Skip to content

~/writingheavy-artillery-skills

Heavy Artillery Skills: field-tested skill packs for AI coding agents

Heavy Artillery Skills is my set of five skill packs for AI coding agents, from proving their own work to email, WordPress and app builds, each built from real bugs.

Jon Phillips5 min read#agents#ai#product#wordpress
A spotting scope on a rooftop at dusk overlooking a small town, its lens glinting green

Heavy Artillery Skills is a set of skill packs I sell for AI coding agents. Each pack is skills plus runnable scripts: they teach an agent how I build, and make it prove its work before it tells you the work is done. They work with Claude Code, Codex, Cursor and Gemini CLI. Every skill traces back to a real bug I hit, and every check ships with a way to make it fail on purpose.

It started as a single kit called Spotter Round. Spotter Round is now the verification pack, one of five.

What goes wrong when you trust a confident agent?

AI coding agents are fast and sure of themselves, and a confident report is not the same as a checked one.

One layout audit I ran reported 57 elements measured and no findings. The page had 196. The other 139 sat inside five collapsed sections the check never opened. The report wasn't lying on purpose. It measured what it could see, found nothing wrong, and said "clean." A check that looks at nothing and a check that finds nothing produce the same report.

It gets worse with several agents on one project. Commits from one session can land on a branch another session owns, with nobody doing anything wrong.

I hit both problems building websites, and wrote the fixes down as rules and scripts my own agents follow. Heavy Artillery Skills is those rules and scripts, packaged so other people can use them.

What's in the packs?

Seventeen skills in five packs, as of release 2.2.1, each with scripts you can read before you run them:

  • Spotter Round, the verification pack: checks that make an agent prove a page works, from layout and visual fidelity to before-and-after speed tests and proof after a deploy.
  • Agent Setup: shared rules for every agent tool, several agents working one repository without landing on each other's work, and handing over secrets without pasting them into a chat.
  • Email: HTML email that holds up in dark mode, and branded sign-in emails for Supabase.
  • WordPress: building with Bricks, Automatic.css and SureCart through an agent, without surprises on the live site.
  • App Stack: Cloudflare Pages, Stripe on Supabase, Supabase passkeys, SureContact and OttoKit.

Each pack's page spells out exactly what its scripts touch on your machine, because a developer should know that before installing anything.

The rule that runs through all of it: every check ships a way to make it fail on purpose. A check that has never failed proves nothing. If you can't make it go red, you don't know it's looking.

Each pack is $39. The All-Access bundle is $149 for every pack, now and later, against $195 for the five bought separately. There's also a free pack with the verification protocol skill, for anyone who wants to see the approach before buying.

Everything sells as a one-time payment for one organization, with every future version included and a 14-day refund. The packs are at skills.heavyartillery.io.

Why does one product need two sites?

Because each half had a different job, and I built each on the stack that fits it.

The product site at skills.heavyartillery.io makes the case, with a page for each pack. It runs on the same React build as Heavy Artillery, my sister brand for AI automation, but keeps to its own host. It's written for developers rather than business owners: the incidents behind each skill, what the scripts do, and the checklist opt-in. The price it shows is read live from the store, so the page can never advertise a number the checkout won't honor.

The store at shop.heavyartillery.io takes the payment and delivers the packs. It runs WordPress, with Bricks Builder and Automatic.css for the design and SureCart for checkout, versioned downloads, licenses, customer accounts and refunds.

The store had to feel like the React site beside it. So the Heavy Artillery design system went in as data rather than a lookalike: the same colors and typefaces, loaded into Automatic.css. I replaced SureCart's stock product template with a custom Bricks product page: an image gallery, a sticky add-to-cart bar, a map of where every file lands, and the questions buyers ask first. I restyled the cart drawer to match the dark theme.

How do you keep two sites from drifting apart?

You make drift fail a check. The store's privacy policy is generated from the same source as heavyartillery.io's, and a check fails if the live copy ever says anything different. The price on the product site comes from the store, not from a number I typed.

And every change to the live store was backed up first, then checked logged out afterward, because the logged-in view of a WordPress site is not what the public sees.

What did building it teach me?

That the store and the product site needed the same discipline as the skills. Two stacks for one brand is fine, as long as anything that can disagree, like the price or the privacy policy, has a single source and a check that notices when it doesn't match.

Stack: React (product site), WordPress, Bricks Builder, Automatic.css and SureCart (store); the skills target Claude Code, Codex, Cursor and Gemini CLI.

Jon Phillips builds websites, web apps and automations atMatchless Web in Clinton, Mississippi.

~/writing · keep reading