634-coverage-gaps.md` (global) or `{output_dir}/634-coverage-gaps-{domain}.md` (domain-aware) with `category: "Coverage Gaps"` and checks: money_flow_coverage, security_flow_coverage, data_integrity_coverage, core_journey_coverage.171172Return summary to coordinator:173```174Report written: docs/project/.audit/ln-630/{YYYY-MM-DD}/634-coverage-gaps.md175Score: X.X/10 | Issues: N (C:N H:N M:N L:N)176```177178## Critical Rules179180**MANDATORY READ:** Load `shared/references/audit_worker_core_contract.md`.181182- **Domain-aware scanning:** If `domain_mode="domain-aware"`, scan ONLY `scan_path` production code (not entire codebase)183- **Tag findings:** Include `domain` field in each finding when domain-aware184- **Test search scope:** Search ALL test files for coverage (tests may be in different location than production code)185- **Match by name:** Use function name, module name, or test description to match tests to production code186187## Definition of Done188189**MANDATORY READ:** Load `shared/references/audit_worker_core_contract.md`.190191- contextStore parsed successfully (including output_dir, domain_mode, current_domain)192- scan_path determined (domain path or codebase root)193- Critical paths identified in scan_path (Money, Security, Data, Core Flows)194- Test coverage checked for each critical path195- Missing tests collected with severity, priority, justification, domain196- Score calculated using penalty algorithm197- Report written to `{output_dir}/634-coverage-gaps.md` or `634-coverage-gaps-{domain}.md` (atomic single Write call)198- Summary returned to coordinator199200## Reference Files201202- **Audit output schema:** `shared/references/audit_output_schema.md`203204---205**Version:** 3.0.0206**Last Updated:** 2025-12-23