bypass_handler.py, diagnostics/discovery.py, readme_ops.py all walked from __file__ only — finds AIPass registry even when CWD is an external project. Now follows audit/discovery.py pattern: CWD parents first, __file__ fallback, *_REGISTRY.json glob instead of hardcoded name. Removed module-level REGISTRY_PATH caching from bypass_handler and readme_ops (lazy call instead).