{"id":"8b90fe4b-408f-4328-ae66-7f8b99762fd6","entityType":"agent","slug":"clawhub-amd5-xz01-dev-skill","name":"Xz01 Dev Skill","canonicalUrl":"https://www.xpersona.co/agent/clawhub-amd5-xz01-dev-skill","canonicalPath":"/agent/clawhub-amd5-xz01-dev-skill","generatedAt":"2026-10-10T11:50:21.549Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:34:08.898Z","emptyReason":null},"description":"Use when 用户提到“xz01规范”时必须命中本技能；xz01规范=xz01-dev-skill。用于 Hermes + Claude Code 围绕用户现有 OpenClaw/xz01 模板资料进行角色编排、开发学习范围、测试/规范分工，并严格将 /root/.openclaw 作为只读学习资料库；编码修...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s1751ams93yq7ebhk4m0rj58f583gjdd:xz01-dev-skill","sourceUrl":"https://clawhub.ai/amd5/xz01-dev-skill","homepage":"https://clawhub.ai/amd5/skills/xz01-dev-skill","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/amd5/xz01-dev-skill","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/amd5/skills/xz01-dev-skill","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Xz01 Dev Skill technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:34:08.898Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:34:08.898Z","emptyReason":null},"stars":null,"forks":null,"downloads":1523,"packageName":null,"latestVersion":"1.0.44","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:34:08.898Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T09:34:08.898Z","lastCrawledAt":"2026-10-10T09:34:08.898Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T09:34:08.898Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.44","createdAt":"2026-05-18T10:32:04.176Z","changelog":"Add data-volume-aware pagination validation: empty page_code is a failure only for multi-page non-rank routes; one-page routes must not get custom fallback pagers.","fileCount":53,"zipByteSize":104850},{"version":"1.0.43","createdAt":"2026-05-18T09:15:01.895Z","changelog":"Add pagination common_data chain rule: validate list template include -> getPcPageData/getMobilePageData -> page_code -> rendered pager; empty pagination ul is a data-chain failure.","fileCount":50,"zipByteSize":100763},{"version":"1.0.41","createdAt":"2026-05-18T08:40:53.642Z","changelog":"Correct pagination rule: forbid custom fallback pager algorithms and require xz01_demo page_code pagination chain.","fileCount":48,"zipByteSize":97196},{"version":"1.0.40","createdAt":"2026-05-18T07:04:33.299Z","changelog":"Clarified and enforced pagination scope: all non-ranking dual-end list routes/templates, including /zoszx/ and image/video/package/kaifu/all-news/search lists, use PC numeric pages and mobile previous/next controls.","fileCount":47,"zipByteSize":94615},{"version":"1.0.39","createdAt":"2026-05-18T06:37:36.785Z","changelog":"Added hard xz01 resource rendering rule: app/game/application items must render with icons/thumbnails/covers in cards, icon grids, or image-text lists; no no-icon title-only horizontal rows. Also synchronized skill metadata.","fileCount":45,"zipByteSize":89406},{"version":"1.0.36","createdAt":"2026-05-18T06:08:27.145Z","changelog":"Added hard dual-end list pagination rule for multi-page list routes: PC numeric page links and mobile previous/next controls matching xz01_demo; synchronized metadata versions.","fileCount":43,"zipByteSize":85778},{"version":"1.0.34","createdAt":"2026-05-18T04:41:48.263Z","changelog":"Require all active detail templates to be covered and PC sidebars to mix app/software, game, and news/guide modules instead of only攻略","fileCount":41,"zipByteSize":82569},{"version":"1.0.33","createdAt":"2026-05-18T04:18:07.014Z","changelog":"Added mandatory full-page PC/mobile screenshot acceptance with segmented/contact-sheet AI review; first-viewport screenshots are supplemental only and cannot justify xz01 visual PASS.","fileCount":39,"zipByteSize":78473}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s1751ams93yq7ebhk4m0rj58f583gjdd:xz01-dev-skill","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s1751ams93yq7ebhk4m0rj58f583gjdd:xz01-dev-skill` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/amd5/xz01-dev-skill before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T11:50:21.545Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-amd5-xz01-dev-skill/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:34:08.898Z","emptyReason":null},"readme":"Skill: Xz01 Dev Skill\n\nOwner: amd5\n\nSummary: Use when 用户提到“xz01规范”时必须命中本技能；xz01规范=xz01-dev-skill。用于 Hermes + Claude Code 围绕用户现有 OpenClaw/xz01 模板资料进行角色编排、开发学习范围、测试/规范分工，并严格将 /root/.openclaw 作为只读学习资料库；编码修...\n\nTags: latest:1.0.44\n\nVersion history:\n\nv1.0.44 | 2026-05-18T10:32:04.176Z | user\n\nAdd data-volume-aware pagination validation: empty page_code is a failure only for multi-page non-rank routes; one-page routes must not get custom fallback pagers.\n\nv1.0.43 | 2026-05-18T09:15:01.895Z | user\n\nAdd pagination common_data chain rule: validate list template include -> getPcPageData/getMobilePageData -> page_code -> rendered pager; empty pagination ul is a data-chain failure.\n\nv1.0.41 | 2026-05-18T08:40:53.642Z | user\n\nCorrect pagination rule: forbid custom fallback pager algorithms and require xz01_demo page_code pagination chain.\n\nv1.0.40 | 2026-05-18T07:04:33.299Z | user\n\nClarified and enforced pagination scope: all non-ranking dual-end list routes/templates, including /zoszx/ and image/video/package/kaifu/all-news/search lists, use PC numeric pages and mobile previous/next controls.\n\nv1.0.39 | 2026-05-18T06:37:36.785Z | user\n\nAdded hard xz01 resource rendering rule: app/game/application items must render with icons/thumbnails/covers in cards, icon grids, or image-text lists; no no-icon title-only horizontal rows. Also synchronized skill metadata.\n\nv1.0.36 | 2026-05-18T06:08:27.145Z | user\n\nAdded hard dual-end list pagination rule for multi-page list routes: PC numeric page links and mobile previous/next controls matching xz01_demo; synchronized metadata versions.\n\nv1.0.34 | 2026-05-18T04:41:48.263Z | user\n\nRequire all active detail templates to be covered and PC sidebars to mix app/software, game, and news/guide modules instead of only攻略\n\nv1.0.33 | 2026-05-18T04:18:07.014Z | user\n\nAdded mandatory full-page PC/mobile screenshot acceptance with segmented/contact-sheet AI review; first-viewport screenshots are supplemental only and cannot justify xz01 visual PASS.\n\nv1.0.32 | 2026-05-18T04:15:19.490Z | user\n\nAdd strict no-temporary-artifacts-under-/root/.openclaw boundary and correct xz01 artifact locations\n\nv1.0.29 | 2026-05-18T03:40:22.483Z | user\n\nAdded strict dual-end navigation rule: every xz01 template set must check and repair PC plus m/mobile top nav together using existing menu data.\n\nv1.0.27 | 2026-05-18T03:27:57.494Z | user\n\nAdded PC top-navigation dynamic menu rule: render header nav from existing menu data instead of guessed labels/links.\n\nv1.0.26 | 2026-05-18T03:07:16.039Z | user\n\n纠正 xz01 双端搜索规则：搜索框样式可渲染，但默认必须禁用功能；无 /search 链接/action、无可用输入/提交、无 JS submit 绑定；同步 SKILL.md、skill.json、_meta.json。\n\nv1.0.25 | 2026-05-18T02:15:12.090Z | user\n\n吸收 Karpathy 精准修改/目标驱动原则；新增 xz01 专用 hook-style gate 脚本与门禁规则；明确不启用安全扫描和并行化\n\nv1.0.24 | 2026-05-18T01:19:01.114Z | user\n\n明确 xz01 栏目显示名称以数据库 cmf_cms_channel.name 为准，PC 与移动端同 alias 必须一致显示 DB name，如 gzos 显示 手游下载\n\nv1.0.22 | 2026-05-16T11:28:35.355Z | user\n\n补充核心页面 Chromium 截图脚本并纳入 xz01 验证流程，配合静态扫描、URL 全量扫描和 AI 视觉复检\n\nv1.0.21 | 2026-05-16T11:24:46.288Z | user\n\n加入 demo_xz01 系统学习规范、双端列表/详情/分页/资源加载硬规则，并内置静态模板扫描与 PC+移动 URL 全量扫描验证脚本\n\nv1.0.20 | 2026-05-16T10:34:04.497Z | user\n\nAdd stability-first serial execution rule for xz01: no concurrent dev/test/rule lanes; use a single queue unless the user explicitly re-enables concurrency\n\nv1.0.19 | 2026-05-16T10:23:58.744Z | user\n\nAdd Claude interactive/tmux guidance for xz01: use tmux only as a supervised workbench for batches of small tasks, while keeping max-turns unchanged and avoiding monolithic long runs\n\nv1.0.18 | 2026-05-16T10:17:06.644Z | user\n\nAdd xz01 execution-time rules: do not raise max-turns; split tasks to minimum units; use fixed validation scripts; keep no-re-exploration rule disabled for now; time-box long dev/test runs\n\nv1.0.16 | 2026-05-16T09:05:47.251Z | user\n\nAdd permanent xz01 rule: template development must never modify PHP/controllers/models/config/backend files; restore scope limited to theme templates/assets only\n\nv1.0.15 | 2026-05-16T08:51:29.662Z | user\n\nClarify xz01 packaging gates: list/detail pages must be generated or available and rendered, not assumed; jQuery must be loaded in head/header output\n\nv1.0.14 | 2026-05-16T07:36:05.529Z | user\n\nAdd hard xz01 packaging gates: clear runtime after every dev change before validation; require homepage/list/detail rendering, jQuery, trailing slashes, real data images, no erroneous page links, and dynamic data before packaging\n\nv1.0.13 | 2026-05-16T06:43:33.081Z | user\n\nAdd mobile back-to-top QA rule: verify visibility, non-overlap, and click-to-top behavior with real mobile UA and 390px screenshot\n\nv1.0.9 | 2026-05-16T04:28:45.397Z | user\n\nRecord xz01 main role boundary correction: coding and HTML/CSS/template repairs must be delegated to Claude Code dev; main only dispatches and reports\n\nv1.0.8 | 2026-05-16T04:17:08.610Z | user\n\nAdd PC right-sidebar/week-topic repair guidance: fill sidebar and balance left hero content to avoid blank disconnects\n\nv1.0.7 | 2026-05-16T04:07:26.087Z | user\n\nFix mobile validation guidance: avoid fixed 390px container causing blank right strip on wider phones; require 390/430 mobile UA checks\n\nv1.0.5 | 2026-05-16T03:50:10.890Z | user\n\nAdd mandatory mobile User-Agent validation for m.900az.com xz01 mobile checks\n\nv1.0.4 | 2026-05-16T03:07:57.689Z | user\n\n更新 xz01 汇报格式：废弃旧 10 列表格，改为 Hermes 原生简洁执行报告；补充 WebUI 媒体路径规则，/www 截图需复制到 /root/.hermes/workspace 后用 MEDIA 引用\n\nv1.0.1 | 2026-05-16T02:34:21.394Z | user\n\n补充 Hermes 原生调度边界：OpenClaw sessions_send/flow-controller 仅作为只读参考，Hermes 流程改用 delegate_task、kanban、cronjob、显式 Hermes/Claude worker 与工厂 SQLite 队列\n\nArchive index:\n\nArchive v1.0.44: 53 files, 104850 bytes\n\nFiles: _meta.json (134b), references/demo-xz01-may-2026-source-update.md (4193b), references/hermes-native-xz01-first-run.md (3667b), references/hermes-native-xz01-live-deploy-validation.md (4425b), references/lanhu-mcp-discovery-notes.md (1141b), references/lanhu-mcp-installation.md (3378b), references/run-0002-visual-repair.md (8209b), references/session-2026-05-16-allpage-visual-qa-and-scanner-fixes.md (2144b), references/session-2026-05-16-db-channel-name-display-standard.md (1326b), references/session-2026-05-16-demo-xz01-systematic-validation.md (4045b), references/session-2026-05-16-main-role-boundary-correction.md (1623b), references/session-2026-05-16-max-turns-task-splitting-validation-scripts.md (3379b), references/session-2026-05-16-no-php-controller-template-dev.md (1649b), references/session-2026-05-16-packaging-gate-runtime-list-detail.md (2420b), references/session-2026-05-16-pc-gap-dev-test-rule-loop.md (3447b), references/session-2026-05-16-right-sidebar-height-balance.md (1890b), references/session-2026-05-16-theme-only-data-links-search.md (3070b), references/session-2026-05-18-all-detail-mixed-sidebar.md (4243b), references/session-2026-05-18-detail-sidebar-bottom-modules.md (4266b), references/session-2026-05-18-dual-end-list-pagination.md (2256b), references/session-2026-05-18-dual-end-nav-dynamic-menu.md (4056b), references/session-2026-05-18-fullpage-visual-qa-correction.md (2085b), references/session-2026-05-18-hermes-native-no-search-regression.md (2998b), references/session-2026-05-18-hermes-native-title-search-repair.md (3432b), references/session-2026-05-18-home-resource-iconized-cards.md (2857b), references/session-2026-05-18-karpathy-ecc-hook-adaptation.md (1935b), references/session-2026-05-18-mobile-domain-validation-correction.md (2743b), references/session-2026-05-18-mobile-layout-overflow-repair.md (3297b), references/session-2026-05-18-openclaw-temp-artifact-boundary.md (1884b), references/session-2026-05-18-pagination-common-data-chain.md (2535b), references/session-2026-05-18-pagination-data-volume-validation.md (1558b), references/session-2026-05-18-pagination-demo-copy-correction.md (2110b), references/session-2026-05-18-pagination-rule-template-repair.md (2222b), references/session-2026-05-18-pc-mobile-search-visual-repair.md (2715b), references/session-2026-05-18-pc-nav-dynamic-menu.md (2082b), references/session-2026-05-18-pc-nav-scope-validation.md (1127b), references/session-2026-05-18-rendered-pc-pagination-fallback.md (3148b), references/session-2026-05-18-skill-library-active-review.md (1132b), references/session-2026-05-18-skill-metadata-sync-audit.md (1103b), references/session-2026-05-18-timeout-recovery-partial-work.md (1876b), references/session-2026-05-18-xz01-skill-autopublish.md (1528b), references/xz01-template-factory-architecture.md (7152b), scripts/xz01-backend-baseline-check.sh (403b), scripts/xz01-full-url-scan.py (4200b), scripts/xz01-hook-gate.py (6560b), scripts/xz01-quick-http-gate.py (2405b), scripts/xz01-runtime-clear.sh (447b), scripts/xz01-screenshot-core.sh (1444b), scripts/xz01-template-static-scan.py (3677b), scripts/xz01-theme-diff-check.sh (621b), skill-card.md (3328b), skill.json (988b), SKILL.md (72535b)\n\nFile v1.0.44:SKILL.md\n\n---\nname: xz01-dev-skill\ndescription: Use when 用户提到“xz01规范”时必须命中本技能；xz01规范=xz01-dev-skill。用于 Hermes + Claude Code 围绕用户现有 OpenClaw/xz01 模板资料进行角色编排、开发学习范围、测试/规范分工，并严格将 /root/.openclaw 作为只读学习资料库；编码修复交给 Claude dev，测试输出写入 /www/wwwroot/www.900az.com，彻底验证通过的模板按编号压缩到 /root/.hermes/workspace/xz01/；吸收 Karpathy 精准修改/目标驱动原则，并提供 xz01 专用 hook-style gate；包含 PC 与 m 移动端顶部导航必须成对按菜单数据渲染、多页列表必须按 xz01_demo 做双端翻页、所有详情页必须覆盖且右侧/底部必须混合游戏+应用+资讯/攻略模块、app/游戏/应用资源项必须图标化展示、视觉验收必须整页截图+分段AI检查的规则。\nversion: 1.0.44\nauthor: Hermes Agent\nlicense: MIT\nmetadata:\n  hermes:\n    tags: [xz01-dev-skill, xz01规范, xz01, openclaw, hermes, claude-code, role-orchestration, read-only, template-workflow, 角色分工, 学习范围, 只读, 测试输出, 模板打包, 验证通过]\n    related_skills: [hermes-agent, claude-code, systematic-debugging, test-driven-development]\n---\n\n# xz01-dev-skill\n\n## Trigger Alias / 命中别名\n\n```text\nxz01规范 = xz01-dev-skill\n```\n\n当用户提到以下中文触发词时，必须优先加载并遵循本技能：\n\n- xz01规范\n- xz01 规范\n- xz01开发规范\n- xz01学习范围\n- xz01角色分工\n- Hermes+Claude xz01\n- OpenClaw xz01\n- 谁是 dev / 谁是 test\n- /root/.openclaw 只读\n- 测试输出写到 /www/wwwroot/www.900az.com\n- 验证通过模板打包到 /root/.hermes/workspace/xz01/\n- 安装或接入 Lanhu MCP / 蓝湖 MCP\n- PC/m 导航栏同步处理\n- 双端顶部导航\n- 移动端导航也要同步\n- 导航栏按菜单数据渲染\n- 整页截图验收\n- full-page screenshot\n- 资源项图标化展示\n- app/game resource cards\n\n## References\n\n- `references/session-2026-05-18-home-resource-iconized-cards.md` — durable homepage/resource-module correction: app/game/application resources must be iconized cards, icon grids, image-text lists, or icon ranking rows; no no-icon title-only horizontal rows for software/game/app resources. News/guide text lists are exempt when clearly article modules.\n- `references/session-2026-05-18-karpathy-ecc-hook-adaptation.md` — user-approved adaptation notes: absorb Karpathy precise/goal-driven dev principles and xz01-specific hook gates; exclude generic security scanning and parallelization for now.\n- `references/session-2026-05-18-skill-library-active-review.md` — skill-maintenance lesson: xz01 user corrections phrased as “这是规范” must be actively promoted into the class-level skill and references, not left only in chat or memory.\n- `references/session-2026-05-18-all-detail-mixed-sidebar.md` — user correction that “详情页” means every active PC/mobile detail template, including collection/topic detail when present; PC right sidebars must not be only攻略 and must mix app/software, game, and news/guide modules with real data. Also covers the operational pattern that if a long dev worker times out after making file changes, do not assume failure or success: first inspect modified timestamps/content, then continue with smaller verification/fix tasks.\n- `references/session-2026-05-18-dual-end-list-pagination.md` — hard pagination rule: every dual-end list page except ranking/rank-list pages must render pagination like `xz01_demo` when data exceeds one page; PC uses numeric page links, mobile uses `上一页` / `下一页` controls. The scope is route/database-list based, not limited to files named `list_soft/list_game/list_news/list_collection`; examples include `/zoszx/`, image/video/package/kaifu/all-news list templates, and search-result list templates when present.\n- `references/session-2026-05-18-rendered-pc-pagination-fallback.md` — correction after a bad pagination repair: do **not** invent a custom fallback pager or page-count algorithm. xz01 list pagination must follow `xz01_demo`'s `getPcPageData` / `getMobilePageData` → `$page_code` → `{$page_code|raw}` pattern; if rendered pagination is absent, fix the data/template chain to match demo rather than designing a new pager.\n- `references/session-2026-05-18-pagination-demo-copy-correction.md` — session-specific correction: when user says “造搬/照搬 xz01_demo”, treat it as an implementation-shape constraint, not just a visual/functional goal; revert self-designed pagination code and update the skill/spec immediately.\n- `references/session-2026-05-18-pagination-common-data-chain.md` — pagination root-cause correction: `{$page_code|raw}` in the bottom template is not enough; the list template must include the matching `common_data/_list_*_common.html`, and that file must call `getPcPageData` / `getMobilePageData` so `$page_code` is actually generated.\n- `references/session-2026-05-18-pagination-data-volume-validation.md` — pagination validation correction: empty rendered `<ul class=\"pagination\"></ul>` is a failure only when the route has more than one page of eligible data; when a non-rank list currently has one page or insufficient data, demo helpers may leave `$page_code` empty and the validator must report it as data-volume-limited rather than asking dev to invent fallback links.\n- `references/session-2026-05-18-skill-metadata-sync-audit.md` — publishing-process correction: before `clawhub publish`, audit that `SKILL.md`, `skill.json`, and `_meta.json` all share the same version and that descriptions/changelog match the actual change.\n- `references/session-2026-05-18-pagination-rule-template-repair.md` — workflow correction after the user pointed out that only the rule was updated: when a new xz01 rule identifies an active template defect, update the skill/spec and immediately apply the rule to affected deployed/candidate templates, then clear runtime and verify.\n- `references/session-2026-05-18-timeout-recovery-partial-work.md` — timeout recovery pattern for xz01 delegate workers: inspect authorized workdirs and partial artifacts after timeout, continue from useful landed work with smaller tasks, and never mark timeout as PASS without independent validation.\n- `references/session-2026-05-18-fullpage-visual-qa-correction.md` — user correction after a first-viewport-only PASS missed lower-page layout details: xz01 visual QA must use PC/mobile full-page screenshots, segment/contact-sheet long pages, and inspect lower modules/footer before PASS.\n- `references/session-2026-05-18-mobile-domain-validation-correction.md` — mobile QA correction: do not validate mobile by applying a 390px/mobile UA to `www.900az.com`; use the real `m.900az.com` URL plus mobile UA/CDP metrics, and parameterize validation scripts by URL per case.\n- `references/session-2026-05-18-openclaw-temp-artifact-boundary.md` — boundary correction after a validation worker created a temporary screenshot script under `/root/.openclaw/workspace`: no temporary scripts, screenshots, reports, manifests, logs, or generated artifacts may be written anywhere under `/root/.openclaw`; use `/tmp`, `/www/wwwroot/www.900az.com/test-artifacts`, or `/root/.hermes/workspace/xz01-artifacts` instead.\n- `references/session-2026-05-18-detail-sidebar-bottom-modules.md` — detail-page repair pattern: every active app/game/news/collection detail template must include demo-like right sidebar and bottom data modules using real existing data; validate with source/static checks plus screenshots/AI, require mixed app/software + game + news/guide modules, and watch for PC bottom summary text overflow.\n- `references/session-2026-05-18-dual-end-nav-dynamic-menu.md` — user correction and hard rule: PC and m/mobile top navigation are a paired requirement for every xz01 template set; both must render from existing menu/navigation data, never guessed hardcoded labels or invented links.\n- `references/session-2026-05-18-mobile-layout-overflow-repair.md` — mobile visual QA/repair pattern: use CDP mobile device emulation plus runtime overflow probes for final validation; fix nav as an internal scroller, two-column modules as shrink-safe grids, and list rows with `min-width:0`/ellipsis.\n- `references/session-2026-05-18-pc-nav-dynamic-menu.md` — PC top-navigation repair lesson: render the header nav from existing menu/navigation data (`get_nav_menu` / `$vo.name` / `$vo.href` or equivalent), never from guessed labels or invented links.\n- `references/session-2026-05-18-pc-nav-scope-validation.md` — validation-scope lesson: when fixing PC top navigation, parse the actual nav container and do not conflate similar labels in lower shortcut/keyword modules with the header nav.\n- `references/session-2026-05-18-hermes-native-title-search-repair.md` — direct Hermes xz01 live-site repair lesson: do not call OpenClaw runtime orchestration when the user addresses Hermes; use Hermes-native dev/test delegation, demo read-only reference, shared-head dynamic title repair, theme-only search template fixes, and multi-keyword title validation.\n- `references/session-2026-05-18-hermes-native-no-search-regression.md` — user correction and repair pattern for xz01 live-site regressions when Hermes is addressed directly: do not invoke OpenClaw sessions/flow-controller; use Hermes-native verification/delegation; dual-end search boxes should keep visual styling when shown but must be non-functional by default: no `/search` action/link, no enabled input/submit, and no JS submit binding.\n- `references/session-2026-05-18-xz01-skill-autopublish.md` — user correction that xz01 skill edits are incomplete until version metadata is synchronized and `clawhub publish` is executed without asking for confirmation.\n- `references/session-2026-05-18-pc-mobile-search-visual-repair.md` — live-site search visual repair lesson: PC search must be right/side-aligned and visually weakened rather than top-center; mobile search must be an obvious compact magnifier-style visual-only entry, not merely the absence of a large input; verify 390px mobile card overflow after search/header changes.\n- `references/lanhu-mcp-installation.md` — recommended Docker Compose + HTTP MCP setup for `dsphper/lanhu-mcp`, including Hermes native MCP and Claude Code connection examples.\n- `references/demo-xz01-may-2026-source-update.md` — read-only learning notes from the May 2026 `demo_xz01` source update, including the user-confirmed rule that front-end PC/mobile search is canceled/weakened and should not be a default QA failure.\n- `references/xz01-template-factory-architecture.md` — architecture notes for upgrading the current main/dev/test/rule loop into a 60-template dual-end xz01 automation factory with corpus ingestion, DB/route learning, planning, rendering, validation, repair loops, rule review, and packaging.\n- `references/hermes-native-xz01-first-run.md` — first-run pattern for building a safe Hermes-native xz01 prototype under `/root/.hermes/workspace/xz01-factory`, including minimal output shape, static validation checklist, and prototype-vs-production boundary.\n- `references/hermes-native-xz01-live-deploy-validation.md` — live temporary deployment pattern for `/www/wwwroot/www.900az.com/public/themes/default/`, including backup, cache clearing, HTTP/PHP/static/browser/AI validation, fallback data blocks, trace-overlay hiding, and screenshot artifact paths.\n- `references/run-0002-visual-repair.md` — session-specific repair notes for making a temporary xz01 homepage more demo-like after AI visual review: PC density/card-count fixes, topic-background cleanup, desktop-vs-mobile-UA validation, true 390px mobile screenshots, right-side alignment/overflow probes, long mobile screenshots for lower modules, and viewport clipping remedies.\n- `references/session-2026-05-16-main-role-boundary-correction.md` — user correction that xz01 coding/HTML/CSS/template fixes must be delegated to Claude Code dev even when the fix is small or obvious; main must not directly patch implementation files.\n- `references/session-2026-05-16-pc-gap-dev-test-rule-loop.md` — concrete example of handling a small PC quick-topic spacing defect through Claude dev → independent test screenshot/AI review → rule audit, including constrained dev prompt shape and test acceptance criteria.\n- `references/session-2026-05-16-right-sidebar-height-balance.md` — follow-up lesson from repeated PC gap corrections: if a lower section is pushed down by a taller right sidebar, reduce right-side content height (e.g. `专题推荐` 4→3) instead of only compressing margins.\n- `references/session-2026-05-16-packaging-gate-runtime-list-detail.md` — user correction after an invalid package: every dev change must clear `/www/wwwroot/www.900az.com/runtime/` before validation, and packaging is forbidden until homepage/list/detail rendering, jQuery, trailing-slash links, data images, and dynamic data gates all pass.\n- `references/session-2026-05-16-no-php-controller-template-dev.md` — user correction that xz01 template development must never modify PHP/backend/controller/model/config files; dev scope is theme templates/assets only unless the user explicitly authorizes a non-template backend task.\n- `references/session-2026-05-16-theme-only-data-links-search.md` — theme-only repair notes after backend restoration: restore data with existing template tags, make slash-ending column links absolute with the correct PC/mobile host, avoid double-prefix domains, keep PC search out of the top center, fix missing detail templates in the theme, and keep test artifacts out of `/root/.openclaw`.\n- `references/session-2026-05-16-max-turns-task-splitting-validation-scripts.md` — user correction for repeated `max_turns` and long-running tasks: do not raise max-turns, split work to minimum units, use fixed validation scripts, do not enable the no-re-exploration rule for now, time-box dev/test tasks, use Claude interactive/tmux only as a supervised workbench for a sequence of small tasks, and prioritize stability with a single serial queue unless the user explicitly re-enables concurrency.\n- `references/session-2026-05-16-demo-xz01-systematic-validation.md` — user correction that `demo_xz01` must be learned systematically: dual-end list/detail templates must exist and render, pagination variables/data rendering must follow demo patterns, runtime cache must be cleared after every dev change, PC+mobile static/HTTP/browser/screenshot/AI gates are mandatory before packaging, and the validation scripts are part of this skill.\n- `references/session-2026-05-16-allpage-visual-qa-and-scanner-fixes.md` — follow-up validation lesson: when the user asks for all-page dual-end screenshots and AI review, capture every crawled URL, create URL→screenshot manifests and contact sheets for AI review, retry screenshot timeouts, and avoid false `0款` scanner matches such as `10款`. Treat DB-backed labels like “手游下载” as wording observations rather than automatic failures when the route and data are valid.\n- `references/session-2026-05-16-db-channel-name-display-standard.md` — user correction that xz01 PC/mobile category/list display names must use `cmf_cms_channel.name` from the database row for the current alias; e.g. alias `gzos` must display `手游下载` because the DB channel name is `手游下载`.\n\n## Overview\n\nThis skill is for operating a Hermes + Claude Code workflow around the user's existing OpenClaw/xz01 material. The existing OpenClaw tree is a **read-only learning corpus**, not a place to write configs, skills, memory, cron state, sessions, templates, or generated reports unless the user explicitly authorizes a specific write.\n\nAuthoritative read-only boundary:\n\n```text\n/root/.openclaw/ and every subdirectory = read-only learning material\n```\n\nDefault runtime division:\n\n```text\nHermes current session = main / dispatcher / final reporter\nClaude Code = dev / implementation worker\nHermes independent test role = test / validation worker\nHermes independent rule role = rule / process and standard reviewer\n```\n\nRecent correction status:\n\n```text\nDual-end top navigation is mandatory for every xz01 template set: PC and m/mobile nav must be checked and fixed together, using existing menu/navigation data on both ends.\nFor any dual-end list page where the data volume is greater than one page, pagination is mandatory: PC uses numeric page links; mobile uses 上一页/下一页, matching xz01_demo.\nWhen a new xz01 rule describes a current live/candidate template defect, the response must not stop at updating the skill/spec; apply the rule to the affected templates immediately, then clear runtime and verify.\n```\n\nSkill-maintenance lesson from this session:\n\n```text\nWhen the user states a new xz01 rule as “这是规范”, treat it as a durable skill update immediately: add/patch the class-level SKILL.md, create or update a concise references/session-*.md detail file if useful, synchronize skill.json/_meta.json versions, and publish the updated skill. Do not leave the rule only in chat or memory.\n```\n\n## When to Use\n\nUse this skill when the user asks about:\n\n- “xz01规范”\n- “xz01 规范”\n- “xz01-dev-skill”\n- “Hermes 和 Claude 怎么分工”\n- “谁是 dev，谁是 test”\n- “OpenClaw 的学习范围”\n- “/root/.openclaw 只读”\n- “把这个流程做成 skill”\n- “持续优化技能”\n- Hermes + Claude role division for OpenClaw/xz01-style work\n- what each role should learn from `/root/.openclaw`\n- turning OpenClaw process rules into Hermes skills\n- coordinating template development, validation, and rule review without modifying OpenClaw's existing files\n- preserving dev/test/rule separation while using Claude Code for implementation\n\nDo **not** use this skill to modify `/root/.openclaw` files. Treat them as reference-only.\n\n## Non-Negotiable Boundary\n\nAll roles must obey:\n\n```text\nDo not write to /root/.openclaw/\nDo not create temporary scripts under /root/.openclaw/\nDo not create screenshots, reports, manifests, logs, lock files, downloads, or generated artifacts under /root/.openclaw/\nDo not patch /root/.openclaw/\nDo not update /root/.openclaw/openclaw.json\nDo not modify /root/.openclaw/workspace/*\nDo not modify /root/.openclaw/agents/*\nDo not modify /root/.openclaw/cron/*\nDo not modify /root/.openclaw/memory/*\nDo not modify /root/.openclaw/flows/*\nDo not modify /root/.openclaw/workspace/demo_xz01\n```\n\nAllowed operations on `/root/.openclaw`:\n\n- read targeted files\n- inventory directories\n- summarize rules\n- learn conventions\n- compare reports against known standards\n\nTemplate-development backend boundary:\n\n```text\nFor xz01 template development, NEVER modify PHP/backend/controller/model/config files.\nForbidden paths include: application/**/*.php, config/**/*.php, route/**/*.php, thinkphp/**/*.php, vendor/**/*.php, and any controller/model/service/backend PHP file.\nAllowed template scope by default: public/themes/<theme>/** only (HTML templates, CSS, JS, theme assets).\nIf required data/routes are unavailable through existing backend/template tags, report the limitation; do not patch PHP to make a template pass.\nAny package created after PHP/controller/config changes is invalid until those backend changes are reverted and the template is revalidated with theme-only changes.\n```\n\nIf writes are required, write only to:\n\n- Hermes skill storage (`~/.hermes/skills/...`) when creating/updating Hermes skills\n- a user-authorized non-OpenClaw project directory\n- `/www/wwwroot/www.900az.com` for all test-side outputs, validation artifacts, screenshots, reports, and website verification outputs unless the user explicitly changes it\n- `/root/.hermes/workspace/xz01/` for numbered zip packages of templates that have fully passed verification\n- `/tmp/...` for short-lived helper scripts and scratch files; never put temporary helpers under `/root/.openclaw`\n- another explicit path the user names\n\nPackaging rule for verified templates:\n\n```text\nOnly templates that are thoroughly verified as passed may be packed.\nPackage verified templates as numbered compressed archives under /root/.hermes/workspace/xz01/.\nDo not store final verified template packages under /root/.openclaw/.\n\nHard packaging gate:\n\n- After every add/modify/delete development change, delete all directories/items under `/www/wwwroot/www.900az.com/runtime/` before validation.\n- Do not package until PC/mobile homepage, software/game/news/category list pages and detail pages are generated/available and render correctly from existing database routes; list/detail pages must not be merely referenced or assumed. Any dual-end list page with more than one page of data must include pagination: PC numeric page links and mobile `上一页` / `下一页`, matching `xz01_demo`.\n- Do not package if rendered pages contain missing header/head jQuery loading, no-slash column URLs, malformed duplicate-host absolute URLs, `cms/page/index/id` / `cms/Page/index` / `mobile/Page/index` errors, prohibited filler SVG data images, mostly `暂无...数据` placeholders, or zero real content/detail links while DB records exist.\n- For every rendered column/category URL whose path ends with `/`, output an absolute URL with protocol and the correct host: PC uses `https://www.900az.com/.../`, mobile uses `https://m.900az.com/.../`. Normalize helper output first so an already-absolute URL is not prefixed again.\n- PC header/search layout gate: the PC search box must never be placed at the top center of the header. Use a right-side, below-header, or otherwise non-center placement. Mobile is evaluated separately.\n- Dual-end top-navigation gate: for every xz01 template set, PC and m/mobile top navigation must be checked/fixed together and rendered from existing menu/navigation data. A header-navigation task is incomplete if either side still uses guessed hardcoded labels or invented links.\n```\n\n## Role Map\n\n| Role | Default assignee | Purpose | May write `/root/.openclaw`? |\n|---|---|---|---:|\n| main | Hermes current session | receive requests, split work, dispatch, supervise, final report | No |\n| dev | Claude Code | implement code/template changes in authorized workdir | No |\n| test | independent Hermes test role/session | screenshots, AI visual analysis, lint/HTML/CSS/template validation | No |\n| rule | independent Hermes rule role/session | process audit, rule review, skill/spec suggestions | No |\n\n## Main Role Learning Scope\n\nMain learns coordination and boundaries, not implementation.\n\nRead-only sources:\n\n- `/root/.openclaw/workspace/IRON_RULES.md`\n- `/root/.openclaw/workspace/AGENTS.md`\n- `/root/.openclaw/workspace/MEMORY.md`\n- `/root/.openclaw/workspace/error.md`\n- `/root/.openclaw/workspace/DREAMS.md`\n- `/root/.openclaw/workspace/scripts/flow-controller.js`\n- `/root/.openclaw/workspace/scripts/check-flow-stuck.js`\n- `/root/.openclaw/workspace/scripts/violation-tracker.js`\n- `/root/.openclaw/openclaw.json`\n- `/root/.openclaw/cron/jobs.json`\n- `/root/.openclaw/agents/*/sessions` only when targeted history/debug context is needed\n- `/root/.openclaw/memory/*.sqlite` only when targeted memory inspection is explicitly needed\n\nMain must learn:\n\n1. role boundaries\n2. flow sequence: main → dev → test → rule → main\n3. when to dispatch to each role\n4. how to avoid dev/test/rule collapse\n5. report format expectations\n6. historical violations and user corrections\n7. that `/root/.openclaw` is read-only\n\nMain must not:\n\n- write code\n- test/screenshot\n- modify CSS/templates\n- modify PHP/backend/controller/model/config files for template development\n- update OpenClaw configs\n- silently skip test or rule\n\n## Dev Role Learning Scope\n\nDev is Claude Code by default. Dev learns implementation standards and writes only in an authorized non-OpenClaw workdir.\n\nRead-only sources:\n\n- `/root/.openclaw/workspace/IRON_RULES.md`\n- `/root/.openclaw/workspace/AGENTS.md`\n- `/root/.openclaw/workspace/TEMPLATE-SPEC.md`\n- `/root/.openclaw/workspace-dev/MEMORY.md`\n- `/root/.openclaw/workspace-dev/skills`\n- `/root/.openclaw/workspace-dev/memory`\n- `/root/.openclaw/workspace/demo_xz01`\n- `/root/.openclaw/workspace/memory/team/project` targeted template-development notes\n\nDev must learn:\n\n1. ThinkPHP template structure\n2. PC/mobile dual-template structure\n3. common module organization\n4. HTML/CSS/JS conventions\n5. template tag closure rules (`include`, `foreach`, `if`)\n6. data filters such as `is_hide=0` and `status=1`\n7. search/navigation/carousel/data rendering conventions, with updated `demo_xz01` nuance and user correction: front-end PC/mobile search should render the search-box visual style when the template design includes that header/search area, but must not render functional search behavior by default. Use disabled/non-submitting visual-only controls: no `/search` link/action, no enabled input, no submit, no JS submit binding. Do not require a working dual-end search feature unless the user explicitly requests functional search. For visual placement, PC search must not sit in the page/header center; keep it right-aligned, side-aligned, below-header, or otherwise clearly non-center and visually weakened. Mobile search must be a compact magnifier/icon-style entry when shown; removing the large input is not enough if no small search entry is visible.\n8. Dual-end top-navigation rendering rule (mandatory for every xz01 template set): PC and m/mobile header/top navigation are a paired requirement and must be checked/fixed together. Both ends must come from existing menu/navigation data such as PC `get_nav_menu(1,0,['list_order'=>'asc'],0,333)` and mobile `get_nav_menu(1,0,['list_order'=>'asc'],0,3333)` with `$vo.name` and `$vo.href` (or an equivalent existing menu source); mobile hrefs must use the mobile host, e.g. by replacing `www.` with `m.` when the helper returns PC URLs. Do not hardcode guessed labels like “热门排行/装机必备/专题合集” or mobile shorthand labels like “软件/排行/必备/资讯” unless they are the exact menu data output; do not invent hrefs just because they open. Preserve each active template's outer nav classes while keeping labels/links data-driven.\n9. route rule: database routes are authoritative; do not invent routes from template filenames\n10. database channel display rule: category/list page labels, headings, breadcrumbs, and related front-end display names must use `cmf_cms_channel.name` for the current database alias on both PC and mobile. The alias/path (e.g. `gzos`) is not the display label; if the DB row has `name='手游下载'`, PC `/gzos/` and mobile `m.900az.com/gzos/` must display `手游下载` consistently. Do not normalize to guessed labels unless explicitly requested.\n11. demo_xz01 is a pattern library, not editable and not copy-paste source\n12. updated template-structure nuance: some newer templates remove `zyxz_module` entirely or inline sidebar/recommendation blocks instead of using fixed `_side_*.html` partials; preserve the specific template's structure instead of forcing old module inventories\n13. demo_xz01 systematic rendering and pagination rules: every xz01 template must implement complete PC+mobile homepage/list/detail coverage for existing DB routes. Except for ranking/rank-list pages, every dual-end database-backed list page whose data volume exceeds one page must render pagination like `xz01_demo`: PC uses numeric page links/page-code style pagination; mobile uses simple `上一页` / `下一页` controls. Scope is based on actual database routes and rendered list pages, not only files named `list_soft/list_game/list_news/list_collection`; include software/game/news/category, collection/topic, image, video, package/gift, kaifu, all-news, and search-result list templates when present. The implementation must copy/align with demo's full pagination chain: the list template includes the matching `common_data/_list_*_common.html`, that common data file calls `getPcPageData` / `getMobilePageData` for the main list, those helpers generate `$page_code`, and templates output `{$page_code|raw}` or an explicitly confirmed demo-equivalent partial. Do not modify PHP/controllers/routes to fake pagination, do not rely on `getAllData()` for the main paginated list, and do not invent custom page-count/request-parameter/fallback pager algorithms in the theme.\n14. app/game/application resource-card rule: every app/game/application resource item on homepage, list pages, sidebars, recommendation modules, latest-resource modules, ranking modules, and detail-page related-resource modules must render with an icon/thumbnail/cover plus title and metadata/action in a card, icon grid, or image-text list. It is forbidden to display app/game/application resources as text-only horizontal title rows inside a module. Article/news/guide text lists may remain text-only, but software/game/app resources may not.\n15. resource loading rules: do not use `/themes/default/common_cms/common/jquery.min.js`; load jQuery from the correct PC/mobile asset path. Include UIkit and Swiper only when needed, using the correct PC/mobile asset CSS+JS pair.\n\nDev must not:\n\n- read Feishu group messages\n- self-certify final acceptance\n- skip test\n- write `/root/.openclaw`\n- modify `demo_xz01`\n- modify PHP/backend/controller/model/config files for template development (`application/**/*.php`, `config/**/*.php`, routes, ThinkPHP core, vendor, backend services). Template tasks are limited to `public/themes/<theme>/**` unless the user explicitly authorizes a non-template backend task.\n- perform official screenshot/AI visual validation\n\nDev output should include:\n\n- changed file list in authorized workdir\n- implementation summary\n- self-check notes\n- items for test to validate\n\n## Test Role Learning Scope\n\nTest is an independent Hermes role/session. It validates; it does not fix.\n\nRead-only sources:\n\n- `/root/.openclaw/workspace/IRON_RULES.md`\n- `/root/.openclaw/workspace/AGENTS.md`\n- `/root/.openclaw/workspace/TEMPLATE-SPEC.md`\n- `/root/.openclaw/workspace-test/MEMORY.md`\n- `/root/.openclaw/workspace-test/skills`\n- `/root/.openclaw/workspace-test/scripts`\n- `/root/.openclaw/workspace-test/skills/template-qa/scripts`\n- `/root/.openclaw/workspace/demo_xz01`\n- `/root/.openclaw/workspace/memory/team/project` targeted testing/screenshot/AI-vision notes\n\nTest must learn:\n\n1. PC screenshot requirements\n2. mobile screenshot requirements\n3. AI visual analysis requirement after screenshots\n4. layout/overlap/missing-element/color/font/responsive checks\n5. HTML tag closure checks\n6. CSS path/layout checks\n7. ThinkPHP template tag checks\n8. search/navigation/carousel/data rendering checks, with updated `demo_xz01` nuance and user correction: a PC/mobile search-box visual shell may be present when required by the template design, but it must be visual-only unless the user explicitly requests functional search. Fail search if it has `/search` links/actions, enabled keyword input, enabled submit buttons, form submission, JS submit binding, or any clickable/searchable behavior; do not fail merely because a disabled visual search box is displayed\n9. dual-end list pagination checks: for representative software/app, game, news/guide, category/channel, and equivalent database-backed list routes where data volume exceeds one page, PC must show numeric page links and mobile must show `上一页` / `下一页`; absence of pagination on a multi-page list is a FAIL even when the first page data renders correctly. Static template evidence is only a pre-check: test must verify the full `xz01_demo` pagination chain, not just the bottom output tag: list template includes matching `common_data/_list_*_common.html`, common data calls `getPcPageData` / `getMobilePageData` for the main list, helpers generate `$page_code`, and the template outputs `{$page_code|raw}`. If rendered HTML shows an empty `<ul class=\"pagination\"></ul>`, first determine whether the route has more than one page of eligible data. For multi-page data, fail it as a missing upstream data-chain issue; for one-page/insufficient data, record it as expected demo behavior and do not ask dev to add a self-designed fallback pager.\n10. app/game/application resource rendering checks: inspect homepage/list/detail/side/recommend/latest/rank modules and fail any app/game/application resource displayed as a text-only horizontal title row without icon/thumbnail/cover. News/article/guide text lists are exempt only when they are clearly not app/game/application resources.\n11. regression testing; do not only check the last fix\n12. full issue report format\n13. full-page screenshot acceptance rule: for homepage/page visual QA, PC and mobile screenshots must capture the whole page, not only the first viewport. First-viewport screenshots may be used only as supplemental evidence. A visual PASS is forbidden unless the full page has been captured, split/contact-sheeted when long, submitted to AI visual review, and lower modules/footer/detail areas have been checked for layout, spacing, overflow, clipping, and missing/overlapping elements.\n\nTest must not:\n\n- write implementation code\n- fix issues directly\n- read Feishu group messages\n- write `/root/.openclaw`\n- claim visual correctness without full-page screenshots + AI visual analysis for homepage/page visual QA\n\nTest output should include:\n\n- PC full-page screenshot paths under `/www/wwwroot/www.900az.com` or mirrored under `/root/.hermes/workspace/...` for WebUI media\n- mobile full-page screenshot paths under `/www/wwwroot/www.900az.com` or mirrored under `/root/.hermes/workspace/...` for WebUI media\n- long-page segment/contact-sheet paths when a full-page screenshot is too tall for reliable visual review\n- AI visual analysis findings saved/reported from the test output area\n- structural/lint findings\n- functional findings\n- pass/fail conclusion\n- issue list for dev when failed\n\nAll test-side artifacts must be written under `/www/wwwroot/www.900az.com` unless the user explicitly changes the output location.\n\n## Rule Role Learning Scope\n\nRule is an independent Hermes role/session. It audits workflow and proposes/maintains durable rules. Under the read-only boundary, it must not update OpenClaw files unless explicitly authorized.\n\nRead-only sources:\n\n- `/root/.openclaw/workspace/IRON_RULES.md`\n- `/root/.openclaw/workspace/AGENTS.md`\n- `/root/.openclaw/workspace/TEMPLATE-SPEC.md`\n- `/root/.openclaw/workspace-rule/MEMORY.md`\n- `/root/.openclaw/workspace-rule/skills`\n- `/root/.openclaw/workspace-rule/memory`\n- `/root/.openclaw/workspace/skills`\n- `/root/.openclaw/workspace/memory/team/project`\n- `/root/.openclaw/workspace/memory/violations`\n- `/root/.openclaw/workspace/error.md`\n\nRule must learn:\n\n1. role-boundary violations to prevent\n2. process-completion requirements\n3. when a lesson should become a skill\n4. when a lesson should remain a report, not memory/skill\n5. skill metadata/version/documentation conventions\n6. cron-log noise restrictions\n7. user-specific hard rules\n\nRule must not:\n\n- implement code\n- test/screenshot\n- write `/root/.openclaw`\n- publish OpenClaw skills or edit OpenClaw specs without explicit authorization\n\nRule output should include:\n\n- compliance audit\n- whether the flow skipped steps\n- whether new durable guidance is needed\n- proposed skill/spec text if needed\n- where it should be saved, subject to authorization\n\n## Visual Repair Loop for xz01 Homepage Runs\n\nWhen the user says to “继续” after a first xz01 prototype or says the page is not close enough to `xz01_demo`, do not stop at a functional page. Run an AI-vision-driven repair loop until the visible defects are fixed.\n\nWorkflow:\n\n1. Compare against the `demo_xz01` target as a high-density download-station portal, not a sparse landing page.\n2. Patch PC/mobile templates and CSS in the authorized run directory and the temporary deployment copy when already deployed.\n3. Clear all directories/items under `/www/wwwroot/www.900az.com/runtime/` after every add/modify/delete development change and before any validation. Do this before rendering screenshots or HTTP checks so stale ThinkPHP cache cannot hide template/controller changes.\n4. Validate HTTP 200, compiled PHP syntax, mobile no `target=\"_blank\"`, and screenshots.\n   - PC validation uses the desktop domain/access path: `https://www.900az.com/` with a desktop UA.\n   - Mobile validation must use the mobile domain/access path: `https://m.900az.com/` with a real Android/iPhone Mobile User-Agent. Do not validate `m.900az.com` using the same desktop/PC browser access method as PC.\n5. Submit PC and true small-width mobile-UA full-page screenshots to AI vision; if the page is long, also create segment images/contact sheets and ask AI to inspect the whole page. Treat AI findings as actionable repair items.\n6. For mobile visual/layout defects, final acceptance must use the real mobile domain (`https://m.900az.com/...`), Chrome DevTools Protocol mobile emulation (`mobile:true`), real iPhone/Android UA, widths such as 360/390/430, and runtime overflow probes (`documentElement.scrollWidth/clientWidth`, `body.scrollWidth`, and bounding boxes). Ordinary headless `--window-size` screenshots are useful for discovery but are not authoritative if they contradict CDP mobile-mode metrics. A 390px/mobile-UA check against `https://www.900az.com/...` is PC-domain responsive testing, not mobile-site validation, unless the user explicitly asks for the PC domain to be phone-responsive. Intentional internal nav scrolling is acceptable only when page-level `scrollWidth` still equals `clientWidth`.\n7. If the user reports right-side alignment issues, inspect both PC and mobile with the correct UA/domain pair, run an overflow probe on PC, capture a long mobile screenshot for lower modules, patch the run/deploy CSS, and re-check until AI vision passes.\n8. Re-patch and re-check until AI confirms pass.\n\nCommon repairs from run-0002:\n\n- PC hot games/apps need enough fallback cards to fill the grid; 3-4 cards create obvious blank areas.\n- Topic-card decorative background text should be low-opacity and not compete with foreground titles.\n- To match `xz01_demo`, reduce excessive modern-card spacing and increase list/module density.\n- Mobile default browser snapshots may hide real phone-width clipping; validate mobile with real Android/iPhone UA against `https://m.900az.com/` and with DevTools mobile emulation at multiple CSS widths such as 390px and 430px.\n- If a template includes a mobile back-to-top control, verify it with real Mobile UA + 390px screenshot: the button should be visible when required, must not cover download buttons or core content, and tapping/clicking after scroll should return the page to the top.\n- Do not reuse the desktop/PC access method for mobile verification; mobile-domain validation requires a mobile UA header.\n- If a 390px screenshot shows left blank strip, right card clipping, or right-side misalignment, fix container/grid width, not just `overflow-x:hidden`.\n- For mobile two-column modules such as `每日推荐`, `攻略` category cards, and `精选专辑`, use shrink-safe grids (`repeat(2,minmax(0,1fr))`) and ensure child cards/text use `min-width:0`, `max-width:100%`, and ellipsis where needed.\n- For dynamic mobile top navigation with more items than fit the viewport, use an intentional internal horizontal scroller (`overflow-x:auto`, `flex:0 0 auto`, no body-level overflow) rather than squeezing all items into one row or hiding overflow.\n- If a mobile back-to-top (`顶`) button visually crowds or overlaps content, prefer a non-intrusive document-flow placement near the page bottom with safe-area spacing over a fixed floating overlay.\n- Do not fix mobile containers to `max-width:390px`; it can pass a 390px screenshot but leave a blank strip on wider real phones. Under phone breakpoints prefer `width:100%; max-width:100%` plus safe padding/grid rules, then verify both 390px and 430px.\n- For right-side alignment defects, verify PC and mobile separately: PC with desktop UA on `www.900az.com`, mobile with real Android/iPhone UA on `m.900az.com`; do not share access mode.\n- For PC right-sidebar drift, probe `documentElement.scrollWidth` and overflowing elements, then unify `.xz-wrap`, hero grid, sidebar, lower sections, and card grids to the same right boundary.\n- For homepage/page visual acceptance, never use only a first-viewport screenshot as PASS evidence. Capture full-page PC and mobile screenshots; for long pages, split/contact-sheet them so lower modules such as 热门应用 / 攻略 / 精选专辑 and the footer are explicitly inspected.\n\nDetailed notes: `references/run-0002-visual-repair.md`.\n\n## Lanhu MCP Integration\n\nFor xz01 work that needs Lanhu requirements/designs, the Lanhu MCP service is installed and managed outside `/root/.openclaw`:\n\n- Session note: see `references/lanhu-mcp-discovery-notes.md` for the currently exposed tools and the no-account-wide-project-list limitation.\n\n```text\nInstall path: /root/.hermes/workspace/lanhu-mcp\nDocker container: lanhu_mcp_service\nHTTP MCP endpoint: http://127.0.0.1:8000/mcp?role=Developer&name=HermesMain\nHermes MCP server name: lanhu\n```\n\nOperational rules:\n\n- Use Docker Compose from `/root/.hermes/workspace/lanhu-mcp` to manage the service.\n- Keep Lanhu credentials in `/root/.hermes/workspace/lanhu-mcp/.env`; do not write them to `/root/.openclaw`.\n- Hermes native MCP connects through `mcp_servers.lanhu` in `/root/.hermes/config.yaml`.\n- After MCP config changes, start a fresh Hermes session or restart the relevant Hermes process so discovered MCP tools are loaded.\n- If external downloads are needed, use the user's temporary proxy:\n\n```bash\nexport http_proxy=http://192.168.1.9:1080\nexport https_proxy=http://192.168.1.9:1080\nexport all_proxy=socks5://192.168.1.9:1080\n```\n\nVerification commands:\n\n```bash\ncd /root/.hermes/workspace/lanhu-mcp\ndocker compose ps\ncurl -fsS http://127.0.0.1:8000/health\nhermes mcp test lanhu\n```\n\nDiscovered Lanhu tools include page analysis, design analysis, slice extraction, team messages, and member listing.\n\n## Hermes-Native Orchestration Boundary\n\nDo not port OpenClaw-only runtime mechanisms into Hermes workflow design.\n\nWhen the user directly addresses Hermes for an xz01 live-site/template issue, use Hermes-native execution immediately. Do **not** call OpenClaw `sessions_send`, `flow-controller`, role sessions, or other OpenClaw runtime orchestration unless the user explicitly asks to operate OpenClaw itself. OpenClaw files may still be read as reference material under the read-only boundary.\n\nOpenClaw-specific concepts such as `sessions_send(sessionKey: agent:dev:main, ...)`, `/root/.openclaw/agents/*/sessions`, and the OpenClaw `flow-controller.js` state machine are read-only legacy/reference material for this workflow. They must not be treated as Hermes-native execution primitives.\n\nIf the user addresses Hermes directly about an xz01 live-site/front-end regression, do **not** call OpenClaw role sessions, OpenClaw `flow-controller`, or OpenClaw dispatch as the first response. Use Hermes-native tools/workers (`delegate_task`, deterministic scans, browser/curl verification, and theme-only edits where authorized by the task). OpenClaw orchestration may be studied as reference, but it is not the active execution path unless the user explicitly asks for OpenClaw.\n\nHermes-native replacements:\n\n| OpenClaw concept | Hermes-native replacement | Use case |\n|---|---|---|\n| `sessions_send` to dev/test/rule sessions | `delegate_task` | Short synchronous subtasks; parent waits for result |\n| Persistent role sessions | Hermes profiles + `hermes kanban` | Durable multi-worker queues and role separation |\n| `flow-controller.js` single JSON state | Kanban board / factory SQLite queue | Multi-task durable workflow state |\n| OpenClaw cron progress monitor | Hermes `cronjob` / `hermes cron` | Scheduled watchdogs and periodic reports |\n| Manual subprocess role agents | `terminal(background=True)` or tmux-spawned `hermes` / `claude` | Long-running autonomous workers |\n| Feishu-only role routing | Hermes gateway / WebUI / kanban notifications | User-facing delivery and status updates |\n\nFor xz01 automation, prefer a Hermes-native design:\n\n```text\nHermes main/orchestrator\n  -> xz01-factory queue/SQLite/Kanban task\n  -> dev worker: Claude Code or Hermes profile for implementation\n  -> renderer/test worker: deterministic scripts + independent Hermes/vision validation\n  -> rule worker: Hermes profile or main-side review task\n  -> packaging/reporting\n```\n\nRules:\n\n1. Do not claim Hermes supports OpenClaw `sessions_send` unless an explicit OpenClaw compatibility bridge is installed and verified.\n2. Do not design new Hermes workflows around `/root/.openclaw` writable state.\n3. Use OpenClaw files only as learning/reference material.\n4. Use Hermes `delegate_task` for quick isolated checks, `hermes kanban` for durable multi-agent work, and deterministic scripts/SQLite queues for production xz01 factory state.\n5. For long-running dev/test agents, spawn explicit `hermes` or `claude` processes via `terminal(background=True)`/tmux, or use Kanban dispatcher profiles.\n6. When the user asks whether to keep noting caveats or directly build the first xz01 prototype, choose a safe action: create a Hermes factory run under `/root/.hermes/workspace/xz01-factory`, generate a prototype without touching production, run deterministic static validation, then report remaining production-validation steps. See `references/hermes-native-xz01-first-run.md`.\n\n\n## Karpathy-Style Dev Execution Principles\n\nThe following principles are absorbed from the Andrej Karpathy Claude Code guidance and adapted to xz01. They are subordinate to xz01 hard rules but should be included in dev prompts and reviews:\n\n1. **Think before editing, but do not over-ask.** State the execution assumption only when it affects boundaries such as production writes, backend/PHP changes, or route creation. For normal xz01 defects, proceed through dev → test → rule without asking the user.\n2. **Keep implementation simple.** Do not add unrequested abstractions, helpers, framework layers, or broad JavaScript systems for template work.\n3. **Make precise edits only.** Every changed line must map to the current xz01 acceptance target. Do not improve neighboring code, reformat unrelated files, remove pre-existing dead code, or change global structure unless required by the task.\n4. **Define success criteria before dev starts.** Main's dev prompt should include: target page/component/defect, allowed files, forbidden files, runtime-clear requirement, and test acceptance criteria.\n5. **Verify against the goal, not against dev's confidence.** Dev self-check is only a handoff note; official pass requires independent test screenshots + AI visual review + rule review where applicable.\n\n## xz01 Hook-Style Gate Policy\n\nHooks **can** be part of this skill, but only as xz01-specific guardrails. Do not copy the generic Everything Claude Code hook system into xz01 wholesale.\n\nUser-specific exclusions:\n\n```text\nNo generic security scanning requirement for xz01.\nNo parallelization/multi-agent expansion unless the user explicitly re-enables it.\nNo automatic hook that writes to /root/.openclaw.\nNo hook may replace independent test screenshots + AI visual review.\n```\n\nAllowed xz01 hook-style gates:\n\n| Gate | Purpose | Blocking conditions |\n|---|---|---|\n| pre-dev | stop illegal implementation scope before editing | `/root/.openclaw` write, `demo_xz01` edit, PHP/backend/controller/model/config/route/core/vendor edit |\n| post-dev | ensure development handoff is testable | changed files outside theme without explicit authorization; runtime not cleared after add/modify/delete |\n| pre-test | prevent stale-cache validation | runtime not cleared |\n| post-test | prevent false PASS | missing PC screenshot, missing mobile screenshot, missing AI visual analysis |\n| pre-package | prevent invalid packages | static/HTTP/screenshot/AI/rule gates missing, source not an already-validated `public/themes/<theme>` directory |\n\nA reusable script is bundled at:\n\n```bash\n/root/.hermes/skills/devops/xz01-dev-skill/scripts/xz01-hook-gate.py\n```\n\nExample usage:\n\n```bash\n# Before/after dev handoff\npython3 scripts/xz01-hook-gate.py pre-dev --changed-files /www/wwwroot/www.900az.com/public/themes/default/pc/index.html\npython3 scripts/xz01-hook-gate.py post-dev --changed-files /www/wwwroot/www.900az.com/public/themes/default/pc/index.html --runtime-cleared\n\n# Before/after test\npython3 scripts/xz01-hook-gate.py pre-test --runtime-cleared\npython3 scripts/xz01-hook-gate.py post-test --pc-screenshot --mobile-screenshot --ai-pass\n\n# Before package\npython3 scripts/xz01-hook-gate.py pre-package \\\n  --theme-dir /www/wwwroot/www.900az.com/public/themes/default \\\n  --static-pass --http-pass --screenshot-pass --ai-pass --rule-pass\n```\n\nThese gates may later be wired into Claude Code hooks, Hermes profiles, Kanban workers, or cron watchdogs. Wiring is optional; the policy and script are part of the skill so every xz01 run can use the same guard semantics.\n\n## Execution Time Control and Task Splitting\n\nUser-specific rules for xz01 work after repeated `max_turns` interruptions and one task exceeding 50 minutes:\n\n```text\nDo not solve this by increasing Claude Code max-turns.\nSplit all work into the smallest practical units.\nUse fixed validation scripts.\nDo not enable a hard \"禁止重新探索\" / no-re-exploration rule for now.\nStability first: do not use concurrency for xz01 template execution unless the user explicitly re-enables it.\nAvoid long-running single tasks; time-box dev/test calls and split earlier.\n```\n\nOperational rules:\n\n1. Main must split work before dispatch. A dev task should normally cover one page, one component, or one defect class only. If a worker times out, inspect partial outputs first and then split the remaining work into a smaller follow-up; do not simply resend the original large prompt.\n2. Execute xz01 template work through a strict serial queue: exactly one active dev task, one active test task, and one active rule review at a time. No parallel dev/test/rule lanes unless the user explicitly changes this rule.\n3. Do not bundle development + broad exploration + screenshot/AI visual + full regression + packaging into a single dev task.\n3. Dev should not perform official screenshots or full regression; test owns those.\n4. Use fixed validation scripts under `/root/.hermes/workspace/xz01-factory/tools/` whenever applicable, or the embedded skill copies under `scripts/` when installing/reusing this skill:\n   - `xz01-runtime-clear.sh` — clear `/www/wwwroot/www.900az.com/runtime/` after every add/modify/delete and before validation.\n   - `xz01-backend-baseline-check.sh` — verify PHP/backend/controller/model/config scope was not modified for a template task.\n   - `xz01-theme-diff-check.sh` — inspect theme-only change boundaries.\n   - `xz01-quick-http-gate.py` — quick HTTP checks for key PC/mobile URLs.\n   - `xz01-template-static-scan.py` — scan template c\n\nFile v1.0.44:_meta.json\n\n{\n  \"ownerId\": \"kn709ac4cea693g2hg2p4p3sgn82vk9z\",\n  \"slug\": \"xz01-dev-skill\",\n  \"version\": \"1.0.44\",\n  \"publishedAt\": 1779100324176\n}\n\nFile v1.0.44:references/demo-xz01-may-2026-source-update.md\n\n# demo_xz01 May 2026 source update learning\n\nContext: user reported `/root/.openclaw/workspace/demo_xz01` source was updated and asked to learn differences from previous content. The analysis was read-only; do not modify `demo_xz01`.\n\n## Compared materials\n\nUpdated archives observed around 2026-05-15:\n\n- `www.277zy.com/public/themes/default_2GmaD.zip` compared against older `default_HrJZZ.zip`\n- `www.400zyw.com/public/themes/default_6amTZ.zip` compared against older `default_KntTK.tar.gz`\n- `www.988zyw.com/public/themes/default_7MikX.zip` compared against older `default_mCYYn.tar.gz`\n- `www.866zyw.com/public/themes/default_L2GB4.zip` compared against current `public/themes/default`; no content delta found\n\n## Durable learning\n\n### Front-end dual-end search is canceled/weakened\n\nThe user explicitly confirmed the example: “其中前台双端搜索，已取消.” Treat this as a rule for future xz01-style template work:\n\n- PC/mobile header search forms are no longer mandatory.\n- Do not fail QA solely because a PC or mobile header lacks a complete `form action=\"...Search/index\"` search submission flow.\n- Search pages such as `cms/search.html` and `mobile/search.html` may still exist; their presence does not mean the front-end header must expose full search.\n- Some updated templates retain only a search icon, placeholder input, hot tags, or static search entrance.\n\nObserved examples:\n\n- `www.277zy.com`: PC header form removed; mobile header form replaced by non-form `searchBox`/input/icon.\n- `www.400zyw.com`: PC and mobile header forms removed/weakly represented.\n- `www.988zyw.com`: no full header form baseline; search UI moved/reshaped.\n- `www.866zyw.com`: no archive-to-current change; if a specific template still keeps search, respect that template.\n\n### Template structure is no longer uniform\n\nUpdated templates diverge more strongly from each other:\n\n- `www.277zy.com` removed `common_cms/common/zyxz_module/*` entirely in the new archive.\n- `www.400zyw.com` and `www.988zyw.com` still have many `zyxz_module` files, but pages/partials changed substantially.\n- Some templates add many mobile bottom/related partials; others reduce PC/mobile partials and inline sidebars/recommendation blocks directly in page templates.\n\nFuture dev/test work should not require a fixed `zyxz_module` inventory or a fixed set of `_side_*.html` includes.\n\n### Page composition changes\n\nObserved updated patterns:\n\n- Home pages increasingly use page-local blocks and `getAllData()` calls for hot data, new data, recommendations, news, slides, videos, rankings, etc.\n- List pages may replace sidebar includes with inline ranking/recommendation/news blocks.\n- Game detail pages emphasize platform/download completeness: Android/iOS availability, QR scan download, screenshots/slider, related games, related news, and rankings.\n- Rank pages may use `cms_appranking`, bind IDs, `$rank_channel_list`, and `$game_list` instead of plain appsoft list calls.\n\n### Existing hard rules still apply\n\nDo not blindly copy risky constructs from updated source:\n\n- Mobile `target=\"_blank\"` remains disallowed by user rule even if some updated templates contain residue.\n- Large-scale `uk-cover` remains risky/disallowed in implementation even if updated archives contain many occurrences; prefer custom `object-fit: cover` approaches when building.\n- Database routes remain authoritative; do not create or fix routes simply because a template file exists.\n\n## Future checklist\n\nWhen asked to learn or implement against updated `demo_xz01`:\n\n1. Treat `/root/.openclaw/workspace/demo_xz01` as read-only.\n2. Inventory updated archives and compare against older package/current directory if available.\n3. Separate durable standard changes from source quirks.\n4. For search: do not require full front-end PC/mobile header search unless the specific requested template/design explicitly includes it.\n5. For testing: remove “missing header search” from default fail criteria; keep validation for navigation, carousel/data rendering, responsive layout, and actual routes.\n6. For implementation: preserve template-specific structure rather than forcing all templates into old module/include patterns.\n\nFile v1.0.44:references/hermes-native-xz01-first-run.md\n\n# Hermes-native xz01 factory first-run pattern\n\nThis reference captures the durable workflow learned from the first Hermes-native xz01 prototype run. It is not a one-off task log; use it as a starter pattern for future xz01 automation work.\n\n## Context\n\nThe user corrected that OpenClaw runtime mechanisms (`sessions_send`, `agent:dev:main`, OpenClaw `flow-controller.js`) do not map to Hermes. For Hermes work, OpenClaw is a read-only standards/corpus source. New automation state and generated files belong under Hermes-owned paths.\n\n## Correct first-run approach\n\nWhen the user asks whether to keep discussing or “直接开发第一套给我看下”, act and produce a small end-to-end prototype rather than only listing caveats.\n\nRecommended minimal first-run sequence:\n\n1. Treat `/root/.openclaw` as read-only reference.\n2. Create a Hermes factory run directory, e.g.:\n   - `/root/.hermes/workspace/xz01-factory/runs/run-0001/`\n   - generated template root: `generated/public/themes/default/`\n   - reports: `reports/`\n3. Write a minimal `state.json` and `requirement.json` for traceability.\n4. Use `delegate_task` for a short dev-worker implementation task, or a long-running explicit `hermes` / `claude` worker if the implementation is large.\n5. Generate only into the Hermes factory run directory; do not deploy or overwrite production themes in the prototype step.\n6. Run deterministic static validation before reporting.\n7. Report what exists, what was validated, and what remains before production deployment.\n\n## Minimal output shape\n\n```text\n/root/.hermes/workspace/xz01-factory/runs/run-0001/\n├── state.json\n├── requirement.json\n├── generated/public/themes/default/\n│   ├── DEV_SUMMARY.md\n│   ├── cms/index.html\n│   ├── mobile/index.html\n│   └── common_cms/\n│       ├── common/_head.html\n│       ├── pc/_header.html\n│       ├── pc/_footer.html\n│       ├── pc/assets/css/style.css\n│       ├── pc/assets/js/style.js\n│       ├── mobile/_header.html\n│       ├── mobile/_footer.html\n│       ├── mobile/assets/css/style.css\n│       └── mobile/assets/js/style.js\n└── reports/basic-validation.json\n```\n\n## Static validation checklist for prototype\n\nBefore telling the user the prototype is ready, verify at least:\n\n- no writes under `/root/.openclaw`\n- no production deploy unless explicitly requested\n- no raw PHP template tags (`<?php`, `<?=`, `<?`)\n- mobile templates contain no `target` / `_blank`\n- no `href=\"#\"`\n- no `uk-cover` attributes\n- no `limit=\"0\"` / `getAllData({limit: 0})`\n- CSS brace counts are balanced\n- all `{include file=\"./themes/default/...\"}` targets exist\n- referenced local CSS/JS assets exist under the generated template root\n- HTML class names used by the prototype have CSS definitions, or intentional exceptions are documented\n\n## Prototype vs production boundary\n\nA prototype-ready result is not production-ready. Before packaging/deployment, continue with:\n\n1. renderer script: deploy to a safe test theme or staging path, clear cache, render PC/mobile\n2. screenshot capture for both devices\n3. AI visual analysis with DOM/Puppeteer anti-hallucination check\n4. data-render verification against real DB/route map\n5. repair loop until issues are zero\n6. rule review\n7. numbered package under `/root/.hermes/workspace/xz01/`\n\n## Reporting preference\n\nFor this user, first line must remain the 10-column table for xz01/template status reports. Keep the prose concise and action-oriented; if a safe prototype can be built without production side effects, build it rather than asking whether to proceed.\n\nFile v1.0.44:references/hermes-native-xz01-live-deploy-validation.md\n\n# Hermes native xz01 live deployment and validation notes\n\nUse this when the user asks to deploy a temporary xz01 template for live validation via:\n\n- `https://www.900az.com/`\n- `https://m.900az.com/`\n\n## Key correction from the first live run\n\nThe prototype directory under `/root/.hermes/workspace/xz01-factory/runs/<run>/generated/` is safe for staging, but the user may explicitly want temporary template development to live under:\n\n```text\n/www/wwwroot/www.900az.com/public/themes/default/\n```\n\nWhen this happens, proceed directly but first make a timestamped backup of the current `default` theme.\n\n## Safe live deployment sequence\n\n1. Ensure generated source exists under the run directory.\n2. Create backup:\n\n```bash\nBACKUP_DIR=/root/.hermes/workspace/xz01-factory/backups\nmkdir -p \"$BACKUP_DIR\"\ntar -czf \"$BACKUP_DIR/default-before-<run_id>-$(date +%Y%m%d-%H%M%S).tar.gz\" \\\n  -C /www/wwwroot/www.900az.com/public/themes default\n```\n\n3. Replace default theme:\n\n```bash\nrm -rf /www/wwwroot/www.900az.com/public/themes/default\nmkdir -p /www/wwwroot/www.900az.com/public/themes/default\ncp -a /root/.hermes/workspace/xz01-factory/runs/<run_id>/generated/public/themes/default/. \\\n  /www/wwwroot/www.900az.com/public/themes/default/\nrm -rf /www/wwwroot/www.900az.com/runtime/*\n```\n\n4. Verify PC and mobile return HTTP 200.\n5. Run PHP syntax checks on compiled runtime templates under `/www/wwwroot/www.900az.com/runtime/temp/*.php` after first render.\n6. Run static checks:\n   - mobile contains no `target=\"_blank\"`\n   - source templates contain no raw PHP tags\n   - no `href=\"#\"`\n   - no `uk-cover`\n   - no `limit=\"0\"` / `getAllData({limit:0})`\n   - CSS brace counts balanced\n7. Use browser screenshots and AI vision on both URLs.\n8. Save artifacts under:\n\n```text\n/www/wwwroot/www.900az.com/xz01-runs/screenshots/<run_id>/\n/www/wwwroot/www.900az.com/xz01-runs/reports/\n```\n\n## Pitfalls found in run-0001\n\n### Undefined template variables can cause 500\n\nIf the controller does not provide variables such as `$recommend_list`, `$latest_list`, `$rank_list`, `$category_list`, `$news_list`, or `$topic_list`, ThinkPHP may throw `未定义变量` during template compilation/rendering.\n\nFor live prototypes, wrap optional data blocks with `isset(...)` and provide static fallback content so the page can render before real DB binding exists:\n\n```html\n{if condition=\"isset($recommend_list)\"}\n  {foreach name=\"recommend_list\" item=\"vo\" key=\"key\"}\n  ...\n  {/foreach}\n{else/}\n  <!-- static fallback cards for visual validation -->\n{/if}\n```\n\n### Some `|default` forms may compile badly\n\nAvoid complex `|default` expressions in live xz01 prototypes, especially inside `{:...}` expressions. Prefer explicit `isset(...) ? ... : ...` or static fallback blocks.\n\n### ThinkPHP trace overlay can pollute screenshots\n\nIf debug trace is enabled, screenshots can show `#think_page_trace_open` with a small runtime number such as `0.070867s`. Hide it in temporary template CSS before visual validation:\n\n```css\n#think_page_trace,\n#think_page_trace_open {\n  display: none !important;\n  visibility: hidden !important;\n}\n```\n\n### Broken images are caught by AI vision\n\nStatic prototype references need actual files. If using fallback cards, create local placeholder assets under both PC and mobile `assets/images/` rather than relying on missing image paths. SVG placeholders are acceptable for temporary validation.\n\n## First-run validated output shape\n\nThe first run successfully used:\n\n```text\npublic/themes/default/\n├── cms/index.html\n├── mobile/index.html\n└── common_cms/\n    ├── common/_head.html\n    ├── pc/_header.html\n    ├── pc/_footer.html\n    ├── pc/assets/css/style.css\n    ├── pc/assets/js/style.js\n    ├── pc/assets/images/*.svg\n    ├── mobile/_header.html\n    ├── mobile/_footer.html\n    ├── mobile/assets/css/style.css\n    ├── mobile/assets/js/style.js\n    └── mobile/assets/images/*.svg\n```\n\n## Acceptance bar for a temporary homepage run\n\nMinimum pass condition before reporting success:\n\n- PC URL returns 200.\n- Mobile URL returns 200.\n- Compiled runtime PHP has no syntax errors.\n- Browser console has no JS errors.\n- PC screenshot AI check says no obvious layout overlap/missing content.\n- Mobile screenshot AI check says no obvious layout overlap/missing content.\n- AI confirms images display normally and trace overlay is not visible.\n\nFile v1.0.44:references/lanhu-mcp-discovery-notes.md\n\n# Lanhu MCP discovery notes\n\nSession-derived notes for the xz01 workflow.\n\n## What this Lanhu MCP exposes\n\nThe current `lanhu-mcp` service exposes project-scoped tools such as:\n\n- `lanhu_resolve_invite_link`\n- `lanhu_get_pages`\n- `lanhu_get_designs`\n- `lanhu_get_design_slices`\n- `lanhu_get_ai_analyze_page_result`\n- `lanhu_get_ai_analyze_design_result`\n- `lanhu_say`, `lanhu_say_list`, `lanhu_say_detail`, `lanhu_say_edit`, `lanhu_say_delete`\n- `lanhu_get_members`\n\n## Important limitation\n\nThere is **no account-wide project enumeration tool** in this MCP setup. In practice:\n\n- you cannot ask the MCP to list all projects owned by the account\n- to inspect a project, you must start from a share/invite link or a known `tid/pid`\n- once a project URL is available, use the page/design/slice tools against that specific project\n\n## Practical workflow\n\n1. Ask the user for a Lanhu project link when the target project is unknown.\n2. If the user has only an invite/share link, resolve it first.\n3. Use the resolved project URL for page/design extraction.\n4. Do not promise an account-wide catalog unless the MCP gains a new tool for it later.\n\nFile v1.0.44:references/lanhu-mcp-installation.md\n\n# Lanhu MCP installation for xz01 workflow\n\nUse when the user asks how to install or connect `https://github.com/dsphper/lanhu-mcp` for the xz01/Hermes+Claude workflow.\n\n## Recommendation\n\nPrefer this architecture:\n\n```text\nLanhu MCP server = Docker Compose HTTP service\nHermes = native MCP HTTP client\nClaude Code = HTTP MCP client pointed at the same service\n/root/.openclaw = read-only learning corpus; do not install or configure Lanhu there\n```\n\nRecommended install directory:\n\n```text\n/root/.hermes/workspace/lanhu-mcp\n```\n\nRationale:\n\n- `lanhu-mcp` is a long-running HTTP MCP server (`/mcp`), not a one-shot stdio/npx tool.\n- It depends on Python + Playwright/Chromium; Docker isolates those dependencies from Hermes and Claude.\n- It requires `LANHU_COOKIE`, so keeping secrets in the service `.env` is clearer than mixing them into unrelated configs.\n- Hermes, Claude dev, Hermes test, and Hermes rule can share one service with different URL query parameters.\n\n## Install outline\n\n```bash\nmkdir -p /root/.hermes/workspace\ngit clone https://github.com/dsphper/lanhu-mcp.git /root/.hermes/workspace/lanhu-mcp\ncd /root/.hermes/workspace/lanhu-mcp\ncp config.example.env .env\n# edit .env and set LANHU_COOKIE; optionally FEISHU_WEBHOOK_URL\n# keep SERVER_HOST=0.0.0.0 and SERVER_PORT=8000 unless there is a port conflict\ndocker compose up -d --build\n```\n\nVerify:\n\n```bash\ndocker compose ps\ndocker compose logs --tail=100 lanhu-mcp\ncurl http://127.0.0.1:8000/health\n```\n\nMCP endpoint pattern:\n\n```text\nhttp://127.0.0.1:8000/mcp?role=Developer&name=HermesMain\n```\n\nUse English URL parameter values; some clients do not handle Chinese query parameters reliably.\n\n## Hermes native MCP config\n\nHermes needs the Python MCP package available in its environment:\n\n```bash\npip install mcp\n```\n\nThen configure Hermes `mcp_servers`:\n\n```yaml\nmcp_servers:\n  lanhu:\n    url: \"http://127.0.0.1:8000/mcp?role=Developer&name=HermesMain\"\n    timeout: 180\n    connect_timeout: 60\n```\n\nRestart Hermes after changing MCP config; MCP tools are discovered on startup. Expected tool names are prefixed like:\n\n```text\nmcp_lanhu_lanhu_get_pages\nmcp_lanhu_lanhu_get_designs\nmcp_lanhu_lanhu_get_ai_analyze_page_result\nmcp_lanhu_lanhu_get_ai_analyze_design_result\n```\n\n## Claude Code config\n\nPoint Claude Code to the same HTTP service, with a separate identity:\n\n```json\n{\n  \"mcpServers\": {\n    \"lanhu\": {\n      \"type\": \"http\",\n      \"url\": \"http://127.0.0.1:8000/mcp?role=Developer&name=ClaudeDev\"\n    }\n  }\n}\n```\n\nSuggested identities:\n\n| Role | URL suffix |\n|---|---|\n| Hermes main | `?role=Developer&name=HermesMain` |\n| Claude dev | `?role=Developer&name=ClaudeDev` |\n| Hermes test | `?role=Tester&name=HermesTest` |\n| Hermes rule | `?role=Developer&name=HermesRule` |\n\n## Required secret\n\n`LANHU_COOKIE` is required. Do not guess it or search for it in unrelated files. The user must provide it or obtain it from a logged-in Lanhu browser session.\n\n## Pitfalls\n\n- Do not install this under `/root/.openclaw`; that tree is read-only for this workflow.\n- Do not use stdio/npx as the primary integration; this project is designed to run as an HTTP MCP service.\n- Do not expose the service publicly without access control; Lanhu cookies and cached design data are sensitive.\n- Do not treat failure before `LANHU_COOKIE` is configured as a durable tool failure; it is a missing credential/setup state.\n\nFile v1.0.44:references/run-0002-visual-repair.md\n\n# run-0002 visual repair notes\n\nUse these notes when an xz01 temporary homepage run renders successfully but AI visual review says it is still not close enough to `demo_xz01`, has viewport defects, or has right-side alignment problems.\n\n## Visual target learned from run-0002\n\nA homepage that is merely functional is not enough when the user asks to continue improving toward `xz01_demo`. The closer target is a high-density download-station portal:\n\n- PC: orange/red gradient header, search/navigation, dense first screen, icon recommendations, category keyword rows, carousel/news area, rank/sidebar, activities/gifts/news columns, hot games/apps, topic collections.\n- Mobile: red/orange header, search/nav pills, hero banner, daily recommendations, news banner/list, hot games/apps, strategy/news blocks, topic collections.\n\n## AI visual repair loop pattern\n\n1. Generate/upgrade the template in the run directory.\n2. Deploy to `/www/wwwroot/www.900az.com/public/themes/default/` with a backup and clear runtime cache.\n3. Validate HTTP 200 and compiled PHP syntax after rendering both PC and mobile.\n4. Take screenshots and run AI visual checks for both ends.\n5. Treat AI visual findings as repair input, not final caveats. Patch the run and deployment copy, clear cache, and re-validate.\n6. Only report pass after the final AI check confirms the visible defect is fixed.\n\n## Domain + User-Agent validation rule\n\nThe user corrected this explicitly: **M-domain validation must use a real mobile User-Agent. Do not validate `https://m.900az.com/` with the same desktop/browser access mode used for PC.**\n\nUse separate access modes:\n\n```bash\nUA_PC='Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36'\nUA_M='Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36'\n\ncurl -k -L -A \"$UA_PC\" https://www.900az.com/\ncurl -k -L -A \"$UA_M\" https://m.900az.com/\n\n/usr/bin/google-chrome --headless=new --no-sandbox --disable-gpu --ignore-certificate-errors \\\n  --window-size=1365,1800 --user-agent=\"$UA_PC\" \\\n  --screenshot=/root/.hermes/workspace/xz01-factory/runs/<run_id>/screenshots/pc.png \\\n  https://www.900az.com/\n\n/usr/bin/google-chrome --headless=new --no-sandbox --disable-gpu --ignore-certificate-errors \\\n  --window-size=390,1600 --user-agent=\"$UA_M\" \\\n  --screenshot=/root/.hermes/workspace/xz01-factory/runs/<run_id>/screenshots/mobile.png \\\n  https://m.900az.com/\n```\n\nVerification expectations:\n\n- PC response should contain PC markers such as `xz-pc-header`, and not mobile markers.\n- Mobile response should contain mobile markers such as `xz-m-header`, and not PC markers.\n- Mobile response must have no `target=\"_blank\"`.\n- Both should be HTTP 200 and have no `系统发生错误`.\n\n## PC repair patterns from run-0002\n\nAI flagged that PC was closer to the demo but still had:\n\n- hot game/app modules with too few cards and large blank areas;\n- topic cards whose oversized background text interfered with foreground titles;\n- overly loose spacing that felt more like a modern card site than a dense download portal;\n- right-side layout misalignment: the sidebar extended farther right than lower sections, and the page showed horizontal overflow.\n\nDurable fixes:\n\n- Provide enough fallback items to fill the grid, e.g. 8-12 hot game/app cards rather than 3-4.\n- Compress module margins/gaps/padding when targeting demo-like density.\n- Lower opacity/saturation or reposition decorative large text in topic cards.\n- Keep rank/sidebar/list blocks dense and visible in the first screen.\n- If adding content under the PC right-side “本周专题” makes the right sidebar taller than the left hero card, do not leave the left column visually empty. Either keep the grid `align-items:start` and add meaningful left-column content (e.g. quick topic cards) or reduce the right-side content height so the lower three-column section does not appear disconnected.\n- A practical repair for the PC right sidebar is: `下载排行 → 本周专题 → 专题推荐` on the right, plus a short `xz-quick-row` of 4 cards at the bottom of the left “今日推荐” card to balance the two columns.\n- For stubborn PC gaps just above lower modules such as `游戏活动`, adjust both sides of the seam: compress `.xz-triple-news` top spacing and reduce the sidebar inter-card `gap`; otherwise one column can still create a small visual shelf even after the quick cards are tightened.\n- Use `minmax(0,1fr)` for grids so fixed gaps do not push right edges out.\n- Add `html,body{overflow-x:hidden}` only as a guard after fixing the actual over-wide elements.\n- Decorative pseudo-elements inside right-side cards should not increase `scrollWidth`; keep them inside the card (`right:12px`) or safely clipped.\n\nUseful overflow probe in browser console:\n\n```js\n(() => {\n  const ww = document.documentElement.clientWidth;\n  return [...document.querySelectorAll('*')]\n    .map(e => {\n      const r = e.getBoundingClientRect();\n      return { tag:e.tagName, cls:e.className, text:(e.innerText||'').slice(0,20), x:r.x, w:r.width, right:r.right, scrollW:e.scrollWidth, clientW:e.clientWidth };\n    })\n    .filter(o => o.right > ww + 1 || o.x < -1 || o.scrollW > o.clientW + 1)\n    .slice(0,50);\n})()\n```\n\n## Mobile viewport repair patterns from run-0002\n\nBrowser UI snapshots may show content, while a real 390px screenshot can reveal horizontal clipping. Always verify with a true small screenshot plus mobile UA, not only the default browser viewport.\n\nIf AI reports left blank strip, right-side clipping, or right-side misalignment:\n\n- Do not stop at `overflow-x:hidden`; fix the actual container/grid sizing.\n- Do not set mobile containers to a fixed `max-width:390px`; it can look correct in a 390px test but leave an empty right strip on wider real phones. Use `width:100%; max-width:100%` under phone breakpoints unless intentionally centering a phone shell.\n- Keep grids as `repeat(2, minmax(0, 1fr))` for daily recommendations and topic/strategy blocks.\n- Ensure cards use `min-width:0` and the parent grid/card widths fit inside the visible viewport.\n- Clip decorative hero/topic overflow without clipping main card content.\n- Use flex for section titles and MORE buttons so the right edge is stable across modules.\n- Use flex for app/game list rows: icon fixed, info `flex:1; min-width:0`, download button `flex:0 0 auto`.\n- Re-run the 390px screenshot and AI check after every viewport patch.\n- Also take a long 390px screenshot (e.g. height 3000) to include lower modules such as 热门应用 / 攻略 / 精选专辑; a first-viewport screenshot is not enough to verify the lower right edge.\n\nExample final guard used in run-0002:\n\n```css\n@media (max-width:600px){\n  .xz-m-header,.xz-m-main,.xz-m-footer{width:100%;max-width:100%;margin-left:0;margin-right:0}\n  .xz-m-main{padding-left:10px;padding-right:10px;overflow:hidden}\n  .xz-m-visual,.xz-m-card,.xz-m-banner,.xz-m-strategy-top a,.xz-m-album-card{overflow:hidden}\n  .xz-m-visual{width:calc(100% + 20px);max-width:none;margin-left:-10px;margin-right:-10px}\n  .xz-m-recom-grid,.xz-m-strategy-top,.xz-m-album-grid{max-width:100%;grid-template-columns:repeat(2,minmax(0,1fr))}\n  .xz-m-section-title{display:flex;align-items:center;justify-content:space-between;gap:8px}\n  .xz-m-section-title a{flex:0 0 auto;max-width:58px;overflow:hidden;text-overflow:ellipsis;white-space:nowrap}\n  .xz-m-recom-card{min-width:0;overflow:hidden}\n  .xz-m-item{display:flex;align-items:center;gap:8px;overflow:hidden}\n  .xz-m-item .info{flex:1;min-width:0;margin:0}\n  .xz-m-item .btn{flex:0 0 auto;white-space:nowrap}\n  .xz-backtop{right:10px}\n}\n```\n\n## Screenshot artifact rule\n\nFor Hermes WebUI reporting, save/copy screenshots under `/root/.hermes/workspace/...` and reference them with `MEDIA:/absolute/path`. Do not rely on `/www/...` paths for WebUI media display.\n\n## Reporting pattern\n\nUse the user's current concise xz01 format:\n\n- conclusion;\n- completed changes;\n- issues found and fixed;\n- validation result;\n- artifact links and screenshots;\n- remaining small issues.\n\nDo not use the old 10-column OpenClaw table unless explicitly requested.\n\nFile v1.0.44:references/session-2026-05-16-allpage-visual-qa-and-scanner-fixes.md\n\n# 2026-05-16 — All-page visual QA + scanner false-positive fixes\n\n## Context\n\nDuring xz01 validation the user required PC+mobile all-page scanning before packaging, including template code scan, curl/browser access, screenshots, and AI recheck. Core page screenshots were not enough when the crawl discovered many existing DB routes.\n\n## Durable workflow lesson\n\nWhen the user asks for “双端所有页面 / 全部页面截图 + AI复检”:\n\n1. Run static template scan first.\n2. Run URL crawl for PC+mobile existing DB routes and save the JSON result.\n3. Capture screenshots for every URL in the crawl result, not only the homepage/list pages.\n4. Also keep a small core screenshot set for direct inspection: PC/mobile homepage, software list, game list, news/list, and at least one detail page per content type.\n5. Build contact sheets from the full screenshot set and submit every contact sheet to AI visual review. This is the scalable way to AI-review dozens of pages without losing coverage.\n6. Keep the screenshot manifest with URL → file path mapping so any contact-sheet issue can be traced back to the exact page.\n7. If a screenshot command times out for a detail page, retry with Chromium flags such as `--disable-dev-shm-usage`, `--disable-extensions`, and `--virtual-time-budget`; do not mark the page as visually checked until a screenshot exists.\n\n## Scanner implementation pitfall\n\nAvoid naive zero-count detection:\n\n```python\nre.search(r'0\\s*款', body)\n```\n\nThis falsely matches strings such as `10款`. Use a digit-boundary-aware pattern instead:\n\n```python\nre.search(r'(?<!\\d)0\\s*款', body)\n```\n\n## AI visual triage rule\n\nAI may flag a page-label mismatch if a game route displays a database category label like “手游下载”. Treat this as a possible wording observation, not an automatic fail, when:\n\n- the DB route is valid,\n- the page renders game/software/news data correctly,\n- there is no 500, no empty list, no broken pagination, and no layout defect.\n\nIf the user requires label normalization, handle it in the template display layer only; do not create routes or modify database categories by default.\n\nFile v1.0.44:references/session-2026-05-16-db-channel-name-display-standard.md\n\n# 2026-05-16 — DB channel name is the front-end display standard\n\nUser correction about route alias `gzos`:\n\n```sql\ncmf_cms_channel.id = 6\nalias = 'gzos'\nname = '手游下载'\nlisttpl = 'list_game'\nshowtpl = 'show_soft_detail'\n```\n\n## Rule\n\nFor xz01 category/list pages, the database channel row is authoritative for both routing and display labels.\n\n- The route alias such as `gzos` is only the database alias/path identifier.\n- The front-end PC and mobile page display name must use the database channel `name` field.\n- PC and mobile must display the same database `name` for the same channel.\n- Do not treat a game route showing `手游下载` as a visual mismatch if the database `cmf_cms_channel.name` is `手游下载`.\n- Do not normalize or rewrite channel names to guessed labels such as `游戏下载`, `游戏中心`, or `游戏列表` unless the user explicitly requests a template-only wording override.\n- Test/AI review must validate display text against the DB channel metadata, not against inferred route semantics.\n\n## Example\n\nFor `alias='gzos'` and `name='手游下载'`:\n\n- PC `/gzos/` heading should display `手游下载`.\n- Mobile `m.900az.com/gzos/` heading should display `手游下载`.\n- This is PASS when the page renders real data, pagination is safe, and there is no HTTP/template/layout error.\n\nFile v1.0.44:references/session-2026-05-16-demo-xz01-systematic-validation.md\n\n# 2026-05-16 — demo_xz01 systematic validation correction\n\nUser correction: xz01 work must learn from `/root/.openclaw/workspace/demo_xz01` systematically, not only patch one page at a time. Ambiguous rules may be listed for user confirmation, but obvious xz01 defects must be handled directly.\n\n## Learned demo_xz01 conventions\n\n- Treat `demo_xz01` as a read-only pattern corpus. Do not edit it and do not copy it blindly.\n- Required dual-end template coverage must be systematic: PC `cms/*` and mobile `mobile/*` counterparts for homepage, list pages, search/page/404/500, and software/game/news/collection detail pages.\n- Software/game list pages and detail pages must exist and render with real data through the existing ThinkPHP/template data functions; they must not be omitted, referenced only, or filled with static placeholders.\n- List pages that paginate should follow the demo data-rendering pattern using `getPcPageData` / `getMobilePageData` and output `$page_code|raw` or equivalent pagination variables. A page failing because pagination variables are missing must be fixed in the template/header/footer include chain, not hidden.\n- Every add/modify/delete development change must clear `/www/wwwroot/www.900az.com/runtime/` before validation.\n- Before packaging, scan both PC and mobile front-end URLs for 500/ThinkPHP errors. Packaging is forbidden if any checked existing DB route returns a 500-style page.\n- Validate all relevant dual-end pages by static template scan, curl/browser HTTP access, screenshots, and AI visual review.\n\n## Resource loading rules confirmed by user\n\n- Do not use the old common jQuery path: `<script type=\"text/javascript\" src=\"/themes/default/common_cms/common/jquery.min.js\"></script>`.\n- Use theme-side PC/mobile asset jQuery loading consistent with demo_xz01, such as `/themes/default/common_cms/pc/assets/js/jquery.min.js` or `/themes/default/common_cms/mobile/assets/js/jquery.min.js` where an absolute path is needed, or the corresponding local `assets/js/jquery.min.js` form in copied common assets.\n- If UIkit is needed, use: `<link rel=\"stylesheet\" href=\"/themes/default/common_cms/pc/assets/css/uikit.css\"><script src=\"/themes/default/common_cms/pc/assets/js/uikit.js\"></script>` (or the minified demo-equivalent only when matching actual assets requires it).\n- If Swiper/carousel is needed, include both: `<script src=\"/themes/default/common_cms/pc/assets/js/swiper-bundle.min.js\"></script>` and `<link rel=\"stylesheet\" href=\"/themes/default/common_cms/pc/assets/css/swiper-bundle.min.css\">` adapted per PC/mobile asset location.\n\n## Validation scripts now part of the skill\n\nSkill support scripts are stored under `scripts/` and should be copied or invoked from there:\n\n- `xz01-runtime-clear.sh` — clear ThinkPHP runtime cache before validation after every dev change.\n- `xz01-backend-baseline-check.sh` — ensure backend/PHP scope has not been modified accidentally.\n- `xz01-theme-diff-check.sh` — inspect theme-only diff boundaries.\n- `xz01-quick-http-gate.py` — quick URL HTTP gate for key URLs.\n- `xz01-template-static-scan.py` — static template scan for dual-end completeness, bad resource paths, pagination-pattern gaps, mobile target_blank, malformed links, and forbidden filler assets.\n- `xz01-full-url-scan.py` — crawl same-host PC/mobile pages and fail on 5xx, ThinkPHP errors, malformed internal links, mobile blank-targets, many empty placeholders, and zero-count software/game list pages.\n- `xz01-screenshot-core.sh` — capture deterministic Chromium headless screenshots for core PC/mobile pages before AI visual review.\n\n## Packaging gate\n\nBefore creating any zip package under `/root/.hermes/workspace/xz01/`:\n\n1. Clear runtime cache.\n2. Run static template scan.\n3. Run HTTP/crawl scan on PC and mobile.\n4. Ensure list and detail pages for software/game render with data.\n5. Capture PC and mobile screenshots for all relevant existing DB routes/pages.\n6. Submit screenshots to AI visual review and incorporate findings.\n7. Only package if all gates pass.\n\nFile v1.0.44:references/session-2026-05-16-main-role-boundary-correction.md\n\n# Session note: main role boundary correction after PC visual repair\n\n## Context\n\nDuring a PC homepage visual repair, the user pointed out that the previous fix was not performed through the xz01 role architecture. Hermes main had directly edited HTML/CSS and ran screenshot/AI validation. The user asked whether, according to xz01 skill rules and architecture, all coding should have been handed to Claude.\n\n## Durable lesson\n\nYes. In xz01 workflow, main is a dispatcher and final reporter, not an implementation worker.\n\nCorrect sequence for visible template defects:\n\n```text\nuser feedback\n  -> Hermes main triages and dispatches\n  -> Claude Code dev performs HTML/CSS/JS/ThinkPHP changes\n  -> independent test role screenshots + deterministic checks + AI visual QA\n  -> rule role audits and captures durable guidance\n  -> Hermes main summarizes\n```\n\n## Pitfall to avoid\n\nDo not treat a small or obvious CSS/template fix as an exception. Speed does not justify role collapse. If main patches templates directly, the workflow loses the independent dev/test separation the user explicitly wants.\n\n## Practical implication\n\nFor future xz01 requests such as “PC 端某模块排版有问题”, main should prepare a precise dev task containing:\n\n- affected URL/domain and device;\n- screenshot or user-visible symptom;\n- relevant files or run directory if already known;\n- constraints: do not modify `/root/.openclaw`, preserve DB-route rule, mobile no `target_blank` when applicable;\n- request for changed-file summary and self-check notes.\n\nThen main should separately route validation to test instead of self-validating.\n\nArchive v1.0.43: 50 files, 100763 bytes\n\nFiles: _meta.json (134b), references/demo-xz01-may-2026-source-update.md (4193b), references/hermes-native-xz01-first-run.md (3667b), references/hermes-native-xz01-live-deploy-validation.md (4425b), references/lanhu-mcp-discovery-notes.md (1141b), references/lanhu-mcp-installation.md (3378b), references/run-0002-visual-repair.md (8209b), references/session-2026-05-16-allpage-visual-qa-and-scanner-fixes.md (2144b), references/session-2026-05-16-db-channel-name-display-standard.md (1326b), references/session-2026-05-16-demo-xz01-systematic-validation.md (4045b), references/session-2026-05-16-main-role-boundary-correction.md (1623b), references/session-2026-05-16-max-turns-task-splitting-validation-scripts.md (3379b), references/session-2026-05-16-no-php-controller-template-dev.md (1649b), references/session-2026-05-16-packaging-gate-runtime-list-detail.md (2420b), references/session-2026-05-16-pc-gap-dev-test-rule-loop.md (3447b), references/session-2026-05-16-right-sidebar-height-balance.md (1890b), references/session-2026-05-16-theme-only-data-links-search.md (3070b), references/session-2026-05-18-all-detail-mixed-sidebar.md (4243b), references/session-2026-05-18-detail-sidebar-bottom-modules.md (4266b), references/session-2026-05-18-dual-end-list-pagination.md (2256b), references/session-2026-05-18-dual-end-nav-dynamic-menu.md (4056b), references/session-2026-05-18-fullpage-visual-qa-correction.md (2085b), references/session-2026-05-18-hermes-native-no-search-regression.md (2998b), references/session-2026-05-18-hermes-native-title-search-repair.md (3432b), references/session-2026-05-18-home-resource-iconized-cards.md (2857b), references/session-2026-05-18-karpathy-ecc-hook-adaptation.md (1935b), references/session-2026-05-18-mobile-domain-validation-correction.md (2743b), references/session-2026-05-18-mobile-layout-overflow-repair.md (3297b), references/session-2026-05-18-openclaw-temp-artifact-boundary.md (1884b), references/session-2026-05-18-pagination-common-data-chain.md (2535b), references/session-2026-05-18-pagination-demo-copy-correction.md (2110b), references/session-2026-05-18-pagination-rule-template-repair.md (2222b), references/session-2026-05-18-pc-mobile-search-visual-repair.md (2715b), references/session-2026-05-18-pc-nav-dynamic-menu.md (2082b), references/session-2026-05-18-pc-nav-scope-validation.md (1127b), references/session-2026-05-18-rendered-pc-pagination-fallback.md (3148b), references/session-2026-05-18-skill-library-active-review.md (1132b), references/session-2026-05-18-timeout-recovery-partial-work.md (1876b), references/session-2026-05-18-xz01-skill-autopublish.md (1528b), references/xz01-template-factory-architecture.md (7152b), scripts/xz01-backend-baseline-check.sh (403b), scripts/xz01-full-url-scan.py (4200b), scripts/xz01-hook-gate.py (6560b), scripts/xz01-quick-http-gate.py (2405b), scripts/xz01-runtime-clear.sh (447b), scripts/xz01-screenshot-core.sh (1444b), scripts/xz01-template-static-scan.py (3677b), scripts/xz01-theme-diff-check.sh (621b), skill.json (977b), SKILL.md (71100b)\n\nFile v1.0.43:SKILL.md\n\n---\nname: xz01-dev-skill\ndescription: Use when 用户提到“xz01规范”时必须命中本技能；xz01规范=xz01-dev-skill。用于 Hermes + Claude Code 围绕用户现有 OpenClaw/xz01 模板资料进行角色编排、开发学习范围、测试/规范分工，并严格将 /root/.openclaw 作为只读学习资料库；编码修复交给 Claude dev，测试输出写入 /www/wwwroot/www.900az.com，彻底验证通过的模板按编号压缩到 /root/.hermes/workspace/xz01/；吸收 Karpathy 精准修改/目标驱动原则，并提供 xz01 专用 hook-style gate；包含 PC 与 m 移动端顶部导航必须成对按菜单数据渲染、多页列表必须按 xz01_demo 做双端翻页、所有详情页必须覆盖且右侧/底部必须混合游戏+应用+资讯/攻略模块、app/游戏/应用资源项必须图标化展示、视觉验收必须整页截图+分段AI检查的规则。\nversion: 1.0.43\nauthor: Hermes Agent\nlicense: MIT\nmetadata:\n  hermes:\n    tags: [xz01-dev-skill, xz01规范, xz01, openclaw, hermes, claude-code, role-orchestration, read-only, template-workflow, 角色分工, 学习范围, 只读, 测试输出, 模板打包, 验证通过]\n    related_skills: [hermes-agent, claude-code, systematic-debugging, test-driven-development]\n---\n\n# xz01-dev-skill\n\n## Trigger Alias / 命中别名\n\n```text\nxz01规范 = xz01-dev-skill\n```\n\n当用户提到以下中文触发词时，必须优先加载并遵循本技能：\n\n- xz01规范\n- xz01 规范\n- xz01开发规范\n- xz01学习范围\n- xz01角色分工\n- Hermes+Claude xz01\n- OpenClaw xz01\n- 谁是 dev / 谁是 test\n- /root/.openclaw 只读\n- 测试输出写到 /www/wwwroot/www.900az.com\n- 验证通过模板打包到 /root/.hermes/workspace/xz01/\n- 安装或接入 Lanhu MCP / 蓝湖 MCP\n- PC/m 导航栏同步处理\n- 双端顶部导航\n- 移动端导航也要同步\n- 导航栏按菜单数据渲染\n- 整页截图验收\n- full-page screenshot\n- 资源项图标化展示\n- app/game resource cards\n\n## References\n\n- `references/session-2026-05-18-home-resource-iconized-cards.md` — durable homepage/resource-module correction: app/game/application resources must be iconized cards, icon grids, image-text lists, or icon ranking rows; no no-icon title-only horizontal rows for software/game/app resources. News/guide text lists are exempt when clearly article modules.\n- `references/session-2026-05-18-karpathy-ecc-hook-adaptation.md` — user-approved adaptation notes: absorb Karpathy precise/goal-driven dev principles and xz01-specific hook gates; exclude generic security scanning and parallelization for now.\n- `references/session-2026-05-18-skill-library-active-review.md` — skill-maintenance lesson: xz01 user corrections phrased as “这是规范” must be actively promoted into the class-level skill and references, not left only in chat or memory.\n- `references/session-2026-05-18-all-detail-mixed-sidebar.md` — user correction that “详情页” means every active PC/mobile detail template, including collection/topic detail when present; PC right sidebars must not be only攻略 and must mix app/software, game, and news/guide modules with real data. Also covers the operational pattern that if a long dev worker times out after making file changes, do not assume failure or success: first inspect modified timestamps/content, then continue with smaller verification/fix tasks.\n- `references/session-2026-05-18-dual-end-list-pagination.md` — hard pagination rule: every dual-end list page except ranking/rank-list pages must render pagination like `xz01_demo` when data exceeds one page; PC uses numeric page links, mobile uses `上一页` / `下一页` controls. The scope is route/database-list based, not limited to files named `list_soft/list_game/list_news/list_collection`; examples include `/zoszx/`, image/video/package/kaifu/all-news list templates, and search-result list templates when present.\n- `references/session-2026-05-18-rendered-pc-pagination-fallback.md` — correction after a bad pagination repair: do **not** invent a custom fallback pager or page-count algorithm. xz01 list pagination must follow `xz01_demo`'s `getPcPageData` / `getMobilePageData` → `$page_code` → `{$page_code|raw}` pattern; if rendered pagination is absent, fix the data/template chain to match demo rather than designing a new pager.\n- `references/session-2026-05-18-pagination-demo-copy-correction.md` — session-specific correction: when user says “造搬/照搬 xz01_demo”, treat it as an implementation-shape constraint, not just a visual/functional goal; revert self-designed pagination code and update the skill/spec immediately.\n- `references/session-2026-05-18-pagination-common-data-chain.md` — pagination root-cause correction: `{$page_code|raw}` in the bottom template is not enough; the list template must include the matching `common_data/_list_*_common.html`, and that file must call `getPcPageData` / `getMobilePageData` so `$page_code` is actually generated.\n- `references/session-2026-05-18-pagination-rule-template-repair.md` — workflow correction after the user pointed out that only the rule was updated: when a new xz01 rule identifies an active template defect, update the skill/spec and immediately apply the rule to affected deployed/candidate templates, then clear runtime and verify.\n- `references/session-2026-05-18-timeout-recovery-partial-work.md` — timeout recovery pattern for xz01 delegate workers: inspect authorized workdirs and partial artifacts after timeout, continue from useful landed work with smaller tasks, and never mark timeout as PASS without independent validation.\n- `references/session-2026-05-18-fullpage-visual-qa-correction.md` — user correction after a first-viewport-only PASS missed lower-page layout details: xz01 visual QA must use PC/mobile full-page screenshots, segment/contact-sheet long pages, and inspect lower modules/footer before PASS.\n- `references/session-2026-05-18-mobile-domain-validation-correction.md` — mobile QA correction: do not validate mobile by applying a 390px/mobile UA to `www.900az.com`; use the real `m.900az.com` URL plus mobile UA/CDP metrics, and parameterize validation scripts by URL per case.\n- `references/session-2026-05-18-openclaw-temp-artifact-boundary.md` — boundary correction after a validation worker created a temporary screenshot script under `/root/.openclaw/workspace`: no temporary scripts, screenshots, reports, manifests, logs, or generated artifacts may be written anywhere under `/root/.openclaw`; use `/tmp`, `/www/wwwroot/www.900az.com/test-artifacts`, or `/root/.hermes/workspace/xz01-artifacts` instead.\n- `references/session-2026-05-18-detail-sidebar-bottom-modules.md` — detail-page repair pattern: every active app/game/news/collection detail template must include demo-like right sidebar and bottom data modules using real existing data; validate with source/static checks plus screenshots/AI, require mixed app/software + game + news/guide modules, and watch for PC bottom summary text overflow.\n- `references/session-2026-05-18-dual-end-nav-dynamic-menu.md` — user correction and hard rule: PC and m/mobile top navigation are a paired requirement for every xz01 template set; both must render from existing menu/navigation data, never guessed hardcoded labels or invented links.\n- `references/session-2026-05-18-mobile-layout-overflow-repair.md` — mobile visual QA/repair pattern: use CDP mobile device emulation plus runtime overflow probes for final validation; fix nav as an internal scroller, two-column modules as shrink-safe grids, and list rows with `min-width:0`/ellipsis.\n- `references/session-2026-05-18-pc-nav-dynamic-menu.md` — PC top-navigation repair lesson: render the header nav from existing menu/navigation data (`get_nav_menu` / `$vo.name` / `$vo.href` or equivalent), never from guessed labels or invented links.\n- `references/session-2026-05-18-pc-nav-scope-validation.md` — validation-scope lesson: when fixing PC top navigation, parse the actual nav container and do not conflate similar labels in lower shortcut/keyword modules with the header nav.\n- `references/session-2026-05-18-hermes-native-title-search-repair.md` — direct Hermes xz01 live-site repair lesson: do not call OpenClaw runtime orchestration when the user addresses Hermes; use Hermes-native dev/test delegation, demo read-only reference, shared-head dynamic title repair, theme-only search template fixes, and multi-keyword title validation.\n- `references/session-2026-05-18-hermes-native-no-search-regression.md` — user correction and repair pattern for xz01 live-site regressions when Hermes is addressed directly: do not invoke OpenClaw sessions/flow-controller; use Hermes-native verification/delegation; dual-end search boxes should keep visual styling when shown but must be non-functional by default: no `/search` action/link, no enabled input/submit, and no JS submit binding.\n- `references/session-2026-05-18-xz01-skill-autopublish.md` — user correction that xz01 skill edits are incomplete until version metadata is synchronized and `clawhub publish` is executed without asking for confirmation.\n- `references/session-2026-05-18-pc-mobile-search-visual-repair.md` — live-site search visual repair lesson: PC search must be right/side-aligned and visually weakened rather than top-center; mobile search must be an obvious compact magnifier-style visual-only entry, not merely the absence of a large input; verify 390px mobile card overflow after search/header changes.\n- `references/lanhu-mcp-installation.md` — recommended Docker Compose + HTTP MCP setup for `dsphper/lanhu-mcp`, including Hermes native MCP and Claude Code connection examples.\n- `references/demo-xz01-may-2026-source-update.md` — read-only learning notes from the May 2026 `demo_xz01` source update, including the user-confirmed rule that front-end PC/mobile search is canceled/weakened and should not be a default QA failure.\n- `references/xz01-template-factory-architecture.md` — architecture notes for upgrading the current main/dev/test/rule loop into a 60-template dual-end xz01 automation factory with corpus ingestion, DB/route learning, planning, rendering, validation, repair loops, rule review, and packaging.\n- `references/hermes-native-xz01-first-run.md` — first-run pattern for building a safe Hermes-native xz01 prototype under `/root/.hermes/workspace/xz01-factory`, including minimal output shape, static validation checklist, and prototype-vs-production boundary.\n- `references/hermes-native-xz01-live-deploy-validation.md` — live temporary deployment pattern for `/www/wwwroot/www.900az.com/public/themes/default/`, including backup, cache clearing, HTTP/PHP/static/browser/AI validation, fallback data blocks, trace-overlay hiding, and screenshot artifact paths.\n- `references/run-0002-visual-repair.md` — session-specific repair notes for making a temporary xz01 homepage more demo-like after AI visual review: PC density/card-count fixes, topic-background cleanup, desktop-vs-mobile-UA validation, true 390px mobile screenshots, right-side alignment/overflow probes, long mobile screenshots for lower modules, and viewport clipping remedies.\n- `references/session-2026-05-16-main-role-boundary-correction.md` — user correction that xz01 coding/HTML/CSS/template fixes must be delegated to Claude Code dev even when the fix is small or obvious; main must not directly patch implementation files.\n- `references/session-2026-05-16-pc-gap-dev-test-rule-loop.md` — concrete example of handling a small PC quick-topic spacing defect through Claude dev → independent test screenshot/AI review → rule audit, including constrained dev prompt shape and test acceptance criteria.\n- `references/session-2026-05-16-right-sidebar-height-balance.md` — follow-up lesson from repeated PC gap corrections: if a lower section is pushed down by a taller right sidebar, reduce right-side content height (e.g. `专题推荐` 4→3) instead of only compressing margins.\n- `references/session-2026-05-16-packaging-gate-runtime-list-detail.md` — user correction after an invalid package: every dev change must clear `/www/wwwroot/www.900az.com/runtime/` before validation, and packaging is forbidden until homepage/list/detail rendering, jQuery, trailing-slash links, data images, and dynamic data gates all pass.\n- `references/session-2026-05-16-no-php-controller-template-dev.md` — user correction that xz01 template development must never modify PHP/backend/controller/model/config files; dev scope is theme templates/assets only unless the user explicitly authorizes a non-template backend task.\n- `references/session-2026-05-16-theme-only-data-links-search.md` — theme-only repair notes after backend restoration: restore data with existing template tags, make slash-ending column links absolute with the correct PC/mobile host, avoid double-prefix domains, keep PC search out of the top center, fix missing detail templates in the theme, and keep test artifacts out of `/root/.openclaw`.\n- `references/session-2026-05-16-max-turns-task-splitting-validation-scripts.md` — user correction for repeated `max_turns` and long-running tasks: do not raise max-turns, split work to minimum units, use fixed validation scripts, do not enable the no-re-exploration rule for now, time-box dev/test tasks, use Claude interactive/tmux only as a supervised workbench for a sequence of small tasks, and prioritize stability with a single serial queue unless the user explicitly re-enables concurrency.\n- `references/session-2026-05-16-demo-xz01-systematic-validation.md` — user correction that `demo_xz01` must be learned systematically: dual-end list/detail templates must exist and render, pagination variables/data rendering must follow demo patterns, runtime cache must be cleared after every dev change, PC+mobile static/HTTP/browser/screenshot/AI gates are mandatory before packaging, and the validation scripts are part of this skill.\n- `references/session-2026-05-16-allpage-visual-qa-and-scanner-fixes.md` — follow-up validation lesson: when the user asks for all-page dual-end screenshots and AI review, capture every crawled URL, create URL→screenshot manifests and contact sheets for AI review, retry screenshot timeouts, and avoid false `0款` scanner matches such as `10款`. Treat DB-backed labels like “手游下载” as wording observations rather than automatic failures when the route and data are valid.\n- `references/session-2026-05-16-db-channel-name-display-standard.md` — user correction that xz01 PC/mobile category/list display names must use `cmf_cms_channel.name` from the database row for the current alias; e.g. alias `gzos` must display `手游下载` because the DB channel name is `手游下载`.\n\n## Overview\n\nThis skill is for operating a Hermes + Claude Code workflow around the user's existing OpenClaw/xz01 material. The existing OpenClaw tree is a **read-only learning corpus**, not a place to write configs, skills, memory, cron state, sessions, templates, or generated reports unless the user explicitly authorizes a specific write.\n\nAuthoritative read-only boundary:\n\n```text\n/root/.openclaw/ and every subdirectory = read-only learning material\n```\n\nDefault runtime division:\n\n```text\nHermes current session = main / dispatcher / final reporter\nClaude Code = dev / implementation worker\nHermes independent test role = test / validation worker\nHermes independent rule role = rule / process and standard reviewer\n```\n\nRecent correction status:\n\n```text\nDual-end top navigation is mandatory for every xz01 template set: PC and m/mobile nav must be checked and fixed together, using existing menu/navigation data on both ends.\nFor any dual-end list page where the data volume is greater than one page, pagination is mandatory: PC uses numeric page links; mobile uses 上一页/下一页, matching xz01_demo.\nWhen a new xz01 rule describes a current live/candidate template defect, the response must not stop at updating the skill/spec; apply the rule to the affected templates immediately, then clear runtime and verify.\n```\n\nSkill-maintenance lesson from this session:\n\n```text\nWhen the user states a new xz01 rule as “这是规范”, treat it as a durable skill update immediately: add/patch the class-level SKILL.md, create or update a concise references/session-*.md detail file if useful, synchronize skill.json/_meta.json versions, and publish the updated skill. Do not leave the rule only in chat or memory.\n```\n\n## When to Use\n\nUse this skill when the user asks about:\n\n- “xz01规范”\n- “xz01 规范”\n- “xz01-dev-skill”\n- “Hermes 和 Claude 怎么分工”\n- “谁是 dev，谁是 test”\n- “OpenClaw 的学习范围”\n- “/root/.openclaw 只读”\n- “把这个流程做成 skill”\n- “持续优化技能”\n- Hermes + Claude role division for OpenClaw/xz01-style work\n- what each role should learn from `/root/.openclaw`\n- turning OpenClaw process rules into Hermes skills\n- coordinating template development, validation, and rule review without modifying OpenClaw's existing files\n- preserving dev/test/rule separation while using Claude Code for implementation\n\nDo **not** use this skill to modify `/root/.openclaw` files. Treat them as reference-only.\n\n## Non-Negotiable Boundary\n\nAll roles must obey:\n\n```text\nDo not write to /root/.openclaw/\nDo not create temporary scripts under /root/.openclaw/\nDo not create screenshots, reports, manifests, logs, lock files, downloads, or generated artifacts under /root/.openclaw/\nDo not patch /root/.openclaw/\nDo not update /root/.openclaw/openclaw.json\nDo not modify /root/.openclaw/workspace/*\nDo not modify /root/.openclaw/agents/*\nDo not modify /root/.openclaw/cron/*\nDo not modify /root/.openclaw/memory/*\nDo not modify /root/.openclaw/flows/*\nDo not modify /root/.openclaw/workspace/demo_xz01\n```\n\nAllowed operations on `/root/.openclaw`:\n\n- read targeted files\n- inventory directories\n- summarize rules\n- learn conventions\n- compare reports against known standards\n\nTemplate-development backend boundary:\n\n```text\nFor xz01 template development, NEVER modify PHP/backend/controller/model/config files.\nForbidden paths include: application/**/*.php, config/**/*.php, route/**/*.php, thinkphp/**/*.php, vendor/**/*.php, and any controller/model/service/backend PHP file.\nAllowed template scope by default: public/themes/<theme>/** only (HTML templates, CSS, JS, theme assets).\nIf required data/routes are unavailable through existing backend/template tags, report the limitation; do not patch PHP to make a template pass.\nAny package created after PHP/controller/config changes is invalid until those backend changes are reverted and the template is revalidated with theme-only changes.\n```\n\nIf writes are required, write only to:\n\n- Hermes skill storage (`~/.hermes/skills/...`) when creating/updating Hermes skills\n- a user-authorized non-OpenClaw project directory\n- `/www/wwwroot/www.900az.com` for all test-side outputs, validation artifacts, screenshots, reports, and website verification outputs unless the user explicitly changes it\n- `/root/.hermes/workspace/xz01/` for numbered zip packages of templates that have fully passed verification\n- `/tmp/...` for short-lived helper scripts and scratch files; never put temporary helpers under `/root/.openclaw`\n- another explicit path the user names\n\nPackaging rule for verified templates:\n\n```text\nOnly templates that are thoroughly verified as passed may be packed.\nPackage verified templates as numbered compressed archives under /root/.hermes/workspace/xz01/.\nDo not store final verified template packages under /root/.openclaw/.\n\nHard packaging gate:\n\n- After every add/modify/delete development change, delete all directories/items under `/www/wwwroot/www.900az.com/runtime/` before validation.\n- Do not package until PC/mobile homepage, software/game/news/category list pages and detail pages are generated/available and render correctly from existing database routes; list/detail pages must not be merely referenced or assumed. Any dual-end list page with more than one page of data must include pagination: PC numeric page links and mobile `上一页` / `下一页`, matching `xz01_demo`.\n- Do not package if rendered pages contain missing header/head jQuery loading, no-slash column URLs, malformed duplicate-host absolute URLs, `cms/page/index/id` / `cms/Page/index` / `mobile/Page/index` errors, prohibited filler SVG data images, mostly `暂无...数据` placeholders, or zero real content/detail links while DB records exist.\n- For every rendered column/category URL whose path ends with `/`, output an absolute URL with protocol and the correct host: PC uses `https://www.900az.com/.../`, mobile uses `https://m.900az.com/.../`. Normalize helper output first so an already-absolute URL is not prefixed again.\n- PC header/search layout gate: the PC search box must never be placed at the top center of the header. Use a right-side, below-header, or otherwise non-center placement. Mobile is evaluated separately.\n- Dual-end top-navigation gate: for every xz01 template set, PC and m/mobile top navigation must be checked/fixed together and rendered from existing menu/navigation data. A header-navigation task is incomplete if either side still uses guessed hardcoded labels or invented links.\n```\n\n## Role Map\n\n| Role | Default assignee | Purpose | May write `/root/.openclaw`? |\n|---|---|---|---:|\n| main | Hermes current session | receive requests, split work, dispatch, supervise, final report | No |\n| dev | Claude Code | implement code/template changes in authorized workdir | No |\n| test | independent Hermes test role/session | screenshots, AI visual analysis, lint/HTML/CSS/template validation | No |\n| rule | independent Hermes rule role/session | process audit, rule review, skill/spec suggestions | No |\n\n## Main Role Learning Scope\n\nMain learns coordination and boundaries, not implementation.\n\nRead-only sources:\n\n- `/root/.openclaw/workspace/IRON_RULES.md`\n- `/root/.openclaw/workspace/AGENTS.md`\n- `/root/.openclaw/workspace/MEMORY.md`\n- `/root/.openclaw/workspace/error.md`\n- `/root/.openclaw/workspace/DREAMS.md`\n- `/root/.openclaw/workspace/scripts/flow-controller.js`\n- `/root/.openclaw/workspace/scripts/check-flow-stuck.js`\n- `/root/.openclaw/workspace/scripts/violation-tracker.js`\n- `/root/.openclaw/openclaw.json`\n- `/root/.openclaw/cron/jobs.json`\n- `/root/.openclaw/agents/*/sessions` only when targeted history/debug context is needed\n- `/root/.openclaw/memory/*.sqlite` only when targeted memory inspection is explicitly needed\n\nMain must learn:\n\n1. role boundaries\n2. flow sequence: main → dev → test → rule → main\n3. when to dispatch to each role\n4. how to avoid dev/test/rule collapse\n5. report format expectations\n6. historical violations and user corrections\n7. that `/root/.openclaw` is read-only\n\nMain must not:\n\n- write code\n- test/screenshot\n- modify CSS/templates\n- modify PHP/backend/controller/model/config files for template development\n- update OpenClaw configs\n- silently skip test or rule\n\n## Dev Role Learning Scope\n\nDev is Claude Code by default. Dev learns implementation standards and writes only in an authorized non-OpenClaw workdir.\n\nRead-only sources:\n\n- `/root/.openclaw/workspace/IRON_RULES.md`\n- `/root/.openclaw/workspace/AGENTS.md`\n- `/root/.openclaw/workspace/TEMPLATE-SPEC.md`\n- `/root/.openclaw/workspace-dev/MEMORY.md`\n- `/root/.openclaw/workspace-dev/skills`\n- `/root/.openclaw/workspace-dev/memory`\n- `/root/.openclaw/workspace/demo_xz01`\n- `/root/.openclaw/workspace/memory/team/project` targeted template-development notes\n\nDev must learn:\n\n1. ThinkPHP template structure\n2. PC/mobile dual-template structure\n3. common module organization\n4. HTML/CSS/JS conventions\n5. template tag closure rules (`include`, `foreach`, `if`)\n6. data filters such as `is_hide=0` and `status=1`\n7. search/navigation/carousel/data rendering conventions, with updated `demo_xz01` nuance and user correction: front-end PC/mobile search should render the search-box visual style when the template design includes that header/search area, but must not render functional search behavior by default. Use disabled/non-submitting visual-only controls: no `/search` link/action, no enabled input, no submit, no JS submit binding. Do not require a working dual-end search feature unless the user explicitly requests functional search. For visual placement, PC search must not sit in the page/header center; keep it right-aligned, side-aligned, below-header, or otherwise clearly non-center and visually weakened. Mobile search must be a compact magnifier/icon-style entry when shown; removing the large input is not enough if no small search entry is visible.\n8. Dual-end top-navigation rendering rule (mandatory for every xz01 template set): PC and m/mobile header/top navigation are a paired requirement and must be checked/fixed together. Both ends must come from existing menu/navigation data such as PC `get_nav_menu(1,0,['list_order'=>'asc'],0,333)` and mobile `get_nav_menu(1,0,['list_order'=>'asc'],0,3333)` with `$vo.name` and `$vo.href` (or an equivalent existing menu source); mobile hrefs must use the mobile host, e.g. by replacing `www.` with `m.` when the helper returns PC URLs. Do not hardcode guessed labels like “热门排行/装机必备/专题合集” or mobile shorthand labels like “软件/排行/必备/资讯” unless they are the exact menu data output; do not invent hrefs just because they open. Preserve each active template's outer nav classes while keeping labels/links data-driven.\n9. route rule: database routes are authoritative; do not invent routes from template filenames\n10. database channel display rule: category/list page labels, headings, breadcrumbs, and related front-end display names must use `cmf_cms_channel.name` for the current database alias on both PC and mobile. The alias/path (e.g. `gzos`) is not the display label; if the DB row has `name='手游下载'`, PC `/gzos/` and mobile `m.900az.com/gzos/` must display `手游下载` consistently. Do not normalize to guessed labels unless explicitly requested.\n11. demo_xz01 is a pattern library, not editable and not copy-paste source\n12. updated template-structure nuance: some newer templates remove `zyxz_module` entirely or inline sidebar/recommendation blocks instead of using fixed `_side_*.html` partials; preserve the specific template's structure instead of forcing old module inventories\n13. demo_xz01 systematic rendering and pagination rules: every xz01 template must implement complete PC+mobile homepage/list/detail coverage for existing DB routes. Except for ranking/rank-list pages, every dual-end database-backed list page whose data volume exceeds one page must render pagination like `xz01_demo`: PC uses numeric page links/page-code style pagination; mobile uses simple `上一页` / `下一页` controls. Scope is based on actual database routes and rendered list pages, not only files named `list_soft/list_game/list_news/list_collection`; include software/game/news/category, collection/topic, image, video, package/gift, kaifu, all-news, and search-result list templates when present. The implementation must copy/align with demo's full pagination chain: the list template includes the matching `common_data/_list_*_common.html`, that common data file calls `getPcPageData` / `getMobilePageData` for the main list, those helpers generate `$page_code`, and templates output `{$page_code|raw}` or an explicitly confirmed demo-equivalent partial. Do not modify PHP/controllers/routes to fake pagination, do not rely on `getAllData()` for the main paginated list, and do not invent custom page-count/request-parameter/fallback pager algorithms in the theme.\n14. app/game/application resource-card rule: every app/game/application resource item on homepage, list pages, sidebars, recommendation modules, latest-resource modules, ranking modules, and detail-page related-resource modules must render with an icon/thumbnail/cover plus title and metadata/action in a card, icon grid, or image-text list. It is forbidden to display app/game/application resources as text-only horizontal title rows inside a module. Article/news/guide text lists may remain text-only, but software/game/app resources may not.\n15. resource loading rules: do not use `/themes/default/common_cms/common/jquery.min.js`; load jQuery from the correct PC/mobile asset path. Include UIkit and Swiper only when needed, using the correct PC/mobile asset CSS+JS pair.\n\nDev must not:\n\n- read Feishu group messages\n- self-certify final acceptance\n- skip test\n- write `/root/.openclaw`\n- modify `demo_xz01`\n- modify PHP/backend/controller/model/config files for template development (`application/**/*.php`, `config/**/*.php`, routes, ThinkPHP core, vendor, backend services). Template tasks are limited to `public/themes/<theme>/**` unless the user explicitly authorizes a non-template backend task.\n- perform official screenshot/AI visual validation\n\nDev output should include:\n\n- changed file list in authorized workdir\n- implementation summary\n- self-check notes\n- items for test to validate\n\n## Test Role Learning Scope\n\nTest is an independent Hermes role/session. It validates; it does not fix.\n\nRead-only sources:\n\n- `/root/.openclaw/workspace/IRON_RULES.md`\n- `/root/.openclaw/workspace/AGENTS.md`\n- `/root/.openclaw/workspace/TEMPLATE-SPEC.md`\n- `/root/.openclaw/workspace-test/MEMORY.md`\n- `/root/.openclaw/workspace-test/skills`\n- `/root/.openclaw/workspace-test/scripts`\n- `/root/.openclaw/workspace-test/skills/template-qa/scripts`\n- `/root/.openclaw/workspace/demo_xz01`\n- `/root/.openclaw/workspace/memory/team/project` targeted testing/screenshot/AI-vision notes\n\nTest must learn:\n\n1. PC screenshot requirements\n2. mobile screenshot requirements\n3. AI visual analysis requirement after screenshots\n4. layout/overlap/missing-element/color/font/responsive checks\n5. HTML tag closure checks\n6. CSS path/layout checks\n7. ThinkPHP template tag checks\n8. search/navigation/carousel/data rendering checks, with updated `demo_xz01` nuance and user correction: a PC/mobile search-box visual shell may be present when required by the template design, but it must be visual-only unless the user explicitly requests functional search. Fail search if it has `/search` links/actions, enabled keyword input, enabled submit buttons, form submission, JS submit binding, or any clickable/searchable behavior; do not fail merely because a disabled visual search box is displayed\n9. dual-end list pagination checks: for representative software/app, game, news/guide, category/channel, and equivalent database-backed list routes where data volume exceeds one page, PC must show numeric page links and mobile must show `上一页` / `下一页`; absence of pagination on a multi-page list is a FAIL even when the first page data renders correctly. Static template evidence is only a pre-check: test must verify the full `xz01_demo` pagination chain, not just the bottom output tag: list template includes matching `common_data/_list_*_common.html`, common data calls `getPcPageData` / `getMobilePageData` for the main list, helpers generate `$page_code`, and the template outputs `{$page_code|raw}`. If rendered HTML shows an empty `<ul class=\"pagination\"></ul>`, fail it as a missing upstream data-chain issue; do not ask dev to add a self-designed fallback pager.\n10. app/game/application resource rendering checks: inspect homepage/list/detail/side/recommend/latest/rank modules and fail any app/game/application resource displayed as a text-only horizontal title row without icon/thumbnail/cover. News/article/guide text lists are exempt only when they are clearly not app/game/application resources.\n11. regression testing; do not only check the last fix\n12. full issue report format\n13. full-page screenshot acceptance rule: for homepage/page visual QA, PC and mobile screenshots must capture the whole page, not only the first viewport. First-viewport screenshots may be used only as supplemental evidence. A visual PASS is forbidden unless the full page has been captured, split/contact-sheeted when long, submitted to AI visual review, and lower modules/footer/detail areas have been checked for layout, spacing, overflow, clipping, and missing/overlapping elements.\n\nTest must not:\n\n- write implementation code\n- fix issues directly\n- read Feishu group messages\n- write `/root/.openclaw`\n- claim visual correctness without full-page screenshots + AI visual analysis for homepage/page visual QA\n\nTest output should include:\n\n- PC full-page screenshot paths under `/www/wwwroot/www.900az.com` or mirrored under `/root/.hermes/workspace/...` for WebUI media\n- mobile full-page screenshot paths under `/www/wwwroot/www.900az.com` or mirrored under `/root/.hermes/workspace/...` for WebUI media\n- long-page segment/contact-sheet paths when a full-page screenshot is too tall for reliable visual review\n- AI visual analysis findings saved/reported from the test output area\n- structural/lint findings\n- functional findings\n- pass/fail conclusion\n- issue list for dev when failed\n\nAll test-side artifacts must be written under `/www/wwwroot/www.900az.com` unless the user explicitly changes the output location.\n\n## Rule Role Learning Scope\n\nRule is an independent Hermes role/session. It audits workflow and proposes/maintains durable rules. Under the read-only boundary, it must not update OpenClaw files unless explicitly authorized.\n\nRead-only sources:\n\n- `/root/.openclaw/workspace/IRON_RULES.md`\n- `/root/.openclaw/workspace/AGENTS.md`\n- `/root/.openclaw/workspace/TEMPLATE-SPEC.md`\n- `/root/.openclaw/workspace-rule/MEMORY.md`\n- `/root/.openclaw/workspace-rule/skills`\n- `/root/.openclaw/workspace-rule/memory`\n- `/root/.openclaw/workspace/skills`\n- `/root/.openclaw/workspace/memory/team/project`\n- `/root/.openclaw/workspace/memory/violations`\n- `/root/.openclaw/workspace/error.md`\n\nRule must learn:\n\n1. role-boundary violations to prevent\n2. process-completion requirements\n3. when a lesson should become a skill\n4. when a lesson should remain a report, not memory/skill\n5. skill metadata/version/documentation conventions\n6. cron-log noise restrictions\n7. user-specific hard rules\n\nRule must not:\n\n- implement code\n- test/screenshot\n- write `/root/.openclaw`\n- publish OpenClaw skills or edit OpenClaw specs without explicit authorization\n\nRule output should include:\n\n- compliance audit\n- whether the flow skipped steps\n- whether new durable guidance is needed\n- proposed skill/spec text if needed\n- where it should be saved, subject to authorization\n\n## Visual Repair Loop for xz01 Homepage Runs\n\nWhen the user says to “继续” after a first xz01 prototype or says the page is not close enough to `xz01_demo`, do not stop at a functional page. Run an AI-vision-driven repair loop until the visible defects are fixed.\n\nWorkflow:\n\n1. Compare against the `demo_xz01` target as a high-density download-station portal, not a sparse landing page.\n2. Patch PC/mobile templates and CSS in the authorized run directory and the temporary deployment copy when already deployed.\n3. Clear all directories/items under `/www/wwwroot/www.900az.com/runtime/` after every add/modify/delete development change and before any validation. Do this before rendering screenshots or HTTP checks so stale ThinkPHP cache cannot hide template/controller changes.\n4. Validate HTTP 200, compiled PHP syntax, mobile no `target=\"_blank\"`, and screenshots.\n   - PC validation uses the desktop domain/access path: `https://www.900az.com/` with a desktop UA.\n   - Mobile validation must use the mobile domain/access path: `https://m.900az.com/` with a real Android/iPhone Mobile User-Agent. Do not validate `m.900az.com` using the same desktop/PC browser access method as PC.\n5. Submit PC and true small-width mobile-UA full-page screenshots to AI vision; if the page is long, also create segment images/contact sheets and ask AI to inspect the whole page. Treat AI findings as actionable repair items.\n6. For mobile visual/layout defects, final acceptance must use the real mobile domain (`https://m.900az.com/...`), Chrome DevTools Protocol mobile emulation (`mobile:true`), real iPhone/Android UA, widths such as 360/390/430, and runtime overflow probes (`documentElement.scrollWidth/clientWidth`, `body.scrollWidth`, and bounding boxes). Ordinary headless `--window-size` screenshots are useful for discovery but are not authoritative if they contradict CDP mobile-mode metrics. A 390px/mobile-UA check against `https://www.900az.com/...` is PC-domain responsive testing, not mobile-site validation, unless the user explicitly asks for the PC domain to be phone-responsive. Intentional internal nav scrolling is acceptable only when page-level `scrollWidth` still equals `clientWidth`.\n7. If the user reports right-side alignment issues, inspect both PC and mobile with the correct UA/domain pair, run an overflow probe on PC, capture a long mobile screenshot for lower modules, patch the run/deploy CSS, and re-check until AI vision passes.\n8. Re-patch and re-check until AI confirms pass.\n\nCommon repairs from run-0002:\n\n- PC hot games/apps need enough fallback cards to fill the grid; 3-4 cards create obvious blank areas.\n- Topic-card decorative background text should be low-opacity and not compete with foreground titles.\n- To match `xz01_demo`, reduce excessive modern-card spacing and increase list/module density.\n- Mobile default browser snapshots may hide real phone-width clipping; validate mobile with real Android/iPhone UA against `https://m.900az.com/` and with DevTools mobile emulation at multiple CSS widths such as 390px and 430px.\n- If a template includes a mobile back-to-top control, verify it with real Mobile UA + 390px screenshot: the button should be visible when required, must not cover download buttons or core content, and tapping/clicking after scroll should return the page to the top.\n- Do not reuse the desktop/PC access method for mobile verification; mobile-domain validation requires a mobile UA header.\n- If a 390px screenshot shows left blank strip, right card clipping, or right-side misalignment, fix container/grid width, not just `overflow-x:hidden`.\n- For mobile two-column modules such as `每日推荐`, `攻略` category cards, and `精选专辑`, use shrink-safe grids (`repeat(2,minmax(0,1fr))`) and ensure child cards/text use `min-width:0`, `max-width:100%`, and ellipsis where needed.\n- For dynamic mobile top navigation with more items than fit the viewport, use an intentional internal horizontal scroller (`overflow-x:auto`, `flex:0 0 auto`, no body-level overflow) rather than squeezing all items into one row or hiding overflow.\n- If a mobile back-to-top (`顶`) button visually crowds or overlaps content, prefer a non-intrusive document-flow placement near the page bottom with safe-area spacing over a fixed floating overlay.\n- Do not fix mobile containers to `max-width:390px`; it can pass a 390px screenshot but leave a blank strip on wider real phones. Under phone breakpoints prefer `width:100%; max-width:100%` plus safe padding/grid rules, then verify both 390px and 430px.\n- For right-side alignment defects, verify PC and mobile separately: PC with desktop UA on `www.900az.com`, mobile with real Android/iPhone UA on `m.900az.com`; do not share access mode.\n- For PC right-sidebar drift, probe `documentElement.scrollWidth` and overflowing elements, then unify `.xz-wrap`, hero grid, sidebar, lower sections, and card grids to the same right boundary.\n- For homepage/page visual acceptance, never use only a first-viewport screenshot as PASS evidence. Capture full-page PC and mobile screenshots; for long pages, split/contact-sheet them so lower modules such as 热门应用 / 攻略 / 精选专辑 and the footer are explicitly inspected.\n\nDetailed notes: `references/run-0002-visual-repair.md`.\n\n## Lanhu MCP Integration\n\nFor xz01 work that needs Lanhu requirements/designs, the Lanhu MCP service is installed and managed outside `/root/.openclaw`:\n\n- Session note: see `references/lanhu-mcp-discovery-notes.md` for the currently exposed tools and the no-account-wide-project-list limitation.\n\n```text\nInstall path: /root/.hermes/workspace/lanhu-mcp\nDocker container: lanhu_mcp_service\nHTTP MCP endpoint: http://127.0.0.1:8000/mcp?role=Developer&name=HermesMain\nHermes MCP server name: lanhu\n```\n\nOperational rules:\n\n- Use Docker Compose from `/root/.hermes/workspace/lanhu-mcp` to manage the service.\n- Keep Lanhu credentials in `/root/.hermes/workspace/lanhu-mcp/.env`; do not write them to `/root/.openclaw`.\n- Hermes native MCP connects through `mcp_servers.lanhu` in `/root/.hermes/config.yaml`.\n- After MCP config changes, start a fresh Hermes session or restart the relevant Hermes process so discovered MCP tools are loaded.\n- If external downloads are needed, use the user's temporary proxy:\n\n```bash\nexport http_proxy=http://192.168.1.9:1080\nexport https_proxy=http://192.168.1.9:1080\nexport all_proxy=socks5://192.168.1.9:1080\n```\n\nVerification commands:\n\n```bash\ncd /root/.hermes/workspace/lanhu-mcp\ndocker compose ps\ncurl -fsS http://127.0.0.1:8000/health\nhermes mcp test lanhu\n```\n\nDiscovered Lanhu tools include page analysis, design analysis, slice extraction, team messages, and member listing.\n\n## Hermes-Native Orchestration Boundary\n\nDo not port OpenClaw-only runtime mechanisms into Hermes workflow design.\n\nWhen the user directly addresses Hermes for an xz01 live-site/template issue, use Hermes-native execution immediately. Do **not** call OpenClaw `sessions_send`, `flow-controller`, role sessions, or other OpenClaw runtime orchestration unless the user explicitly asks to operate OpenClaw itself. OpenClaw files may still be read as reference material under the read-only boundary.\n\nOpenClaw-specific concepts such as `sessions_send(sessionKey: agent:dev:main, ...)`, `/root/.openclaw/agents/*/sessions`, and the OpenClaw `flow-controller.js` state machine are read-only legacy/reference material for this workflow. They must not be treated as Hermes-native execution primitives.\n\nIf the user addresses Hermes directly about an xz01 live-site/front-end regression, do **not** call OpenClaw role sessions, OpenClaw `flow-controller`, or OpenClaw dispatch as the first response. Use Hermes-native tools/workers (`delegate_task`, deterministic scans, browser/curl verification, and theme-only edits where authorized by the task). OpenClaw orchestration may be studied as reference, but it is not the active execution path unless the user explicitly asks for OpenClaw.\n\nHermes-native replacements:\n\n| OpenClaw concept | Hermes-native replacement | Use case |\n|---|---|---|\n| `sessions_send` to dev/test/rule sessions | `delegate_task` | Short synchronous subtasks; parent waits for result |\n| Persistent role sessions | Hermes profiles + `hermes kanban` | Durable multi-worker queues and role separation |\n| `flow-controller.js` single JSON state | Kanban board / factory SQLite queue | Multi-task durable workflow state |\n| OpenClaw cron progress monitor | Hermes `cronjob` / `hermes cron` | Scheduled watchdogs and periodic reports |\n| Manual subprocess role agents | `terminal(background=True)` or tmux-spawned `hermes` / `claude` | Long-running autonomous workers |\n| Feishu-only role routing | Hermes gateway / WebUI / kanban notifications | User-facing delivery and status updates |\n\nFor xz01 automation, prefer a Hermes-native design:\n\n```text\nHermes main/orchestrator\n  -> xz01-factory queue/SQLite/Kanban task\n  -> dev worker: Claude Code or Hermes profile for implementation\n  -> renderer/test worker: deterministic scripts + independent Hermes/vision validation\n  -> rule worker: Hermes profile or main-side review task\n  -> packaging/reporting\n```\n\nRules:\n\n1. Do not claim Hermes supports OpenClaw `sessions_send` unless an explicit OpenClaw compatibility bridge is installed and verified.\n2. Do not design new Hermes workflows around `/root/.openclaw` writable state.\n3. Use OpenClaw files only as learning/reference material.\n4. Use Hermes `delegate_task` for quick isolated checks, `hermes kanban` for durable multi-agent work, and deterministic scripts/SQLite queues for production xz01 factory state.\n5. For long-running dev/test agents, spawn explicit `hermes` or `claude` processes via `terminal(background=True)`/tmux, or use Kanban dispatcher profiles.\n6. When the user asks whether to keep noting caveats or directly build the first xz01 prototype, choose a safe action: create a Hermes factory run under `/root/.hermes/workspace/xz01-factory`, generate a prototype without touching production, run deterministic static validation, then report remaining production-validation steps. See `references/hermes-native-xz01-first-run.md`.\n\n\n## Karpathy-Style Dev Execution Principles\n\nThe following principles are absorbed from the Andrej Karpathy Claude Code guidance and adapted to xz01. They are subordinate to xz01 hard rules but should be included in dev prompts and reviews:\n\n1. **Think before editing, but do not over-ask.** State the execution assumption only when it affects boundaries such as production writes, backend/PHP changes, or route creation. For normal xz01 defects, proceed through dev → test → rule without asking the user.\n2. **Keep implementation simple.** Do not add unrequested abstractions, helpers, framework layers, or broad JavaScript systems for template work.\n3. **Make precise edits only.** Every changed line must map to the current xz01 acceptance target. Do not improve neighboring code, reformat unrelated files, remove pre-existing dead code, or change global structure unless required by the task.\n4. **Define success criteria before dev starts.** Main's dev prompt should include: target page/component/defect, allowed files, forbidden files, runtime-clear requirement, and test acceptance criteria.\n5. **Verify against the goal, not against dev's confidence.** Dev self-check is only a handoff note; official pass requires independent test screenshots + AI visual review + rule review where applicable.\n\n## xz01 Hook-Style Gate Policy\n\nHooks **can** be part of this skill, but only as xz01-specific guardrails. Do not copy the generic Everything Claude Code hook system into xz01 wholesale.\n\nUser-specific exclusions:\n\n```text\nNo generic security scanning requirement for xz01.\nNo parallelization/multi-agent expansion unless the user explicitly re-enables it.\nNo automatic hook that writes to /root/.openclaw.\nNo hook may replace independent test screenshots + AI visual review.\n```\n\nAllowed xz01 hook-style gates:\n\n| Gate | Purpose | Blocking conditions |\n|---|---|---|\n| pre-dev | stop illegal implementation scope before editing | `/root/.openclaw` write, `demo_xz01` edit, PHP/backend/controller/model/config/route/core/vendor edit |\n| post-dev | ensure development handoff is testable | changed files outside theme without explicit authorization; runtime not cleared after add/modify/delete |\n| pre-test | prevent stale-cache validation | runtime not cleared |\n| post-test | prevent false PASS | missing PC screenshot, missing mobile screenshot, missing AI visual analysis |\n| pre-package | prevent invalid packages | static/HTTP/screenshot/AI/rule gates missing, source not an already-validated `public/themes/<theme>` directory |\n\nA reusable script is bundled at:\n\n```bash\n/root/.hermes/skills/devops/xz01-dev-skill/scripts/xz01-hook-gate.py\n```\n\nExample usage:\n\n```bash\n# Before/after dev handoff\npython3 scripts/xz01-hook-gate.py pre-dev --changed-files /www/wwwroot/www.900az.com/public/themes/default/pc/index.html\npython3 scripts/xz01-hook-gate.py post-dev --changed-files /www/wwwroot/www.900az.com/public/themes/default/pc/index.html --runtime-cleared\n\n# Before/after test\npython3 scripts/xz01-hook-gate.py pre-test --runtime-cleared\npython3 scripts/xz01-hook-gate.py post-test --pc-screenshot --mobile-screenshot --ai-pass\n\n# Before package\npython3 scripts/xz01-hook-gate.py pre-package \\\n  --theme-dir /www/wwwroot/www.900az.com/public/themes/default \\\n  --static-pass --http-pass --screenshot-pass --ai-pass --rule-pass\n```\n\nThese gates may later be wired into Claude Code hooks, Hermes profiles, Kanban workers, or cron watchdogs. Wiring is optional; the policy and script are part of the skill so every xz01 run can use the same guard semantics.\n\n## Execution Time Control and Task Splitting\n\nUser-specific rules for xz01 work after repeated `max_turns` interruptions and one task exceeding 50 minutes:\n\n```text\nDo not solve this by increasing Claude Code max-turns.\nSplit all work into the smallest practical units.\nUse fixed validation scripts.\nDo not enable a hard \"禁止重新探索\" / no-re-exploration rule for now.\nStability first: do not use concurrency for xz01 template execution unless the user explicitly re-enables it.\nAvoid long-running single tasks; time-box dev/test calls and split earlier.\n```\n\nOperational rules:\n\n1. Main must split work before dispatch. A dev task should normally cover one page, one component, or one defect class only. If a worker times out, inspect partial outputs first and then split the remaining work into a smaller follow-up; do not simply resend the original large prompt.\n2. Execute xz01 template work through a strict serial queue: exactly one active dev task, one active test task, and one active rule review at a time. No parallel dev/test/rule lanes unless the user explicitly changes this rule.\n3. Do not bundle development + broad exploration + screenshot/AI visual + full regression + packaging into a single dev task.\n3. Dev should not perform official screenshots or full regression; test owns those.\n4. Use fixed validation scripts under `/root/.hermes/workspace/xz01-factory/tools/` whenever applicable, or the embedded skill copies under `scripts/` when installing/reusing this skill:\n   - `xz01-runtime-clear.sh` — clear `/www/wwwroot/www.900az.com/runtime/` after every add/modify/delete and before validation.\n   - `xz01-backend-baseline-check.sh` — verify PHP/backend/controller/model/config scope was not modified for a template task.\n   - `xz01-theme-diff-check.sh` — inspect theme-only change boundaries.\n   - `xz01-quick-http-gate.py` — quick HTTP checks for key PC/mobile URLs.\n   - `xz01-template-static-scan.py` — scan template code for PC/mobile core template completeness, bad jQuery/UI resource paths, pagination-pattern gaps, malformed links, mobile `target=\"_blank\"`, and forbidden filler assets.\n   - `xz01-full-url-scan.py` — crawl same-host PC/mobile front-end URLs and fail on 5xx/ThinkPHP errors, malformed links, mobile blank targets, many empty placeholders, and zero-count software/game list pages.\n   - `xz01-screenshot-core.sh` — deterministic Chromium headless screenshots for core PC/mobile homepage, software/game list, and news list pages; use before AI visual review and copy artifacts into `/root/.hermes/workspace/...` for WebUI media.\n   - `xz01-hook-gate.py` — xz01-specific hook-style guard script for manual use or future Claude Code/Hermes hook wiring; blocks `/root/.openclaw` writes, demo edits, backend/PHP/config/route/core/vendor edits, missing runtime-clear, missi\n\nFile v1.0.43:_meta.json\n\n{\n  \"ownerId\": \"kn709ac4cea693g2hg2p4p3sgn82vk9z\",\n  \"slug\": \"xz01-dev-skill\",\n  \"version\": \"1.0.43\",\n  \"publishedAt\": 1779095701895\n}\n\nFile v1.0.43:references/demo-xz01-may-2026-source-update.md\n\n# demo_xz01 May 2026 source update learning\n\nContext: user reported `/root/.openclaw/workspace/demo_xz01` source was updated and asked to learn differences from previous content. The analysis was read-only; do not modify `demo_xz01`.\n\n## Compared materials\n\nUpdated archives observed around 2026-05-15:\n\n- `www.277zy.com/public/themes/default_2GmaD.zip` compared against older `default_HrJZZ.zip`\n- `www.400zyw.com/public/themes/default_6amTZ.zip` compared against older `default_KntTK.tar.gz`\n- `www.988zyw.com/public/themes/default_7MikX.zip` compared against older `default_mCYYn.tar.gz`\n- `www.866zyw.com/public/themes/default_L2GB4.zip` compared against current `public/themes/default`; no content delta found\n\n## Durable learning\n\n### Front-end dual-end search is canceled/weakened\n\nThe user explicitly confirmed the example: “其中前台双端搜索，已取消.” Treat this as a rule for future xz01-style template work:\n\n- PC/mobile header search forms are no longer mandatory.\n- Do not fail QA solely because a PC or mobile header lacks a complete `form action=\"...Search/index\"` search submission flow.\n- Search pages such as `cms/search.html` and `mobile/search.html` may still exist; their presence does not mean the front-end header must expose full search.\n- Some updated templates retain only a search icon, placeholder input, hot tags, or static search entrance.\n\nObserved examples:\n\n- `www.277zy.com`: PC header form removed; mobile header form replaced by non-form `searchBox`/input/icon.\n- `www.400zyw.com`: PC and mobile header forms removed/weakly represented.\n- `www.988zyw.com`: no full header form baseline; search UI moved/reshaped.\n- `www.866zyw.com`: no archive-to-current change; if a specific template still keeps search, respect that template.\n\n### Template structure is no longer uniform\n\nUpdated templates diverge more strongly from each other:\n\n- `www.277zy.com` removed `common_cms/common/zyxz_module/*` entirely in the new archive.\n- `www.400zyw.com` and `www.988zyw.com` still have many `zyxz_module` files, but pages/partials changed substantially.\n- Some templates add many mobile bottom/related partials; others reduce PC/mobile partials and inline sidebars/recommendation blocks directly in page templates.\n\nFuture dev/test work should not require a fixed `zyxz_module` inventory or a fixed set of `_side_*.html` includes.\n\n### Page composition changes\n\nObserved updated patterns:\n\n- Home pages increasingly use page-local blocks and `getAllData()` calls for hot data, new data, recommendations, news, slides, videos, rankings, etc.\n- List pages may replace sidebar includes with inline ranking/recommendation/news blocks.\n- Game detail pages emphasize platform/download completeness: Android/iOS availability, QR scan download, screenshots/slider, related games, related news, and rankings.\n- Rank pages may use `cms_appranking`, bind IDs, `$rank_channel_list`, and `$game_list` instead of plain appsoft list calls.\n\n### Existing hard rules still apply\n\nDo not blindly copy risky constructs from updated source:\n\n- Mobile `target=\"_blank\"` remains disallowed by user rule even if some updated templates contain residue.\n- Large-scale `uk-cover` remains risky/disallowed in implementation even if updated archives contain many occurrences; prefer custom `object-fit: cover` approaches when building.\n- Database routes remain authoritative; do not create or fix routes simply because a template file exists.\n\n## Future checklist\n\nWhen asked to learn or implement against updated `demo_xz01`:\n\n1. Treat `/root/.openclaw/workspace/demo_xz01` as read-only.\n2. Inventory updated archives and compare against older package/current directory if available.\n3. Separate durable standard changes from source quirks.\n4. For search: do not require full front-end PC/mobile header search unless the specific requested template/design explicitly includes it.\n5. For testing: remove “missing header search” from default fail criteria; keep validation for navigation, carousel/data rendering, responsive layout, and actual routes.\n6. For implementation: preserve template-specific structure rather than forcing all templates into old module/include patterns.\n\nFile v1.0.43:references/hermes-native-xz01-first-run.md\n\n# Hermes-native xz01 factory first-run pattern\n\nThis reference captures the durable workflow learned from the first Hermes-native xz01 prototype run. It is not a one-off task log; use it as a starter pattern for future xz01 automation work.\n\n## Context\n\nThe user corrected that OpenClaw runtime mechanisms (`sessions_send`, `agent:dev:main`, OpenClaw `flow-controller.js`) do not map to Hermes. For Hermes work, OpenClaw is a read-only standards/corpus source. New automation state and generated files belong under Hermes-owned paths.\n\n## Correct first-run approach\n\nWhen the user asks whether to keep discussing or “直接开发第一套给我看下”, act and produce a small end-to-end prototype rather than only listing caveats.\n\nRecommended minimal first-run sequence:\n\n1. Treat `/root/.openclaw` as read-only reference.\n2. Create a Hermes factory run directory, e.g.:\n   - `/root/.hermes/workspace/xz01-factory/runs/run-0001/`\n   - generated template root: `generated/public/themes/default/`\n   - reports: `reports/`\n3. Write a minimal `state.json` and `requirement.json` for traceability.\n4. Use `delegate_task` for a short dev-worker implementation task, or a long-running explicit `hermes` / `claude` worker if the implementation is large.\n5. Generate only into the Hermes factory run directory; do not deploy or overwrite production themes in the prototype step.\n6. Run deterministic static validation before reporting.\n7. Report what exists, what was validated, and what remains before production deployment.\n\n## Minimal output shape\n\n```text\n/root/.hermes/workspace/xz01-factory/runs/run-0001/\n├── state.json\n├── requirement.json\n├── generated/public/themes/default/\n│   ├── DEV_SUMMARY.md\n│   ├── cms/index.html\n│   ├── mobile/index.html\n│   └── common_cms/\n│       ├── common/_head.html\n│       ├── pc/_header.html\n│       ├── pc/_footer.html\n│       ├── pc/assets/css/style.css\n│       ├── pc/assets/js/style.js\n│       ├── mobile/_header.html\n│       ├── mobile/_footer.html\n\n\nArchive v1.0.41: 48 files, 97196 bytes\n\nFiles: _meta.json (134b), references/demo-xz01-may-2026-source-update.md (4193b), references/hermes-native-xz01-first-run.md (3667b), references/hermes-native-xz01-live-deploy-validation.md (4425b), references/lanhu-mcp-discovery-notes.md (1141b), references/lanhu-mcp-installation.md (3378b), references/run-0002-visual-repair.md (8209b), references/session-2026-05-16-allpage-visual-qa-and-scanner-fixes.md (2144b), references/session-2026-05-16-db-channel-name-display-standard.md (1326b), references/session-2026-05-16-demo-xz01-systematic-validation.md (4045b), references/session-2026-05-16-main-role-boundary-correction.md (1623b), references/session-2026-05-16-max-turns-task-splitting-validation-scripts.md (3379b), references/session-2026-05-16-no-php-controller-template-dev.md (1649b), references/session-2026-05-16-packaging-gate-runtime-list-detail.md (2420b), references/session-2026-05-16-pc-gap-dev-test-rule-loop.md (3447b), references/session-2026-05-16-right-sidebar-height-balance.md (1890b), references/session-2026-05-16-theme-only-data-links-search.md (3070b), references/session-2026-05-18-all-detail-mixed-sidebar.md (4243b), references/session-2026-05-18-detail-sidebar-bottom-modules.md (4266b), references/session-2026-05-18-dual-end-list-pagination.md (2256b), references/session-2026-05-18-dual-end-nav-dynamic-menu.md (4056b), references/session-2026-05-18-fullpage-visual-qa-correction.md (2085b), references/session-2026-05-18-hermes-native-no-search-regression.md (2998b), references/session-2026-05-18-hermes-native-title-search-repair.md (3432b), references/session-2026-05-18-home-resource-iconized-cards.md (2857b), references/session-2026-05-18-karpathy-ecc-hook-adaptation.md (1935b), references/session-2026-05-18-mobile-domain-validation-correction.md (2743b), references/session-2026-05-18-mobile-layout-overflow-repair.md (3297b), references/session-2026-05-18-openclaw-temp-artifact-boundary.md (1884b), references/session-2026-05-18-pagination-rule-template-repair.md (2222b), references/session-2026-05-18-pc-mobile-search-visual-repair.md (2715b), references/session-2026-05-18-pc-nav-dynamic-menu.md (2082b), references/session-2026-05-18-pc-nav-scope-validation.md (1127b), references/session-2026-05-18-rendered-pc-pagination-fallback.md (3148b), references/session-2026-05-18-skill-library-active-review.md (1132b), references/session-2026-05-18-timeout-recovery-partial-work.md (1876b), references/session-2026-05-18-xz01-skill-autopublish.md (1528b), references/xz01-template-factory-architecture.md (7152b), scripts/xz01-backend-baseline-check.sh (403b), scripts/xz01-full-url-scan.py (4200b), scripts/xz01-hook-gate.py (6560b), scripts/xz01-quick-http-gate.py (2405b), scripts/xz01-runtime-clear.sh (447b), scripts/xz01-screenshot-core.sh (1444b), scripts/xz01-template-static-scan.py (3677b), scripts/xz01-theme-diff-check.sh (621b), skill.json (951b), SKILL.md (69500b)\n\nArchive v1.0.40: 47 files, 94615 bytes\n\nFiles: _meta.json (134b), references/demo-xz01-may-2026-source-update.md (4193b), references/hermes-native-xz01-first-run.md (3667b), references/hermes-native-xz01-live-deploy-validation.md (4425b), references/lanhu-mcp-discovery-notes.md (1141b), references/lanhu-mcp-installation.md (3378b), references/run-0002-visual-repair.md (8209b), references/session-2026-05-16-allpage-visual-qa-and-scanner-fixes.md (2144b), references/session-2026-05-16-db-channel-name-display-standard.md (1326b), references/session-2026-05-16-demo-xz01-systematic-validation.md (4045b), references/session-2026-05-16-main-role-boundary-correction.md (1623b), references/session-2026-05-16-max-turns-task-splitting-validation-scripts.md (3379b), references/session-2026-05-16-no-php-controller-template-dev.md (1649b), references/session-2026-05-16-packaging-gate-runtime-list-detail.md (2420b), references/session-2026-05-16-pc-gap-dev-test-rule-loop.md (3447b), references/session-2026-05-16-right-sidebar-height-balance.md (1890b), references/session-2026-05-16-theme-only-data-links-search.md (3070b), references/session-2026-05-18-all-detail-mixed-sidebar.md (4243b), references/session-2026-05-18-detail-sidebar-bottom-modules.md (4266b), references/session-2026-05-18-dual-end-list-pagination.md (2256b), references/session-2026-05-18-dual-end-nav-dynamic-menu.md (4056b), references/session-2026-05-18-fullpage-visual-qa-correction.md (2085b), references/session-2026-05-18-hermes-native-no-search-regression.md (2998b), references/session-2026-05-18-hermes-native-title-search-repair.md (3432b), references/session-2026-05-18-home-resource-iconized-cards.md (2857b), references/session-2026-05-18-karpathy-ecc-hook-adaptation.md (1935b), references/session-2026-05-18-mobile-domain-validation-correction.md (2743b), references/session-2026-05-18-mobile-layout-overflow-repair.md (3297b), references/session-2026-05-18-openclaw-temp-artifact-boundary.md (1884b), references/session-2026-05-18-pagination-rule-template-repair.md (2222b), references/session-2026-05-18-pc-mobile-search-visual-repair.md (2715b), references/session-2026-05-18-pc-nav-dynamic-menu.md (2082b), references/session-2026-05-18-pc-nav-scope-validation.md (1127b), references/session-2026-05-18-skill-library-active-review.md (1132b), references/session-2026-05-18-timeout-recovery-partial-work.md (1876b), references/session-2026-05-18-xz01-skill-autopublish.md (1528b), references/xz01-template-factory-architecture.md (7152b), scripts/xz01-backend-baseline-check.sh (403b), scripts/xz01-full-url-scan.py (4200b), scripts/xz01-hook-gate.py (6560b), scripts/xz01-quick-http-gate.py (2405b), scripts/xz01-runtime-clear.sh (447b), scripts/xz01-screenshot-core.sh (1444b), scripts/xz01-template-static-scan.py (3677b), scripts/xz01-theme-diff-check.sh (621b), skill.json (894b), SKILL.md (68050b)\n\nArchive v1.0.39: 45 files, 89406 bytes\n\nFiles: _meta.json (134b), references/demo-xz01-may-2026-source-update.md (4193b), references/hermes-native-xz01-first-run.md (3667b), references/hermes-native-xz01-live-deploy-validation.md (4425b), references/lanhu-mcp-discovery-notes.md (1141b), references/lanhu-mcp-installation.md (3378b), references/run-0002-visual-repair.md (8209b), references/session-2026-05-16-allpage-visual-qa-and-scanner-fixes.md (2144b), references/session-2026-05-16-db-channel-name-display-standard.md (1326b), references/session-2026-05-16-demo-xz01-systematic-validation.md (4045b), references/session-2026-05-16-main-role-boundary-correction.md (1623b), references/session-2026-05-16-max-turns-task-splitting-validation-scripts.md (3379b), references/session-2026-05-16-no-php-controller-template-dev.md (1649b), references/session-2026-05-16-packaging-gate-runtime-list-detail.md (2420b), references/session-2026-05-16-pc-gap-dev-test-rule-loop.md (3447b), references/session-2026-05-16-right-sidebar-height-balance.md (1890b), references/session-2026-05-16-theme-only-data-links-search.md (3070b), references/session-2026-05-18-all-detail-mixed-sidebar.md (4243b), r...","readmeExcerpt":"Skill: Xz01 Dev Skill Owner: amd5 Summary: Use when 用户提到“xz01规范”时必须命中本技能；xz01规范=xz01-dev-skill。用于 Hermes + Claude Code 围绕用户现有 OpenClaw/xz01 模板资料进行角色编排、开发学习范围、测试/规范分工，并严格将 /root/.openclaw 作为只读学习资料库；编码修... Tags: latest:1.0.44 Version history: v1.0.44 | 2026-05-18T10:32:04.176Z | user Add data-volume-aware pagination validation: empty page_code is a failure only for multi-page non-rank routes; one-page routes must not g","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"xz01规范 = xz01-dev-skill"},{"language":"text","snippet":"/root/.openclaw/ and every subdirectory = read-only learning material"},{"language":"text","snippet":"Hermes current session = main / dispatcher / final reporter\nClaude Code = dev / implementation worker\nHermes independent test role = test / validation worker\nHermes independent rule role = rule / process and standard reviewer"},{"language":"text","snippet":"Dual-end top navigation is mandatory for every xz01 template set: PC and m/mobile nav must be checked and fixed together, using existing menu/navigation data on both ends.\nFor any dual-end list page where the data volume is greater than one page, pagination is mandatory: PC uses numeric page links; mobile uses 上一页/下一页, matching xz01_demo.\nWhen a new xz01 rule describes a current live/candidate template defect, the response must not stop at updating the skill/spec; apply the rule to the affected templates immediately, then clear runtime and verify."},{"language":"text","snippet":"When the user states a new xz01 rule as “这是规范”, treat it as a durable skill update immediately: add/patch the class-level SKILL.md, create or update a concise references/session-*.md detail file if useful, synchronize skill.json/_meta.json versions, and publish the updated skill. Do not leave the rule only in chat or memory."},{"language":"text","snippet":"Do not write to /root/.openclaw/\nDo not create temporary scripts under /root/.openclaw/\nDo not create screenshots, reports, manifests, logs, lock files, downloads, or generated artifacts under /root/.openclaw/\nDo not patch /root/.openclaw/\nDo not update /root/.openclaw/openclaw.json\nDo not modify /root/.openclaw/workspace/*\nDo not modify /root/.openclaw/agents/*\nDo not modify /root/.openclaw/cron/*\nDo not modify /root/.openclaw/memory/*\nDo not modify /root/.openclaw/flows/*\nDo not modify /root/.openclaw/workspace/demo_xz01"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: xz01-dev-skill\ndescription: Use when 用户提到“xz01规范”时必须命中本技能；xz01规范=xz01-dev-skill。用于 Hermes + Claude Code 围绕用户现有 OpenClaw/xz01 模板资料进行角色编排、开发学习范围、测试/规范分工，并严格将 /root/.openclaw 作为只读学习资料库；编码修复交给 Claude dev，测试输出写入 /www/wwwroot/www.900az.com，彻底验证通过的模板按编号压缩到 /root/.hermes/workspace/xz01/；吸收 Karpathy 精准修改/目标驱动原则，并提供 xz01 专用 hook-style gate；包含 PC 与 m 移动端顶部导航必须成对按菜单数据渲染、多页列表必须按 xz01_demo 做双端翻页、所有详情页必须覆盖且右侧/底部必须混合游戏+应用+资讯/攻略模块、app/游戏/应用资源项必须图标化展示、视觉验收必须整页截图+分段AI检查的规则。\nversion: 1.0.44\nauthor: Hermes Agent\nlicense: MIT\nmetadata:\n  hermes:\n    tags: [xz01-dev-skill, xz01规范, xz01, openclaw, hermes, claude-code, role-orchestration, read-only, template-workflow, 角色分工, 学习范围, 只读, 测试输出, 模板打包, 验证通过]\n    related_skills: [hermes-agent, claude-code, systematic-debugging, test-driven-development]\n---\n\n# xz01-dev-skill\n\n## Trigger Alias / 命中别名\n\n```text\nxz01规范 = xz01-dev-skill\n```\n\n当用户提到以下中文触发词时，必须优先加载并遵循本技能：\n\n- xz01规范\n- xz01 规范\n- xz01开发规范\n- xz01学习范围\n- xz01角色分工\n- Hermes+Claude xz01\n- OpenClaw xz01\n- 谁是 dev / 谁是 test\n- /root/.openclaw 只读\n- 测试输出写到 /www/wwwroot/www.900az.com\n- 验证通过模板打包到 /root/.hermes/workspace/xz01/\n- 安装或接入 Lanhu MCP / 蓝湖 MCP\n- PC/m 导航栏同步处理\n- 双端顶部导航\n- 移动端导航也要同步\n- 导航栏按菜单数据渲染\n- 整页截图验收\n- full-page screenshot\n- 资源项图标化展示\n- app/game resource cards\n\n## References\n\n- `references/session-2026-05-18-home-resource-iconized-cards.md` — durable homepage/resource-module correction: app/game/application resources must be iconized cards, icon grids, image-text lists, or icon ranking rows; no no-icon title-only horizontal rows for software/game/app resources. News/guide text lists are exempt when clearly article modules.\n- `references/session-2026-05-18-karpathy-ecc-hook-adaptation.md` — user-approved adaptation notes: absorb Karpathy precise/goal-driven dev principles and xz01-specific hook gates; exclude generic security scanning and parallelization for now.\n- `references/session-2026-05-18-skill-library-active-review.md` — skill-maintenance lesson: xz01 user corrections phrased as “这是规范” must be actively promoted into the class-level skill and references, not left only in chat or memory.\n- `references/session-2026-05-18-all-detail-mixed-sidebar.md` — user correction that “详情页” means every active PC/mobile detail template, including collection/topic detail when present; PC right sidebars must not be only攻略 and must mix app/software, game, and news/guide modules with real data. Also covers the operational pattern that if a long dev worker times out after making file changes, do not assume failure or success: first inspect modified timestamps/content, then continue with smaller verification/fix tasks.\n- `references/session-2026-05-18-dual-end-list-pagination.md` — hard pagination rule: every dual-end list page except ranking/rank-list pages must render pagination like `xz01_demo` when data exceeds one page; PC uses numeric page links, mobile uses `上一页` / `下一页` controls. The scope is route/database-list based, not limited to files named `list_soft/list_game/list_news/l"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn709ac4cea693g2hg2p4p3sgn82vk9z\",\n  \"slug\": \"xz01-dev-skill\",\n  \"version\": \"1.0.44\",\n  \"publishedAt\": 1779100324176\n}"},{"path":"references/demo-xz01-may-2026-source-update.md","content":"# demo_xz01 May 2026 source update learning\n\nContext: user reported `/root/.openclaw/workspace/demo_xz01` source was updated and asked to learn differences from previous content. The analysis was read-only; do not modify `demo_xz01`.\n\n## Compared materials\n\nUpdated archives observed around 2026-05-15:\n\n- `www.277zy.com/public/themes/default_2GmaD.zip` compared against older `default_HrJZZ.zip`\n- `www.400zyw.com/public/themes/default_6amTZ.zip` compared against older `default_KntTK.tar.gz`\n- `www.988zyw.com/public/themes/default_7MikX.zip` compared against older `default_mCYYn.tar.gz`\n- `www.866zyw.com/public/themes/default_L2GB4.zip` compared against current `public/themes/default`; no content delta found\n\n## Durable learning\n\n### Front-end dual-end search is canceled/weakened\n\nThe user explicitly confirmed the example: “其中前台双端搜索，已取消.” Treat this as a rule for future xz01-style template work:\n\n- PC/mobile header search forms are no longer mandatory.\n- Do not fail QA solely because a PC or mobile header lacks a complete `form action=\"...Search/index\"` search submission flow.\n- Search pages such as `cms/search.html` and `mobile/search.html` may still exist; their presence does not mean the front-end header must expose full search.\n- Some updated templates retain only a search icon, placeholder input, hot tags, or static search entrance.\n\nObserved examples:\n\n- `www.277zy.com`: PC header form removed; mobile header form replaced by non-form `searchBox`/input/icon.\n- `www.400zyw.com`: PC and mobile header forms removed/weakly represented.\n- `www.988zyw.com`: no full header form baseline; search UI moved/reshaped.\n- `www.866zyw.com`: no archive-to-current change; if a specific template still keeps search, respect that template.\n\n### Template structure is no longer uniform\n\nUpdated templates diverge more strongly from each other:\n\n- `www.277zy.com` removed `common_cms/common/zyxz_module/*` entirely in the new archive.\n- `www.400zyw.com` and `www.988zyw.com` still have many `zyxz_module` files, but pages/partials changed substantially.\n- Some templates add many mobile bottom/related partials; others reduce PC/mobile partials and inline sidebars/recommendation blocks directly in page templates.\n\nFuture dev/test work should not require a fixed `zyxz_module` inventory or a fixed set of `_side_*.html` includes.\n\n### Page composition changes\n\nObserved updated patterns:\n\n- Home pages increasingly use page-local blocks and `getAllData()` calls for hot data, new data, recommendations, news, slides, videos, rankings, etc.\n- List pages may replace sidebar includes with inline ranking/recommendation/news blocks.\n- Game detail pages emphasize platform/download completeness: Android/iOS availability, QR scan download, screenshots/slider, related games, related news, and rankings.\n- Rank pages may use `cms_appranking`, bind IDs, `$rank_channel_list`, and `$game_list` instead of plain appsoft list calls.\n\n### Existing hard rules still apply\n\nDo not blindly copy risky c"},{"path":"references/hermes-native-xz01-first-run.md","content":"# Hermes-native xz01 factory first-run pattern\n\nThis reference captures the durable workflow learned from the first Hermes-native xz01 prototype run. It is not a one-off task log; use it as a starter pattern for future xz01 automation work.\n\n## Context\n\nThe user corrected that OpenClaw runtime mechanisms (`sessions_send`, `agent:dev:main`, OpenClaw `flow-controller.js`) do not map to Hermes. For Hermes work, OpenClaw is a read-only standards/corpus source. New automation state and generated files belong under Hermes-owned paths.\n\n## Correct first-run approach\n\nWhen the user asks whether to keep discussing or “直接开发第一套给我看下”, act and produce a small end-to-end prototype rather than only listing caveats.\n\nRecommended minimal first-run sequence:\n\n1. Treat `/root/.openclaw` as read-only reference.\n2. Create a Hermes factory run directory, e.g.:\n   - `/root/.hermes/workspace/xz01-factory/runs/run-0001/`\n   - generated template root: `generated/public/themes/default/`\n   - reports: `reports/`\n3. Write a minimal `state.json` and `requirement.json` for traceability.\n4. Use `delegate_task` for a short dev-worker implementation task, or a long-running explicit `hermes` / `claude` worker if the implementation is large.\n5. Generate only into the Hermes factory run directory; do not deploy or overwrite production themes in the prototype step.\n6. Run deterministic static validation before reporting.\n7. Report what exists, what was validated, and what remains before production deployment.\n\n## Minimal output shape\n\n```text\n/root/.hermes/workspace/xz01-factory/runs/run-0001/\n├── state.json\n├── requirement.json\n├── generated/public/themes/default/\n│   ├── DEV_SUMMARY.md\n│   ├── cms/index.html\n│   ├── mobile/index.html\n│   └── common_cms/\n│       ├── common/_head.html\n│       ├── pc/_header.html\n│       ├── pc/_footer.html\n│       ├── pc/assets/css/style.css\n│       ├── pc/assets/js/style.js\n│       ├── mobile/_header.html\n│       ├── mobile/_footer.html\n│       ├── mobile/assets/css/style.css\n│       └── mobile/assets/js/style.js\n└── reports/basic-validation.json\n```\n\n## Static validation checklist for prototype\n\nBefore telling the user the prototype is ready, verify at least:\n\n- no writes under `/root/.openclaw`\n- no production deploy unless explicitly requested\n- no raw PHP template tags (`<?php`, `<?=`, `<?`)\n- mobile templates contain no `target` / `_blank`\n- no `href=\"#\"`\n- no `uk-cover` attributes\n- no `limit=\"0\"` / `getAllData({limit: 0})`\n- CSS brace counts are balanced\n- all `{include file=\"./themes/default/...\"}` targets exist\n- referenced local CSS/JS assets exist under the generated template root\n- HTML class names used by the prototype have CSS definitions, or intentional exceptions are documented\n\n## Prototype vs production boundary\n\nA prototype-ready result is not production-ready. Before packaging/deployment, continue with:\n\n1. renderer script: deploy to a safe test theme or staging path, clear cache, render PC/mobile\n2. screenshot capture for both d"},{"path":"references/hermes-native-xz01-live-deploy-validation.md","content":"# Hermes native xz01 live deployment and validation notes\n\nUse this when the user asks to deploy a temporary xz01 template for live validation via:\n\n- `https://www.900az.com/`\n- `https://m.900az.com/`\n\n## Key correction from the first live run\n\nThe prototype directory under `/root/.hermes/workspace/xz01-factory/runs/<run>/generated/` is safe for staging, but the user may explicitly want temporary template development to live under:\n\n```text\n/www/wwwroot/www.900az.com/public/themes/default/\n```\n\nWhen this happens, proceed directly but first make a timestamped backup of the current `default` theme.\n\n## Safe live deployment sequence\n\n1. Ensure generated source exists under the run directory.\n2. Create backup:\n\n```bash\nBACKUP_DIR=/root/.hermes/workspace/xz01-factory/backups\nmkdir -p \"$BACKUP_DIR\"\ntar -czf \"$BACKUP_DIR/default-before-<run_id>-$(date +%Y%m%d-%H%M%S).tar.gz\" \\\n  -C /www/wwwroot/www.900az.com/public/themes default\n```\n\n3. Replace default theme:\n\n```bash\nrm -rf /www/wwwroot/www.900az.com/public/themes/default\nmkdir -p /www/wwwroot/www.900az.com/public/themes/default\ncp -a /root/.hermes/workspace/xz01-factory/runs/<run_id>/generated/public/themes/default/. \\\n  /www/wwwroot/www.900az.com/public/themes/default/\nrm -rf /www/wwwroot/www.900az.com/runtime/*\n```\n\n4. Verify PC and mobile return HTTP 200.\n5. Run PHP syntax checks on compiled runtime templates under `/www/wwwroot/www.900az.com/runtime/temp/*.php` after first render.\n6. Run static checks:\n   - mobile contains no `target=\"_blank\"`\n   - source templates contain no raw PHP tags\n   - no `href=\"#\"`\n   - no `uk-cover`\n   - no `limit=\"0\"` / `getAllData({limit:0})`\n   - CSS brace counts balanced\n7. Use browser screenshots and AI vision on both URLs.\n8. Save artifacts under:\n\n```text\n/www/wwwroot/www.900az.com/xz01-runs/screenshots/<run_id>/\n/www/wwwroot/www.900az.com/xz01-runs/reports/\n```\n\n## Pitfalls found in run-0001\n\n### Undefined template variables can cause 500\n\nIf the controller does not provide variables such as `$recommend_list`, `$latest_list`, `$rank_list`, `$category_list`, `$news_list`, or `$topic_list`, ThinkPHP may throw `未定义变量` during template compilation/rendering.\n\nFor live prototypes, wrap optional data blocks with `isset(...)` and provide static fallback content so the page can render before real DB binding exists:\n\n```html\n{if condition=\"isset($recommend_list)\"}\n  {foreach name=\"recommend_list\" item=\"vo\" key=\"key\"}\n  ...\n  {/foreach}\n{else/}\n  <!-- static fallback cards for visual validation -->\n{/if}\n```\n\n### Some `|default` forms may compile badly\n\nAvoid complex `|default` expressions in live xz01 prototypes, especially inside `{:...}` expressions. Prefer explicit `isset(...) ? ... : ...` or static fallback blocks.\n\n### ThinkPHP trace overlay can pollute screenshots\n\nIf debug trace is enabled, screenshots can show `#think_page_trace_open` with a small runtime number such as `0.070867s`. Hide it in temporary template CSS before visual validation:\n\n```css\n#think_page_tr"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2065,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T09:34:08.898Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T09:34:08.898Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:50:21.549Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}