Our strategy for a curated Agent Skills registry for TYPO3 has evolved into a full research paper. Agent Skills are knowledge packages for AI coding assistants like Claude Code; a curated registry would verify these skills before anyone installs them. We systematically tested the research paper for its own weaknesses and published it openly today. In this article, we primarily describe the methodology behind it and explain why we are sharing it openly.
The full paper "Trust Infrastructure for AI-Supported Software Development" is now available to read in our new Research section: eleven chapters, a glossary, and 27 verified sources. Under /forschung we will collect future papers that go beyond a standard blog post.
Why an agency conducts research
We build TYPO3 projects, and to do so, we must understand how AI-supported development is currently changing. The two are becoming increasingly interconnected. When designing the strategy for a curated skills registry, we quickly realised that the truly difficult questions did not concern the implementation, but rather the underlying structure: How do you organise trust in an ecosystem where the raw text of instructions can be exploited as an attack vector ? When is such a model economically viable? And who should own it?
To answer such questions rigorously requires a transparent methodology. We therefore structured the strategy as a Design Science Research paper – a research approach in which you design something concrete and then evaluate it critically. The paper follows the pattern of problem, requirements, design, and evaluation; every step is documented and backed by sources. This process has also yielded something useful beyond TYPO3: a requirements catalogue and five lessons from 25 years of registry history that can be applied to other ecosystems.
The methodology: research widely first, then look for your own weaknesses
The process can be described in four steps:
Research widely
Consolidate into requirements
Conduct adversarial review
Correct and disclose
Step 3 is the most important: an AI can write a convincing strategy in a short space of time. However, the real added value comes from the subsequent critical review, where the same AI systematically searches for flaws in its own design. This step improved our design the most.
What the adversarial review uncovered
The review identified four problems. All four were highly relevant and led to changes in the design:
Trust marks expire with each LTS cycle
A conflict of ownership
Liability without a contract
The operator as a bottleneck
The fact that the analysis revealed a capacity requirement exceeding available time by a factor of 2.7 is an uncomfortable but useful result. A strategy that knows and openly names its weaknesses is more reliable in practice.
Three texts, three levels of detail
For those who want to dive deeper, the same topic is available in three versions:
The Strategy
The Summary
The Research Paper
What /forschung stands for
In this new section, we disclose how we arrive at our conclusions: with sources, methodology, and the inherent limitations. Clients do not simply have to take our word for it; they can verify our arguments for themselves.
The open standard behind Agent Skills and our growing catalogue of curated skills remain the practical side of this work. The research provides the foundation upon which we continue to develop both.
If you find a logical flaw in the paper, please let us know – the easiest way is via our contact form. Such feedback helps us improve our work.
Conclusion
An internal strategy has evolved into a verified research paper, and the critical review has concretely improved the design in four areas. This approach has proven successful for us. We will therefore work this way more often and publish the results under /forschung.