How a TYPO3 Idea Became a Research Paper

An internal strategy evolved into a full research paper, tested for weaknesses via adversarial review and published openly. This article explains our methodology, the new /forschung section, and why we work this way.

Overview

  • An internal strategy for a curated Agent Skills registry has evolved into a full research paper. It is now freely available to read at /forschung.
  • What makes it special is the method: first AI-supported research, then a catalogue of requirements, followed by an adversarial review that systematically searches for weaknesses in our own design.
  • This review identified four serious risks in our design and led to four concrete corrections.
  • There are three texts on the same topic at different levels of detail: the strategy, a summary, and the complete research paper.

Our strategy for a curated Agent Skills registry for TYPO3 has evolved into a full research paper. Agent Skills are knowledge packages for AI coding assistants like Claude Code; a curated registry would verify these skills before anyone installs them. We systematically tested the research paper for its own weaknesses and published it openly today. In this article, we primarily describe the methodology behind it and explain why we are sharing it openly.

New: the /forschung section

The full paper "Trust Infrastructure for AI-Supported Software Development" is now available to read in our new Research section: eleven chapters, a glossary, and 27 verified sources. Under /forschung we will collect future papers that go beyond a standard blog post.

Why an agency conducts research  

We build TYPO3 projects, and to do so, we must understand how AI-supported development is currently changing. The two are becoming increasingly interconnected. When designing the strategy for a curated skills registry, we quickly realised that the truly difficult questions did not concern the implementation, but rather the underlying structure: How do you organise trust in an ecosystem where the raw text of instructions can be exploited as an attack vector ? When is such a model economically viable? And who should own it?

To answer such questions rigorously requires a transparent methodology. We therefore structured the strategy as a Design Science Research paper – a research approach in which you design something concrete and then evaluate it critically. The paper follows the pattern of problem, requirements, design, and evaluation; every step is documented and backed by sources. This process has also yielded something useful beyond TYPO3: a requirements catalogue and five lessons from 25 years of registry history that can be applied to other ecosystems.

The methodology: research widely first, then look for your own weaknesses  

The process can be described in four steps:

Research widely

Seven subject areas – technical, legal, governance, marketing, usage, precedents, business model – were researched in parallel and with AI support, each backed by verified primary sources instead of gut feeling.

Consolidate into requirements

The research resulted in a catalogue of twelve requirements (A1–A12) – the benchmark against which every subsequent design decision must be measured.

Conduct adversarial review

An adversarial review systematically searched for contradictions and blind spots in the design. The goal was to find weaknesses, not to validate the design.

Correct and disclose

The identified weaknesses were integrated into the design, the limitations of the work were clearly stated, and everything was published, including open points.

Step 3 is the most important: an AI can write a convincing strategy in a short space of time. However, the real added value comes from the subsequent critical review, where the same AI systematically searches for flaws in its own design. This step improved our design the most.

What the adversarial review uncovered  

The review identified four problems. All four were highly relevant and led to changes in the design:

Trust marks expire with each LTS cycle

Every TYPO3 LTS cycle invalidates existing trust marks. Therefore, every verification carries a visible date to remain transparent about its current status.

A conflict of ownership

A registry that serves the community but is owned by an agency is a contradiction. This is resolved through a proven operator model inspired by Packagist.

Liability without a contract

Those who install via CLI never see the terms of use. Therefore, trust marks describe processes and do not provide guarantees.

The operator as a bottleneck

The original programme exceeded the available capacity by 2.7 times; the study discloses this openly.

The fact that the analysis revealed a capacity requirement exceeding available time by a factor of 2.7 is an uncomfortable but useful result. A strategy that knows and openly names its weaknesses is more reliable in practice.

Three texts, three levels of detail  

For those who want to dive deeper, the same topic is available in three versions:

The Strategy

The original design: what a curated registry would require technically, legally, and organisationally.

The Summary

Summarises the study in ten minutes: twelve requirements, five lessons, four risks.

The Research Paper

The complete monograph with eleven chapters, methodology, evaluation, and all sources.

What /forschung stands for  

In this new section, we disclose how we arrive at our conclusions: with sources, methodology, and the inherent limitations. Clients do not simply have to take our word for it; they can verify our arguments for themselves.

The open standard behind Agent Skills and our growing catalogue of curated skills remain the practical side of this work. The research provides the foundation upon which we continue to develop both.

Feedback welcome

If you find a logical flaw in the paper, please let us know – the easiest way is via our contact form. Such feedback helps us improve our work.

Conclusion  

An internal strategy has evolved into a verified research paper, and the critical review has concretely improved the design in four areas. This approach has proven successful for us. We will therefore work this way more often and publish the results under /forschung.

Let's talk about your project

Locations

  • Mattersburg
    Johann Nepomuk Bergerstraße 7/2/14
    7210 Mattersburg, Austria
  • Vienna
    Ungargasse 64-66/3/404
    1030 Wien, Austria

Parts of this content were created with the assistance of AI.