At a glance
An open-source general agent with desktop, CLI, and headless use, broad provider, subscription, and local-model access, plus MCP extensions, recipes, subagents, browser control, configurable approvals, and platform-specific isolation.
Good choice if
- Open-standard and MCP-heavy workflows
- Users who want desktop, CLI, headless, local-model, and subscription choices
- Reusable automation through recipes, extensions, and subagents
Check before choosing
- Broader than a code-only specialist
- Developer tools run autonomously with user privileges by default unless approval policies are configured
- The documented native OS sandbox is specific to goose Desktop on macOS; other isolation paths are optional
See 4 more considerations
- Adversary Mode is optional, reviews only configured tools, and fails open when its reviewer fails; prompt-injection detection is also optional and cannot catch every threat
- ML-based prompt-injection detection can send tool-call content and recent messages to the configured classifier endpoint, while allowed commands still run with the user's full permissions
- goose CLI versions before 1.44.0 are affected by a high-severity arbitrary-command-execution advisory in goose review and should not be treated as equivalent to the verified release
- Large-repository support uses analysis tools and context guards, not a documented persistent repository index or scale guarantee