.query_candidate_recipes() (extracted in #33) now filters candidates by category_type ('expenditure' vs 'revenue'), derived from the calling verb's own flow_prefixes (E/F/G -> 'expenditure', else 'revenue'). Without this, a category shared across both flow families in summary_categories leaked cross-family recipes: cog_revenue(category = "Corrections") surfaced the expenditure-only corrections_combined recipe (E04/E05) merely because "Corrections" is also a spending category name, and cog_spending(category = "IG Federal") surfaced the revenue-only ig_federal_b47_wide recipe. Both are wrong: following either hint would attribute dollars to the wrong flow, or (IG Federal) fire the coverage-gap machinery for a category the calling verb structurally cannot report on at all. Updates the two tests this changes the expected behavior of: - "a mis-scoped cog_spending() call never attaches an M/L counterpart to a revenue-flavored recipe" (test-expenditure-concept.R): IG Federal is revenue-only, so a spending call now finds zero candidates outright rather than firing the suggestion and then blocking its M/L counterpart as a second-order check. - "cog_revenue never suggests expenditure-only recipes" (test-recipes.R, was "I1: ... never fabricates suppressed dollars"): corrections_combined is expenditure-only, so a revenue call now never considers it as a candidate, rather than considering it and reporting zero suppressed dollars. All 1078 tests pass (2 skipped live-corpus), measured devtools::test() against this commit in a clean worktree stacked on the #33 refactor. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>