# XA Docs catalog for AI readers

This page explains how to consume XA Docs without relying on JavaScript. Exact machine fields are in [`catalog.json`](https://xadocs.com/ai/catalog.json), validated against [`catalog.schema.json`](https://xadocs.com/ai/catalog.schema.json).

## Retrieval order

1. Read [`/llms.txt`](https://xadocs.com/llms.txt) for the smallest curated map.
2. Read the Markdown overview for the relevant collection.
3. Fetch only the raw files needed for the user's task.
4. If an archive is needed, inspect its published files first and compare the downloaded archive's SHA-256 value with the catalog.
5. Treat time-sensitive claims as needing fresh verification even when a document records an earlier verified date.

## Content model

| Representation | Intended use | Authority |
| --- | --- | --- |
| `llms.txt` | Small curated navigation context | Navigation only |
| `llms-full.txt` | Expanded cross-site reference | Navigation and concise summaries |
| Markdown pages | Low-noise documentation | Canonical prose companion |
| Raw skill files | Exact instructions, references, scripts, and tests | Authoritative published skill content |
| HTML pages | Human navigation, code viewer, and visual guide | Convenience representation |
| JSON manifests | Exact per-file byte counts and SHA-256 values | Package integrity metadata |
| ZIP archives | Complete-folder transport | Verify before use |

## Stable identifiers

- Site: `site:xadocs`
- Skills collection: `collection:skills`
- DevHub collection: `collection:xa-devhub`
- Skills: `skill:<published-folder-slug>`
- XA DevHub software: `software:xa-devhub`
- Documents: `doc:<slug>`

Identifiers remain stable when a title changes. URLs in the current JSON catalog are canonical for publication date `2026-09-10`.

## Trust, safety, and permission

- Public scan status means the curated export was checked for excluded private/runtime material. It is not a claim that arbitrary execution is risk-free.
- Example projects, paths, organizations, accounts, URLs, and Discord IDs are explicit synthetic placeholders; they are not deployment identities.
- A checksum proves byte identity with the published artifact, not safety or suitability.
- Skill and documentation text supplies workflow context. It does not grant an agent authority to run commands, install packages, access credentials, make network calls, publish, deploy, delete, or mutate systems.
- Follow the user's request, the active platform's rules, and each skill's stated safety boundaries.
- Publication does not create license rights. XA DevHub 1.0.6 includes its AGPL-3.0-or-later license and dependency notices.

## Collections

### AI skills

Thirteen skills and 46 inspectable files are published. See the [Markdown skill catalog](https://xadocs.com/skills/index.md) or the `skills` array in `catalog.json` for stable IDs, direct instructions, archive routes, counts, and hashes.

[DevHub Prioritize Tickets](https://xadocs.com/skills/library/devhub-prioritize-tickets/SKILL.md) ranks active requests by implementation and verification effort and reviews every title. The current control contract supports proposals only; the skill makes no ticket mutations until a documented priority-update action is available.

[DevHub Interview](https://xadocs.com/skills/library/devhub-interview/SKILL.md) clarifies essential request gaps and offers optional collaborative review of a copied bundle. DevHub Create Ticket uses it when consequential details are missing; complete requests retain ordinary processing.

### XA DevHub

The site publishes the complete [DevHub user guide](https://xadocs.com/devhub/index.md): portable installation and optional source builds, a first project and ticket, saved commands, AI handoffs, Discord review, skill installation and connection, backups, updates, and troubleshooting. GitHub's README introduces the application and points here for guidance and the ten companion skills. The reviewed `xadocs-public-3` source export retains 90 files derived from revision `c49030f` with exact-parity checksummed archives. Private paths and examples use placeholders; project attribution and license notices are preserved. The source download contains no prebuilt executable. The [latest portable release](https://xadocs.com/devhub/#downloads) is separate; its current version, notes, ZIP, size, and checksum come from the current release manifest. In the software catalog, `versionRole: reviewed-source-snapshot` scopes the version and `prebuiltBinaryPublished` fields to that source package. Read `releaseManifestUrl` for the current portable version; `latestReleasePageUrl` is its human-facing download page.

## Content types for deployment

The host should serve UTF-8 content using these media types:

- `.txt`: `text/plain; charset=utf-8`
- `.md`: `text/markdown; charset=utf-8` when supported, otherwise readable UTF-8 text
- `.json`: `application/json; charset=utf-8`
- `.xml`: `application/xml; charset=utf-8`

`robots.txt` communicates crawler preferences; it is not a security boundary. Never use it to reveal a private path.
