General-purpose agent

goose

Open standards, native apps, and broad workflow automation.

Status
Active
License
Apache-2.0
Evidence
Documented + code-verifiable, 19 sources
Product record checked
2026-07-27

At a glance

An open-source general agent with desktop, CLI, and headless use, broad provider, subscription, and local-model access, plus MCP extensions, recipes, subagents, browser control, configurable approvals, and platform-specific isolation.

Good choice if

  • Open-standard and MCP-heavy workflows
  • Users who want desktop, CLI, headless, local-model, and subscription choices
  • Reusable automation through recipes, extensions, and subagents

Check before choosing

  • Broader than a code-only specialist
  • Developer tools run autonomously with user privileges by default unless approval policies are configured
  • The documented native OS sandbox is specific to goose Desktop on macOS; other isolation paths are optional
See 4 more considerations
  • Adversary Mode is optional, reviews only configured tools, and fails open when its reviewer fails; prompt-injection detection is also optional and cannot catch every threat
  • ML-based prompt-injection detection can send tool-call content and recent messages to the configured classifier endpoint, while allowed commands still run with the user's full permissions
  • goose CLI versions before 1.44.0 are affected by a high-severity arbitrary-command-execution advisory in goose review and should not be treated as equivalent to the verified release
  • Large-repository support uses analysis tools and context guards, not a documented persistent repository index or scale guarantee

Why it qualifies as a coding harness

This confirms category fit, not product quality. Every required criterion links back to first-party evidence.

Qualifies4 of 4 required criteria evidenced
  • Adaptive agent loop

    Documented

    The system repeatedly observes results and chooses the next action instead of following a fixed one-pass graph.

  • Repository tool execution

    Documented

    The system can use tools to inspect and change a repository or its execution environment.

  • Task-aware context management

    Documented

    The runtime assembles, updates, compacts, retrieves, or persists task-relevant context while work proceeds.

  • Model-independent runtime control

    Documented

    Permissions, budgets, interruption, policy, or stop controls operate outside the model's own text generation.

Membership establishes category fit only. It does not score quality, safety, autonomy, model capability, or benchmark performance. · Read the membership rule.

How it works under the hood

Seven mechanisms mapped from first-party records. These labels describe what the harness provides, not how intelligent its model is.

7/7layers documented
  • Execution & isolationSandbox availableDocumented mechanism, not a performance score.
  • Tooling & integrationsExtensible + browserDocumented mechanism, not a performance score.
  • Context & stateManaged contextDocumented mechanism, not a performance score.
  • Lifecycle & recoverySession resumeDocumented mechanism, not a performance score.
  • ObservabilityLogs/transcriptsDocumented mechanism, not a performance score.
  • VerificationTool-assistedDocumented mechanism, not a performance score.
  • Governance & permissionsPolicy controlsDocumented mechanism, not a performance score.

Public code audit

5/5public artifacts present
Security policy
Present at inspected commit
CI workflow
Present at inspected commit
Automated tests
Present at inspected commit
Evaluation assets
Present at inspected commit
Contributor documentation
Present at inspected commit

The repository contains project-owned Harbor and Terminal-Bench tooling with one-attempt snapshots; these are auditable artifacts, not independent benchmark evidence.

Inspect commit 2855b87a6595, checked 2026-07-27

Measured configurations

No benchmark run passes the full metadata admission policy for this harness yet. Missing data is not scored as zero.

Benchmark policy and all runs

Capability support

Documented first-class product support, checked against the sources below.

External tools (MCP)
DocumentedProduct-supported MCP integrationSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Local models
DocumentedLocal or self-hosted model pathSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Agent parallelism
DocumentedDelegated or parallel agent workflowSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Runs without an open UI
DocumentedNon-interactive or automation surfaceSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Browser control
DocumentedBuilt-in or product-supported browser controlSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Isolated execution
DocumentedDocumented execution-isolation mechanismSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Undo file changes
Not documentedNo first-class support established by the current recordAbsence of current documentation is not proof that the capability is impossible.

Primary evidence

Each capability claim is tied to a first-party record and a verification date.

Product record checked 2026-07-27
View 11 additional sources
Product and interfaces1 sources
Execution and control4 sources
Agents, state and recovery1 sources
Enterprise and operations2 sources
Releases and public code audit3 sources