Skip to content
CAI
Software that uses CAICheck a score

aaif-goose/goose

54.3

Weak · 27 September 2026

317.4k

lines of production code

Rust

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Goose is an open-source, extensible AI agent framework that orchestrates interactions with large language models through a structured state machine and the Agent Client Protocol (ACP). It supports a wide array of cloud and local inference providers, enabling capabilities such as live voice dictation, code analysis, and automated workflow execution via recipes. The system provides robust tool management, security controls, and cross-language SDK bindings for Python and Kotlin, while offering both a CLI and an Electron-based desktop application for user interaction.

How it got here

2024–2025 — Rust rewrite and desktop launch

65 changes.

The project underwent a major architectural shift, replacing the legacy Python CLI with a new Rust-based core featuring a structured state machine, declarative configuration, and robust security controls. This period saw the introduction of the Electron-based desktop application, expanded provider support, and advanced agent capabilities like voice interaction and session management. Concurrently, the documentation site was completely redesigned to support the new brand and ecosystem, including recipes and MCP server integration.

2026 — ACP protocol and platform expansion

58 changes.

This period focused on implementing the Agent Client Protocol (ACP) server and client infrastructure, establishing a unified provider system with declarative configuration, and expanding the agent's capabilities through new platform extensions like Developer, Analyze, and Apps. The work also introduced cross-language SDK bindings via UniFFI, enhanced local inference with native tool calling, and added robust plugin and hook support to extend the ecosystem.

Features

ACP server exposes new custom methods for apps, dictation, and agent mentions

The ACP server now implements a suite of new custom JSON-RPC methods to manage MCP apps (list, export, import, delete), handle voice dictation (transcribe, configure, manage local models), and resolve agent mentions (listing recipes and sub-recipes). These handlers are registered in the custom dispatch layer and include schema definitions for agent-to-client requests, enabling clients to interact with these features directly over the ACP protocol.

crates/goose/src/acp/server · high confidence

ACP server implementation and protocol integration

The ACP server module has been implemented, introducing core components for the Agent Client Protocol including session management, tool execution (file read/write, terminal), permission handling, and context handoff. This adds the server-side infrastructure for ACP clients to interact with Goose agents, including support for MCP app proxying and live voice conversations.

crates/goose/src/acp · high confidence

Add 'Copy as Markdown' button to documentation pages

Users can now click a new 'Copy as Markdown' button on documentation pages to copy the page content as clean Markdown to their clipboard. The feature uses the Turndown library to convert the HTML content, stripping out navigation, footers, and other UI elements, while intelligently handling video embeds (converting YouTube/Vimeo iframes to watch URLs) and custom components like video carousels and category grids.

documentation/src/theme/DocItem · high confidence

Add GDK API Reference component with multi-language and version support

The documentation now includes a new \GdkApiReference\ component that renders the GDK API documentation with support for switching between Rust, Python, and Kotlin language bindings, as well as selecting specific API versions. The component reads version and language parameters from the URL to preserve user selection across navigation and ensures that deep-link anchors remain stable regardless of the selected language or version.

documentation/src/components/GdkApiReference · high confidence

Add MCP Wiki example server

Added a new example MCP server in the \examples/mcp-wiki\ directory that provides a \read\_wikipedia\_article\ tool. This tool fetches a Wikipedia article from a provided URL, extracts the main content, and converts it to Markdown. The example includes the necessary Python source files, a README with setup and testing instructions, and configuration files for the Python environment.

examples, examples/mcp-wiki · high confidence

Add UniFFI example applications for Python and Kotlin

New example applications have been added to demonstrate the in-process GDK UniFFI bindings. The Python example (\provider.py\) showcases the declarative provider model using DeepSeek, while the Kotlin/JVM smoke test (\Main.kt\) demonstrates the native OpenAI provider via a Maven artifact. These examples include necessary README documentation and configuration to help users verify the bindings work correctly on their local environments.

crates/goose-sdk/examples/uniffi · high confidence

Add documentation for Goose Recipes styles and type definitions

This change introduces new documentation pages for the Goose Recipes feature. It adds a CSS file defining the visual styles, including the Cash Sans font family, a comprehensive set of light and dark mode color tokens (Arcade colors), and specific styling for command toggles and content blocks. It also adds a React component that documents the TypeScript type definitions used in the Prompt Library, specifically detailing the structures for EnvironmentVariable, Extension, Category, and Prompt.

documentation/src/pages/recipes/styles, documentation/src/pages/recipes/types · high confidence

Add hello-hooks example plugin to demonstrate the hook system

An example plugin named 'hello-hooks' has been added to the examples directory to showcase the platform's hook capabilities. This plugin registers handlers for SessionStart, UserPromptSubmit, PreToolUse, and PostToolUse events, executing a shell script that logs event payloads and prints status messages to stderr, providing a concrete reference for building custom event-driven plugins.

examples/plugins/hello-hooks · high confidence

Add interactive Recipes Cookbook with search, filtering, and detail views

The documentation site now includes a dedicated Recipes Cookbook section, featuring a landing page (\/recipes\) with keyword search, pagination, and filtering by extensions, as well as a detail page (\/recipes/detail\) that displays recipe metadata, activities, and provides a one-click copy button for the CLI execution command.

documentation/src/pages/recipes · high confidence

Add social sharing buttons to blog posts

Blog posts now include a 'Share' button in the header metadata area, allowing readers to share the post on Twitter/X, LinkedIn, Facebook, and Reddit, or copy the post link to their clipboard. This new SocialShare component is integrated into the blog post header via a theme override, appearing alongside existing post metadata when viewing an individual blog post.

documentation/src/components/SocialShare, documentation/src/theme/BlogPostItem · high confidence

Added new documentation icon components

The documentation site now includes a set of new SVG icon components in the \documentation/src/components/icons\ directory. These additions support specific UI features, including category indicators for ETFs and moving items, a download action icon, a brand logo for the 'Goose' entity, and social media icons for Facebook, LinkedIn, Reddit, and Twitter. Additionally, a 'Pay in Four' payment method icon is provided in both SVG and React component formats.

documentation/src/components/icons · high confidence

Automated CLI command documentation tracking pipeline

A new automation pipeline in \documentation/automation/cli-command-tracking\ automatically detects changes to the Goose CLI commands and options between releases and updates the CLI Commands Guide. The pipeline uses deterministic scripts to extract the CLI structure from the binary, diffs the structures to identify added, removed, or modified commands and options, and then uses AI-powered recipes to synthesize human-readable change documentation and apply targeted updates to the existing guide. This ensures the CLI documentation stays synchronized with code changes without manual intervention.

documentation/automation · high confidence

Automated GitHub-to-Buzz issue synchronization

New automation tools in the buzz directory now connect GitHub issues to the public Goose Buzz community. A dedicated 'Github Manager' identity creates and manages issue channels, posts summaries, and syncs channel topics, while a managed bot (e.g., Doose) can review issues when explicitly mentioned. The system includes scripts to create the manager identity, generate issue channels with core team members and bots, list pending work based on assignment load, and synchronize issue states (like archiving closed issues) between GitHub and Buzz.

buzz · high confidence

Automated OpenRouter onboarding with PKCE authentication

New users can now sign up for OpenRouter directly within Goose via an automated, out-of-the-box experience. The system implements a PKCE (Proof Key for Code Exchange) flow that opens the OpenRouter authorization page in the browser, spins up a local callback server on localhost:3000 to capture the authorization code, and exchanges it for an API key. Once authenticated, the configuration is automatically updated to use the OpenRouter provider with the default model (anthropic/claude-sonnet-4). This change introduces the \signup\_openrouter\ module, including the authentication logic, the local HTTP server for handling callbacks, and the associated unit tests for the PKCE flow and HTML escaping.

_crates/goose/src/config/signup\openrouter · high confidence

Blog post and demo notebook for MCP Jupyter Server

Added a new blog post and an accompanying Jupyter notebook demo to the documentation site. The post introduces the MCP Jupyter Server, explaining how it enables AI agents to interact with Jupyter notebooks while maintaining persistent kernel state and variable context. The included demo notebook illustrates a typical data science workflow, including installing libraries, generating synthetic data, training a linear regression model with scikit-learn, and visualizing results with seaborn.

documentation/blog/2025-08-04-mcp-jupyter-server · high confidence

Conversation compaction to extend session context

The \goose-context-management\ crate now provides a conversation compaction feature that summarizes message history into a single summary message, allowing sessions to continue past a model's context window. When a provider returns a \ContextLengthExceeded\ error, the new \CompactingProvider\ wrapper automatically triggers this compaction, replaces the full history with the summary, and retries the request. The compaction process uses a structured JSON schema to capture user intent, technical concepts, file activities, errors, and pending tasks, which is then rendered into a readable format. Users can customize the compaction prompts by placing modified copies at \\~/.config/goose/prompts/compaction\_summary.md\.

crates/goose-context-management/src · high confidence

Expanded provider catalog with new declarative definitions

This update adds declarative configuration files for a wide range of new and updated AI providers, significantly broadening the models available to users. New supported providers include AI/ML API, Alibaba (Qwen), Atomic Chat, Celeris, EmpirioLabs, EUrouter, Fireworks AI, Friendli AI, FuturMix, iFlytek (Spark and Astron), Inception, Llama Swap, LM Studio, Lynkr, Meta (Muse Spark), Mistral AI, Moonshot, NEAR AI Cloud, Novita AI, NVIDIA, Ollama Cloud, oMLX, OpenCode (Go and Zen), Opper, OrcaRouter, OVHcloud, Perplexity, PleumRouter, Routstr, Sakana AI, and SaladCloud. Existing providers have also been updated: DeepSeek models now include 'deepseek-flash' alongside 'deepseek-v4-pro' and 'deepseek-reasoner'; Groq has 'preserves\_thinking' explicitly disabled; and MiniMax now supports the M3 and M2.7 variants. These definitions allow users to connect to these services directly through the declarative provider system.

crates/goose-providers/src/declarative · high confidence

Homepage features section and testimonials added

The documentation site now includes a new HomepageFeatures component that displays four key product capabilities (Open Source, Runs Locally, Extensible, Autonomous) with icons, followed by a 'Loved by engineers' section showcasing testimonials from various users. The component uses local CSS modules for styling, including specific styles for feature icons and a video container (though no video is currently rendered in the JSX).

documentation/src/components/HomepageFeatures · high confidence

Import sessions from Claude Code, Codex, and Pi

Users can now import conversation history from other coding agents into Goose. The new \import\_formats\ module adds converters for Claude Code \.jsonl\ transcripts, Codex (OpenAI) \.jsonl\ rollouts, and Pi-mono \.jsonl\ sessions. These formats are automatically detected and converted into Goose's native session JSON, preserving message content, tool responses, timestamps, and token usage statistics (including cache read/write tokens).

_crates/goose/src/session/import\formats · high confidence

Initial repository scaffolding and developer documentation

The repository has been initialized with essential configuration and documentation files to support development and distribution. A Dockerfile and associated guides (BUILDING\_DOCKER.md, BUILDING\_LINUX.md) provide instructions for building and running the goose CLI and desktop application in containerized and Linux environments. Developer workflows are standardized via a Justfile for build and lint tasks, while AGENTS.md and .goosehints establish contribution guidelines and AI-assisted coding rules. Additional files include .dockerignore and .gitattributes for build hygiene, GOVERNANCE.md and CODE\_OF\_CONDUCT.md for community standards, and I18N.md detailing the internationalization infrastructure for the desktop UI.

(repo-wide) · high confidence

Introduce AskAI Discord bot service with Anthropic integration

A new AskAI Discord bot service has been added to the repository, providing a standalone Dockerized application for answering user questions in the Goose Discord server. The bot connects to Discord using the discord.js library and leverages the Anthropic API (via @ai-sdk/anthropic) with the default model set to claude-sonnet-4-6. It features a suite of AI tools that allow the bot to search and view project documentation, search and view the local codebase, and query GitHub issues and pull requests. The service includes a Dockerfile for containerization, environment configuration examples, and a TypeScript-based architecture for handling message events and streaming responses.

services · high confidence

Introduce Autovisualiser extension for interactive data charts

The goose-mcp crate now includes an Autovisualiser extension that allows users to generate interactive visualizations directly from structured data. This feature supports multiple chart types, including line, bar, scatter, Sankey, radar, donut/pie, treemap, chord, and Mermaid diagrams. The extension leverages the rmcp SDK and integrates with the MCP Apps UI capability, providing embedded HTML-based charts via Chart.js and D3.js libraries. Users can trigger these visualizations through specific tools (e.g., render\_sankey) that accept JSON data, with the system handling parameter validation and rendering.

crates/goose-mcp · high confidence

Introduce Harbor-based benchmark runner and comparison tooling for Goose

Added a new evaluation harness in \evals/harbor\ that uses the Harbor 0.8 benchmarking framework to run and compare terminal-bench tasks against Goose. This includes a custom \GooseBinaryAgent\ adapter that uploads a local Goose binary into task containers, a CLI (\cmd.py\) for running, listing, and comparing benchmark jobs, and a reporting module that calculates trial status, token usage, and costs. The tooling also provides agent recipes for automated failure analysis and run comparison, enabling users to benchmark different Goose builds, models, and extensions against the \terminal-bench-2\ dataset.

evals · high confidence

Introduce OIDC Proxy for secure GitHub Actions API access

The new oidc-proxy Cloudflare Worker enables CI workflows to call upstream APIs (such as Anthropic or OpenAI) using short-lived GitHub Actions OIDC tokens instead of long-lived secrets. The proxy validates the JWT against GitHub's JWKS, enforces both the IdP's \exp\ claim and an operator-configurable \MAX\_TOKEN\_AGE\_SECONDS\ cap, and applies per-token request budgets and rate limits via a Durable Object. It injects the real upstream API key into the request headers and forwards the call, allowing workflows to authenticate securely without storing static credentials.

oidc-proxy · high confidence

Introduce bundled MCP app support with a default clock widget

The application now includes a built-in MCP app ecosystem, starting with a default 'Swiss Railway Clock' widget. This feature adds a new \goose\_apps\ module that handles the lifecycle of these apps, including a cache system to store and retrieve app definitions and a parser to extract metadata (such as name, dimensions, and required MCP servers) from HTML resources. The bundled clock app is automatically initialized and protected from deletion, while user-installed apps are marked as deletable. The implementation also defines the data structures for MCP app resources, including support for Content Security Policy (CSP) and browser permission policies (camera, microphone, etc.) to ensure secure sandboxing.

_crates/goose/src/goose\apps · high confidence

Introduce cross-language SDK bindings and release tooling

The goose-sdk now exposes a cross-language API via UniFFI, generating native bindings for Python and Kotlin so developers can interact with the goose agent from those languages. To support this, the SDK includes build automation (justfile) and release scripts that handle generating bindings, packaging Python wheels and Maven artifacts, and synchronizing versions across Rust, Python, and Kotlin packages. The release process is standardized using release-plz to manage version bumps and publication of the GDK packages.

crates/goose-sdk · high confidence

Introduce custom ACP notification and request type definitions

The \goose-sdk-types\ crate now exposes the Rust type definitions for Goose's custom \\goose/\\ JSON-RPC methods and notifications. This includes session update notifications (carrying usage stats, status messages, and live voice interaction events) and provider authentication notifications (for OAuth device-code flows), alongside request types for managing session extensions, listing/calling tools, managing Goose apps, and updating session working directories. These types provide the single source of truth for the wire format of these custom ACP methods.

crates/goose-sdk-types/src · high confidence

Introduce lifecycle hooks for plugins

Users can now configure plugins to execute custom scripts at specific points in the agent's lifecycle, such as before or after tool usage, session start/end, and file edits. This is achieved by adding a \hooks/hooks.json\ file to any discovered plugin, where users define rules matching specific events (e.g., \PreToolUse\, \PostToolUse\) and command actions to run. The system supports command-type hooks with configurable timeouts and failure handling, allowing for extensible automation and monitoring of agent activities.

crates/goose/src/hooks · high confidence

Introduce local Whisper transcription and model-native audio support

The dictation module now supports two new transcription modes. First, when the local-inference feature is enabled, users can transcribe audio locally using OpenAI's Whisper model via the Candle ML framework, with configurable models (tiny, base, small, medium) and language selection via the LOCAL\_WHISPER\_LANGUAGE setting. Second, a new ModelNative provider allows using the active chat model for transcription, supporting models with native audio input capabilities like Gemini, GPT-4o-audio, and Gemma4, eliminating the need for a separate API key for dictation.

crates/goose/src/dictation · high confidence

The \goose review\ command now supports local code review checks defined in \.agents/checks/\.md\ and \\\*/.agents/REVIEW.md\ files. These checks are parsed using a shared YAML frontmatter pipeline and expose tunables such as model override, turn limits, allowed tools, and severity defaults. To ensure security, the discovery process now rejects check sources that are symlinks, preventing potential path traversal or unintended file inclusion.

crates/goose/src/checks · high confidence

Introduce local download manager with progress tracking and partial file cleanup

The goose-download-manager crate now provides a centralized system for managing model downloads, including tracking progress (status, bytes, speed, ETA) and handling sharded downloads with optional bearer token authentication. It introduces a cleanup mechanism that automatically removes orphaned \.part\ files while preserving in-progress downloads registered by the system, ensuring resume capability after restarts.

crates/goose-download-manager · high confidence

Introduce the goose-agent crate with an unrolled state machine for agent operations

The new goose-agent crate provides the core agent loop, replacing previous implementations with an unrolled state machine defined in machine.rs. This architecture introduces a modular operation system (operation.rs) where distinct steps like inference (inference.rs) and tool handling (tool.rs) are executed sequentially. Users benefit from a more structured agent workflow that explicitly manages conversation history, tool registration, and provider inference calls within a single, cohesive agent loop.

crates/goose-agent/src · high confidence

Introduces a new provider-types crate with unified provider metadata, canonical model registry, and prompt-cache semantics

This change introduces the \goose-provider-types\ crate, establishing a foundational layer for provider configuration and model management. It adds structured metadata for providers (including OAuth support and deprecation info), a canonical model registry for mapping provider-specific model names to standard identifiers, and explicit prompt-cache semantics to optimize cost and performance across different providers. Additionally, it includes utilities for handling conversation messages, document and image formats, context limits, and robust JSON parsing to recover from malformed model outputs.

crates/goose-provider-types/src · high confidence

Introduces goose-provider-types crate with compressed model catalog

This change adds the new \goose-provider-types\ crate, which defines the core provider contract (the \Provider\ trait and \MessageStream\) and shared conversation types. It includes a build script that compresses the \canonical\_models.json\ catalog into a \.zst\ file at build time, and provides documentation for implementing providers and working with messages.

crates/goose-provider-types · high confidence

Introduces in-process bindings for Python and Kotlin via UniFFI

The SDK now exposes an in-process API to Python and Kotlin through a new UniFFI setup, allowing these languages to interact directly with the Rust-based GDK without relying on external processes or JSON-only shims. This change adds the necessary scaffolding, including a bindgen binary and a comprehensive bindings module that maps provider messages, tool streaming, and error types (such as rate limits and authentication failures) to the target languages. Additionally, it introduces structured observability hooks, enabling Python and Kotlin callers to register callbacks for detailed request lifecycle events (start, response metadata, completion) and optional payload capture, providing better visibility into provider interactions.

crates/goose-sdk/src · high confidence

Langfuse integration for application tracing

Added a new tracing layer that exports application spans and events to Langfuse. This includes a batch manager that sends observation data (spans and traces) to the Langfuse ingestion API, supporting configuration via environment variables for public/secret keys and the base URL. The implementation handles span creation and closure, mapping internal trace levels to Langfuse observation levels, and ensures trace IDs are correctly propagated.

crates/goose/src/tracing · high confidence

Live voice conversations and agent self-healing diagnostics

Users can now start live voice conversations directly from the desktop app, where the voice interface handles real-time transcription, user interruptions, and delegates complex backend tasks to the main agent. Additionally, a new /doctor slash command allows the agent to automatically diagnose and fix provider or model configuration issues by testing connectivity and switching to a working alternative when the current setup fails.

crates/goose/src · high confidence

MCP session recording and playback tooling

The goose-test crate now includes a CLI binary and library modules for capturing and replaying MCP (Model Context Protocol) stdio sessions. Users can record command interactions to a log file and subsequently playback those sessions to verify behavior, with the playback mode validating that inputs match recorded expectations and reporting mismatches to an error file.

crates/goose-test · high confidence

New ACP client example and DeepSeek provider configuration

The examples directory now includes a new Rust-based ACP (Agent Client Protocol) client example that spawns the goose binary, initializes a session, and handles agent responses and permission requests via stdio. Additionally, a new DeepSeek provider configuration file has been added, defining the deepseek-v4-flash and deepseek-reasoner models with their respective context limits and streaming support.

crates/goose-sdk/examples · high confidence

New CLI diagnostic and documentation tools

The Goose CLI now includes a \goose doctor\ command to run a diagnostic session and a \goose info\ command to display configuration paths and verify provider connectivity. Additionally, a new \generate\_manpages\ binary has been added to automatically generate Unix manpages from the CLI definitions, improving offline documentation access for Linux and macOS users.

crates/goose-cli · high confidence

New CLI tools for code analysis, canonical model management, and ACP schema generation

This change introduces four new command-line binaries to the goose crate. The \analyze\_cli\ tool allows users to perform ad-hoc code analysis using tree-sitter, supporting focused symbol call graphs, single-file semantic details, and directory structure overviews. The \build\_canonical\_models\ script fetches model data from the models.dev API and generates a canonical model mapping report, helping users verify provider model coverage. The \generate\_acp\_schema\ utility produces JSON Schema definitions for the ACP protocol, handling unstable type naming and TypeScript codegen compatibility. Finally, \goose-acp\ provides a dedicated binary entry point for running the ACP server, supporting optional builtin extensions via the \--with-builtin\ flag.

crates/goose/src/bin · high confidence

New Community Landing Page with All-Stars and Content Spotlight

The documentation site now includes a dedicated Community landing page that showcases an embedded calendar for upcoming events, a monthly 'Community All-Stars' section with a dropdown to view top contributors by month, and a 'Community Content' spotlight featuring filterable blog posts and videos.

documentation/src/pages/community · high confidence

New Developer extension with file, image, and shell tools

The Developer extension now provides a set of tools for software development workflows. The \write\ and \edit\ tools allow creating and modifying files, with the edit tool offering context-aware suggestions when text replacements fail to match. The \read\_image\ tool loads images from local paths or HTTP(S) URLs, supporting cropping and returning structured metadata alongside the image data. The \shell\ tool executes commands with streaming output support, respecting the \GOOSE\_SHELL\ environment variable and handling platform-specific behaviors like Flatpak sandboxing. The \tree\ tool lists directory structures with line counts while respecting \.gitignore\ rules.

_crates/goose/src/agents/platform\extensions/developer · high confidence

New Electron-based Goose Desktop application scaffolding

The \ui/desktop\ directory now contains the initial scaffolding for a native desktop application built with Electron, React, and Vite. This includes the core configuration for packaging and distribution via Electron Forge (supporting macOS, Windows, and Linux builds including Flatpak), a Vite-based build pipeline, and a custom ESLint configuration. The app integrates with the ACP backend, supports the \goose://\ deep-link protocol, and includes infrastructure for internationalization (i18n) and macOS auto-updates.

ui · high confidence

New Kotlin SDK Maven package with multi-provider support

The \goose-sdk\ now publishes a Maven artifact (\io.github.aaif-goose:gdk\) containing UniFFI-generated Kotlin/JVM bindings for the Rust SDK. This package includes native libraries for macOS (Intel/Apple Silicon), Linux, and Windows, and provides Kotlin wrapper functions for the Anthropic, Databricks, Groq, and OpenAI providers. The OpenAI provider specifically supports a custom \baseUrl\ parameter, allowing users to connect to compatible API endpoints beyond the default.

crates/goose-sdk/maven · high confidence

New OpenTelemetry OTLP integration with Tokio runtime support

Added a new OpenTelemetry module (crates/goose/src/otel) that integrates OTLP tracing, metrics, and logging into Goose. To prevent background-thread panics when using the async HTTP exporter, the implementation wraps exporters in a dedicated single-thread Tokio runtime. It supports configuring the exporter type (OTLP or Console) and respects standard OpenTelemetry environment variables for protocol and endpoint selection.

crates/goose/src/otel · high confidence

New SDK types for recipe parameters and scheduler management

The SDK now exposes data structures and JSON-RPC request types for managing recipes and scheduled jobs. The new \recipe.rs\ module defines the \RecipeDto\ schema, including fields for parameters, extensions, and retry configurations, along with the \\_goose/unstable/session/recipe/request-params\ method to retrieve recipe inputs. The \schedule.rs\ module adds support for the scheduler with methods to list, create, update, pause, unpause, and delete scheduled recipe jobs, as well as to run jobs immediately, inspect running jobs, and list sessions generated by schedules.

_crates/goose-sdk-types/src/custom\requests · high confidence

New UI component library for documentation site

The documentation site now includes a new set of reusable UI components located in \documentation/src/components/ui\. This addition introduces \Badge\, \Button\, \Card\ (with \CardHeader\ and \CardContent\), \Input\, \PillFilter\, and \SidebarFilter\. These components provide standardized styling and interaction patterns for the documentation interface, supporting features like filtering and content display.

documentation/src/components/ui · high confidence

New benchmarking, diagnostics, and build tooling scripts

This change introduces a suite of new scripts to support the Goose benchmarking framework, diagnostics inspection, and Windows desktop builds. The \bench-postprocess-scripts\ directory adds Python tools to generate leaderboards from aggregate metrics, run LLM-based judges for 'vibes' evaluations (blog summary, restaurant research), and calculate final scores. A new \diagnostics-viewer.py\ provides an interactive terminal UI to browse JSON diagnostics reports and copy long strings to the clipboard. Additionally, \run-benchmarks.sh\ and \parse-benchmark-results.sh\ automate benchmark execution and failure analysis, while \build-windows.ps1\ streamlines the Windows desktop build process with the VMware Tanzu Platform provider. A \goose-db-helper.sh\ script is also added to manage session database migrations and backups.

scripts · high confidence

New blog post about the first Goose Meetup in Boston

A new blog post titled 'Codename Goose Goes to Boston' has been added to the documentation site, detailing the first community meetup held in Boston. The post covers event highlights, including lightning talks on Goose and the Model Context Protocol (MCP), hands-on hacking sessions, and community feedback, along with social media links for future events.

documentation/blog/2025-03-21-goose-boston-meetup · high confidence

New blog post on Block's enterprise adoption of MCP

A new blog post titled 'MCP in the Enterprise: Real World Adoption at Block' has been added to the documentation site. The article details how Block uses the Model Context Protocol (MCP) and their open-source agent, Goose, to power company-wide automation. It covers the security philosophy, configuration strategies (including OAuth and LLM allowlists), and real-world impact across engineering, data, and non-engineering teams.

documentation/blog/2025-04-21-mcp-in-enterprise · high confidence

New blog post on Goose VS Code integration

A new documentation blog post titled 'Cracking the Code with VS Code MCP' has been added, detailing how to connect Goose to Visual Studio Code via the Model Context Protocol. The post covers key features such as intelligent context awareness, interactive code modifications via diff tools, and real-time visual feedback, while also outlining future roadmap items like custom diff tools and terminal integration.

documentation/blog/2025-03-21-goose-vscode · high confidence

New blog post on building a chaotic emotion detection app with Goose

Added a new blog post documenting the creation of a playful, emotion-reactive web application using Goose. The article details the development strategy, including prompt chaining and model selection, and provides a link to a live demo, the source repository, and a Goose recipe for users to build their own chaotic UI that reacts to facial expressions.

documentation/blog/2025-06-17-goose-emotion-detection-app · high confidence

New blog post on making MCP servers MCP-UI compatible

Added a new documentation blog post titled 'How to Make An MCP Server MCP-UI Compatible' which guides users on integrating the @mcp-ui/server SDK to transform raw text responses into interactive, rich UI components within the agent's chat interface. The post details the implementation pattern for TypeScript and Ruby servers, including installing the SDK, creating HTML resources, and handling interactive elements like buttons and media previews.

documentation/blog/2025-09-08-turn-any-mcp-server-mcp-ui-compatible · high confidence

New blog post on streamlining detection development with Goose recipes

Added a new blog post titled 'Streamlining Detection Development with Goose Recipes' that explains how the Panther detection engineering team uses Goose recipes and subrecipes to automate the security detection creation lifecycle. The post details the architecture of the workflow, including six specialized subrecipes (workflow\_setup, similar\_rule\_analyzer, schema\_and\_sample\_events\_analyzer, rule\_creator, testing\_validator, and pr\_creator) that handle repository preparation, pattern analysis, schema validation, rule implementation, testing, and pull request creation. It also covers design principles like single responsibility and explicit data flow, as well as smart optimizations for conditional execution based on parameters and runtime conditions.

documentation/blog/2025-07-28-streamlining-detection-development-with-goose-recipes · high confidence

New blog post on top MCP servers for developer workflows

A new blog post titled "Top 5 MCP Servers I Use as a Developer with Goose" has been added to the documentation site. The article details five specific Model Context Protocol (MCP) extensions—GitHub MCP Server, Knowledge Graph Memory, Fetch Extension, Memory Extension, and the VS Code Extension—and explains how they integrate with the Goose agent to automate tasks like pull request reviews, context retrieval, and code change previews.

documentation/blog/2025-04-01-top-5-mcp-servers · high confidence

New code analysis extension for navigating and understanding codebases

A new 'analyze' platform extension has been added to Goose, enabling the agent to parse and understand code structure using tree-sitter. This extension supports Rust, Python, JavaScript, TypeScript, TSX, Go, and Swift, and provides three distinct views: a directory structure summary (showing file counts, lines of code, and function/class totals), a semantic file view (listing functions, classes, imports, and call frequencies), and a focused call-graph view that traces incoming and outgoing dependencies for a specific symbol. The tool helps users quickly navigate unfamiliar or large codebases by providing structured summaries and dependency maps.

_crates/goose/src/agents/platform\extensions/analyze · high confidence

New documentation and community contribution scripts

This update adds several new scripts to the documentation folder to improve content management and community recognition. A new Python script and team list file automate the generation of 'Community Stars' rankings by analyzing GitHub contributor data and categorizing users as external, Block employees, or maintainers. Additionally, a JavaScript script and its test suite now generate an ACP (Agent Communication Protocol) reference documentation page directly from release schemas, while another script creates a navigable documentation map from markdown files. Supporting utilities include a static file server for testing markdown exports and a build verification script to ensure the documentation map is present in the final output.

documentation/scripts · high confidence

New documentation build plugins for Tailwind, YAML, and Markdown export

The documentation build system now includes three new plugin files in the \documentation/plugins\ directory. The \tailwind-config.cjs\ plugin configures PostCSS to use Tailwind CSS and Autoprefixer, enabling Tailwind-based styling for the docs site. The \custom-webpack.cjs\ plugin adds Webpack loaders for YAML files and raw text assets, allowing these file types to be imported directly. The \markdown-export.cjs\ plugin adds a post-build step that exports cleaned Markdown files (stripping frontmatter and MDX imports) alongside the generated HTML, making the documentation content accessible as standalone Markdown.

documentation/plugins · high confidence

The documentation site now includes several new pages to guide users through key workflows. A new Deeplink Generator page allows users to create and manage deep links for installing extensions, supporting both local (stdio) and remote (streamable HTTP) server configurations, with automatic parsing of URL parameters for quick setup. An Extension Redirect page handles the \goose://extension\ protocol to seamlessly open the Goose desktop app for installation. Additionally, a Grants page details the $100K open-source grant program, outlining eligibility, application processes, and FAQ, while the homepage has been updated with new styling and content highlighting goose's features, stats, and extensibility.

documentation/src/pages · high confidence

New example programs for agent, provider, and authentication workflows

Added five new Rust example programs in crates/goose/examples to demonstrate core capabilities: agent.rs shows how to initialize an agent with a session, add MCP extensions, and stream replies; databricks\_oauth.rs and image\_tool.rs demonstrate direct provider usage for text and image content respectively; test\_whisper.rs illustrates local audio transcription using the Whisper model; and tetrate\_auth.rs walks through the PKCE authentication flow for the Tetrate Agent Router Service.

crates/goose/examples · high confidence

New goose-providers crate consolidates provider implementations and introduces declarative configuration

The provider logic has been moved into a new \goose-providers\ crate, centralizing the \Provider\ trait, \ApiClient\, and \TlsConfig\ alongside implementations for OpenAI, Anthropic, Google, Databricks, and Azure AI Foundry. This change introduces a declarative provider system that allows new providers to be registered via configuration files, and adds support for new capabilities such as OpenAI Live (WebSocket) and browser-based WebRTC transport. Example files demonstrate how to use the new streaming and declarative APIs.

crates/goose-providers/src · high confidence

New platform extensions for apps, chat recall, and code execution

The platform extensions system has been expanded with new capabilities: the Apps extension allows creating and managing custom HTML/CSS/JavaScript apps through chat; the Chat Recall extension enables searching past conversations and loading session summaries for contextual memory; and the Code Execution extension (Code Mode) allows Goose to make extension calls through code execution to save tokens. These are registered as new platform extensions alongside existing ones like Developer, Summon, and Extension Manager.

_crates/goose/src/agents/platform\extensions · high confidence

New procedural macro for declarative ACP custom method handlers

The \goose-acp-macros\ crate introduces a \\#\[custom\_methods\]\ procedural macro that simplifies the implementation of ACP extension methods. By annotating an impl block with this macro and marking individual handler functions with \\#\[custom\_method(RequestType)\]\, the macro automatically generates a JSON-RPC dispatcher and schema definitions. This eliminates manual routing logic and ensures that request method names, parameter parsing, and JSON Schema generation are derived directly from the handler signatures at compile time.

crates/goose-acp-macros · high confidence

New provider format adapters for Anthropic, Databricks, Google, Ollama, OpenAI, and Snowflake

The provider-type layer now includes dedicated format adapters for Anthropic, Databricks, Google, Ollama, OpenAI, OpenAI Responses, and Snowflake. These modules translate internal messages into each provider's API wire format and parse their responses back into the internal model. Key capabilities include first-class thinking/reasoning support (with adaptive thinking, explicit disable, and cache-TTL controls for Anthropic), XML-style tool-call fallback for Ollama models like Qwen3-coder, thought-signature handling for Google, and document/image handling across providers. This change adds the format-conversion logic in crates/goose-provider-types/src/formats; wiring of these adapters to the provider runtime is handled in other crates.

crates/goose-provider-types/src/formats · high confidence

New provider format modules for Bedrock and GCP Vertex AI

The \crates/goose/src/providers/formats\ directory now includes dedicated format modules for AWS Bedrock and GCP Vertex AI. The new \bedrock.rs\ module implements Bedrock-specific message formatting, including support for adaptive thinking, explicit inference configuration (max\_tokens, temperature), and prompt caching. The new \gcpvertexai.rs\ module adds support for GCP Vertex AI models (Claude and Gemini), handling model routing by location (e.g., Global for Gemini 3.x) and defining known model lists. These modules are exported via \mod.rs\, making them available for use by their respective providers.

crates/goose/src/providers/formats · high confidence

New provider implementations and declarative configuration support

This change introduces several new provider implementations and enhances the provider configuration system. New providers include Amp (via the amp-acp adapter), Avian (supporting DeepSeek, Kimi, GLM, and MiniMax models), and declarative definitions for Anthropic and Azure Foundry. The Azure provider now supports both API key and Entra ID bearer token authentication, with automatic detection of v1 endpoints. Additionally, the Bedrock provider has been expanded to include support for OpenAI GPT-5.5, GPT-5.4, GPT-5.6 variants, and Google Gemma 4 models, with proper routing to Converse and MantleResponses endpoints. The system also introduces declarative provider configuration support, allowing users to define custom providers via configuration files, and adds cost estimation capabilities based on canonical model pricing.

crates/goose/src/providers · high confidence

New recipes added to the Community Recipe Cookbook

The Recipe Cookbook now includes a new set of community-contributed recipes, such as the A/B Test Framework Generator, CI/CD Pipeline Generator, Code Documentation Generator, and Data Analysis Pipeline. These additions expand the available automation capabilities for tasks ranging from web testing and DevOps to code analysis and data processing.

documentation/src/pages/recipes/data · high confidence

New release risk assessment workflow recipe

A new workflow recipe named 'Release Change Risk Check' has been added to the \workflow\_recipes\ directory. This tool helps identify high-risk pull requests for upcoming releases by generating a heuristic report based on file changes, lines of code, and core path analysis, and then feeding medium/high-risk PRs to an LLM for further risk assessment and testing suggestions. The recipe includes a Python script (\release\_risk\_report.py\) to collect PR data and a shell script (\run.sh\) to execute the workflow, enabling users to produce a comprehensive risk report before release.

_workflow\recipes · high confidence

New reusable documentation components for extensions, recipes, and platform-specific installation

The documentation site now includes a suite of new reusable React components to standardize and improve the user experience for extension installation, recipe browsing, and platform-specific setup. \GooseDesktopInstaller\ and \CLIExtensionInstructions\ provide step-by-step guides for installing extensions via the Desktop app (using \goose://\ deep links) or the CLI, supporting both local command-line and remote Streamable HTTP extension types. \ArchivedExtensionWarning\ alerts users when an extension is no longer maintained. For content discovery, \RecipeCard\ and \server-card\ display recipes and MCP servers with details like extensions, activities, and GitHub stars, while \ContentCard\ and \ContentCardCarousel\ offer a unified way to present videos, blogs, and topics. Platform-specific installation is handled by \LinuxDesktopInstallButtons\ (which dynamically detects architecture and offers DEB, RPM, and Flatpak downloads), \MacDesktopInstallButtons\, and \WindowsDesktopInstallButtons\. Additional components like \GooseLogo\ (with dark mode support), \SupportedEnvironments\, \RateLimits\, and \OnboardingProviderSetup\ provide consistent informational context for new and existing users.

documentation/src/components · high confidence

New security inspection framework with ML-based prompt injection detection and egress logging

The security module has been restructured into a modular inspection system that introduces several new capabilities. A new Adversary Inspector allows users to define custom security rules via an \adversary.md\ configuration file to review specific tool calls. The system now supports ML-based prompt injection detection using a \ClassificationClient\ that connects to external HuggingFace-style inference endpoints, configurable via the \SECURITY\_ML\_MODEL\_MAPPING\ environment variable, with automatic fallback to pattern-based detection if ML initialization fails. Additionally, an Egress Inspector has been added to log and analyze outbound network connections (such as URLs, SSH, SCP, S3, and Docker registries) from shell commands, providing directionality (inbound/outbound) for security auditing. These components are orchestrated by a central \SecurityManager\ and \SecurityInspector\ that integrate with the existing tool inspection pipeline.

crates/goose/src/security · high confidence

New session management capabilities: search, diagnostics, markdown export, and Nostr sharing

The session module now includes several new capabilities. Users can search chat history across sessions using the new \ChatHistorySearch\ component, which queries the SQLite database for keywords and returns matching sessions with message snippets. A new \Diagnostics\ module generates structured reports containing system info, configuration, logs, and errors for troubleshooting. Session exports can now be generated in Markdown format via \export\_markdown.rs\, handling tool calls and content with appropriate formatting and truncation. Additionally, sessions can be shared securely via Nostr using the \nostr\_share\ module, which publishes encrypted session data to relays and generates shareable deeplinks. The \session\_manager\ has been updated to support these features, including new session types (Terminal, Gateway, Acp), last message snippets for session lists, and extension state persistence.

crates/goose/src/session · high confidence

New static assets for goose-docs.ai and extensions registry

The documentation site now includes a CNAME file pointing to goose-docs.ai, a robots.txt file that explicitly allows major AI crawlers (such as GPTBot, Claude-Web, and Google-Extended), and an llms.txt file providing a structured summary of goose's features, concepts, and documentation links for AI consumption. Additionally, a servers.json file has been added to serve as the machine-readable registry for MCP extensions, listing both built-in extensions (like Auto Visualiser and Computer Controller) and third-party servers with their installation commands and environment variable requirements. The legacy CHANGELOG.md file has been renamed to .nojekyll to disable Jekyll processing on the static site.

documentation/static · high confidence

New test support utilities for MCP, OpenTelemetry, and session validation

The \goose-test-support\ crate now provides dedicated helpers to streamline integration testing. It includes an \McpFixtureServer\ that runs a local MCP server over Streamable HTTP with tools for retrieving code, images, and audience-scoped content, alongside a fixture example for manual testing. An \OtelTestGuard\ is introduced to safely isolate OpenTelemetry environment variables and tracer/meter providers during tests. Additionally, session management is standardized with an \ExpectedSessionId\ trait and implementations (\EnforceSessionId\, \IgnoreSessionId\) to validate or ignore session IDs, along with constants for a test model (\gpt-4.1\) and session ID.

crates/goose-test-support · high confidence

New type definitions for Prompt, Extension, and MCP Server documentation

Added TypeScript type definitions in the documentation source to structure content for the Prompt Library, Extension Library, and MCP Server sections. The new \Prompt\, \Extension\, and \MCPServer\ types define the schema for documentation entries, including fields for installation notes, environment variables, and server connection details, ensuring consistent data structures for the revamped extensions and prompts sites.

documentation/src/types · high confidence

New utility modules for documentation site functionality

Added several new utility modules to the documentation source code: \cn.ts\ for combining CSS classes, \github-stars.ts\ for fetching and caching GitHub repository star counts, \install-links.ts\ for generating deep links to install MCP servers (including support for streamable HTTP and environment variables), \mcp-servers.ts\ for fetching and searching the local MCP server registry, and \recipes.ts\ for loading, searching, and normalizing recipe data from YAML files into structured objects with encoded Goose recipe URLs.

documentation/src/utils · high confidence

OAuth credentials are now persisted to the system keyring

Goose now saves OAuth access tokens and client metadata to the operating system's secure credential store (keychain) instead of keeping them only in memory. This means users will not need to re-authorize every time the application restarts, as their valid sessions are restored automatically from the persistent storage.

crates/goose/src/oauth · high confidence

Recipes now support structured output, parameters, and sub-recipes

The recipe system has been expanded to allow users to define structured inputs and outputs. Recipes can now declare parameters (including file imports and selection lists) to prompt users for configuration before execution, and can specify a JSON schema in the response field to enforce structured model output. Additionally, recipes can now include sub-recipes to compose complex workflows, and users can configure specific settings like model, provider, and max turns directly within the recipe file.

crates/goose/src/recipe · high confidence

Slash commands now support built-in, recipe, and skill sources

Users can now invoke commands via slash syntax that are sourced from three distinct origins: built-in agent commands, user-defined recipes, and installed skills. The system automatically merges these sources into a single command list, with built-in commands taking precedence over recipes and skills in case of name collisions. Recipe-based commands are resolved from configuration mappings that link command names to recipe file paths, while skill-based commands are dynamically discovered from installed skill directories. This unified command interface allows users to access all available functionality through a consistent slash-command syntax.

_crates/goose/src/slash\commands · high confidence

Support for Gemini and Open Plugins formats

Users can now install plugins using the Gemini extension format (identified by \gemini-extension.json\) and the Open Plugins format (identified by \plugin.json\ or specific component markers like \.mcp.json\). The system detects these new formats, validates their manifests, and installs their associated skills, with Open Plugins skills being namespaced under the plugin name to avoid conflicts.

crates/goose/src/plugins/formats · high confidence

Support for Open Plugins with MCP server integration and auto-updates

Goose now supports the Open Plugins standard, allowing users to install and use plugins that expose skills and Model Context Protocol (MCP) servers. The system discovers plugins from both user-level and project-level directories (specifically \.agents/plugins\), respects enablement settings from configuration files and scoped settings files, and automatically updates installed plugins every 24 hours. Users can install plugins via git sources, and the application will parse their \mcp.json\ manifests to register the associated tools and servers as extensions.

crates/goose/src/plugins · high confidence

Tetrate Agent Router Service authentication with PKCE and dynamic local server

Users can now authenticate with the Tetrate Agent Router Service using a secure PKCE (Proof Key for Code Exchange) flow. The application starts a local callback server on a dynamic port to receive the OAuth authorization code, exchanges it for an API key, and automatically configures the provider. The flow includes user-friendly HTML feedback pages for success, error, and invalid request states, and ensures security by escaping HTML content in error messages to prevent XSS.

_crates/goose/src/config/signup\tetrate · high confidence

Unified agent execution management with session isolation

The execution module now provides centralized lifecycle management for Goose agents, introducing an \AgentManager\ singleton that caches agents per session using an LRU cache and serializes agent creation to prevent duplicate initialization of MCP extensions. A new \ActiveRunRegistry\ tracks active prompt runs and live voice interactions, ensuring that only one run type is active per session and preventing conflicts between them. This architecture enables multiple concurrent sessions with independent agent states, extensions, and providers, while handling cleanup and cancellation through dedicated token management.

crates/goose/src/execution · high confidence

Removals

Removal of legacy CLI and core runtime components

The \src/goose\ directory has removed the previous CLI implementation and core runtime files, including \build.py\, \cli/\ (config, main, session, prompt), \command/\, \notifier.py\, \profile.py\, \system.jinja\, and \toolkit/\ (base, developer, github, prompts, repo\_context). This eliminates the old session management, profile configuration, command execution, and toolkit infrastructure that previously powered the Goose CLI.

src/goose · high confidence

Architecture

Local inference provider restructured with new backend and configuration APIs

The local inference provider has been refactored to introduce a pluggable backend architecture (backend.rs) supporting both LlamaCPP and MLX inference engines, alongside a new configuration resolution system (config\_resolver.rs) for managing model settings and parameters. This change includes updated Hugging Face model discovery (hf\_models.rs) to handle non-standard filenames and preserve model sizes, new MLX backend integration using the safemlx crate (mlx.rs) with SafeTensors validation, and a dedicated management layer (management.rs) for model listing, downloading, and Hugging Face search. Additionally, the provider now enforces absolute paths for the Goose root directory (paths.rs) and includes improved multimodal image extraction (multimodal.rs) and native tool parsing (native\_tool\_parsing.rs) for local model responses.

crates/goose-local-inference/src · high confidence

Behavioural changes

7 commits (0 fixes) modifying documentation/static/videos

A change to existing behaviour in documentation/static/videos — 7 commits, 8 files.

documentation/static/videos · medium confidence · unverified

ACP transport now supports TLS and stricter origin authentication

The ACP transport layer now includes built-in TLS support, allowing the server to serve over HTTPS with either user-provided certificates or auto-generated self-signed ones (cached locally). Additionally, authentication for ACP endpoints has been strengthened: requests must now provide a secret key via the \X-Secret-Key\ header or \token\ query parameter, and WebSocket connections are restricted to specific origins (loopback, file://, or explicitly allowed) to prevent unauthorized cross-origin access.

crates/goose/src/acp/transport · high confidence

Adopts Hermit for local development environment management

The repository now uses Hermit to manage local development tools, replacing previous methods. This change introduces a self-bootstrapping environment in the \bin/\ directory that automatically downloads and manages specific versions of Node.js (24.10.0), pnpm (10.30.3), Rust (rustup 1.28.2), CMake (4.2.3), protoc (31.1), just (1.40.0), and the Temporal CLI (1.3.0). Developers can activate this isolated environment using the provided \activate-hermit\ scripts for Bash, Zsh, or Fish, ensuring consistent tool versions across the team without requiring global installations.

bin · high confidence

Conversation context compaction with preserved user messages

The context management module now implements a compaction process that summarizes older conversation history to manage context window limits. When compaction occurs, the system identifies the most recent text-only user message and preserves it in the conversation, ensuring that the user's immediate intent is not lost. The summarized history is replaced with a concise summary message, and specific continuation instructions are appended to guide the agent's subsequent behavior, distinguishing between standard conversation flow, tool-use loops, and manual compaction requests.

_crates/goose/src/context\mgmt · high confidence

Conversation data model refactoring and security hardening

The conversation data types have been restructured into dedicated modules (message, token\_usage, tool\_request, tool\_result\_serde) to improve maintainability. This change introduces per-message usage and cost tracking, including detailed provider statistics and cache token breakdowns. It also adds security sanitization for Unicode tags in text content and tool responses during deserialization, and implements migration logic to handle legacy 'reasoning' content blocks as 'thinking'. Additionally, tool request handling now supports provider-specific metadata, external dispatch markers, and chain summaries to better manage complex tool execution flows.

crates/goose-provider-types/src/conversation · high confidence

Custom MDX components and conditional hackathon banner in documentation theme

The documentation theme now includes a custom MDX component configuration that replaces the default Button with a specialized InstallButton, and adds a Root component that initializes a no-op gtag function to prevent development errors. Additionally, the Root component contains a conditional banner for the 'No Keyboards Allowed Hackathon' which is currently disabled via a SHOW\_BANNER flag, though the code structure for displaying it remains in place.

documentation/src/theme · high confidence

Documentation site adopts Cash Sans typography and Arcade design system

The documentation site now uses the Cash Sans font family for all text and applies the Arcade design system's color palette, including specific variables for backgrounds, borders, icons, and text. This change introduces a new visual identity with updated primary colors (green for light mode, teal for dark mode), rounded button styles, and a dedicated dark mode theme, while also adding new CSS files for extensions styling and Tailwind integration to support the revamped UI components.

documentation/src/css · high confidence

Documentation site restructured with new branding and blog layout

The documentation site has been reorganized and updated to reflect new brand guidelines and improved content presentation. The product name 'goose' is now consistently written in lowercase across all documentation, blog posts, and configuration files, enforced by new style guide files (AGENTS.md, .goosehints). The blog section now features a redesigned magazine-style layout with a prominent featured post section and an improved author display that supports avatars. Additionally, the site configuration has been updated to use a new URL (goose-docs.ai), includes redirects from the previous v1 documentation paths, and integrates Tailwind CSS for styling.

documentation · high confidence

Extension transport logic is modularized and HTTP client security is hardened

The extension manager's transport implementation has been split into dedicated modules (stdio, streamable\_http, and builtin), separating the connection logic for local processes, Docker containers, and built-in extensions from the main manager. Additionally, the streamable HTTP client now includes SSRF protections that block redirects to loopback, link-local, and metadata endpoints, and adds reactive OAuth handling to automatically retry connections when servers return 401/403 authentication challenges.

_crates/goose/src/agents/extension\manager · high confidence

Introduce gateway operator allowlist and stricter session controls

The gateway now supports an operator allowlist that restricts which users can initiate the pairing flow, enhancing access control for public-facing instances. Additionally, gateway sessions now enforce a stricter default cap of 5 tool-calling turns (configurable via GOOSE\_GATEWAY\_MAX\_TURNS) to prevent runaway loops on chat platforms, and the system properly preserves user pairings when the gateway is stopped rather than clearing them.

crates/goose/src/gateway · high confidence

Introduces a canonical model catalog and provider setup metadata system

The \goose-provider-types\ crate now includes a new canonical model system that normalizes provider-specific model names (e.g., \claude-sonnet-4-5-20250929\) into unified canonical IDs (e.g., \anthropic/claude-sonnet-4.5\). This system provides a unified view of model metadata, including pricing, capabilities (tool calling, reasoning, attachments), and context limits, while also unifying provider setup metadata to standardize how different LLM providers are configured and authenticated within the application.

crates/goose-provider-types/src/canonical · high confidence

New provider inventory system for unified model discovery and configuration

The provider configuration and model discovery logic has been restructured into a new inventory system. This change introduces a centralized service that manages provider registrations, identity resolution, and model metadata. Users will experience more consistent provider setup flows, improved model discovery (including support for refresh-only providers and dynamic model lists), and better handling of configuration states across different provider types like OpenAI, Azure AI Foundry, and Anthropic. The inventory system also enables features like recommended model families in the picker and supports refreshing provider configurations.

crates/goose/src/providers/inventory · high confidence

New tool permission management system with smart approval and LLM-based read-only detection

The permission module has been restructured into a dedicated subsystem (mod.rs, permission\_inspector.rs, permission\_judge.rs, permission\_store.rs) that introduces granular control over tool execution. Users now benefit from a 'SmartApprove' mode where read-only operations are automatically allowed, while write operations require approval. This mode leverages an LLM-based 'permission judge' to analyze tool requests and arguments to distinguish between read-only and state-modifying actions. Additionally, a persistent permission store tracks tool permissions with context-aware hashing (using argument hashes) and supports time-limited approvals, ensuring that permissions are scoped to specific tool calls and contexts rather than just tool names.

crates/goose/src/permission · high confidence

New unrolled agent loop with structured state machine and security controls

The agent execution engine has been rewritten as a new unrolled state machine (crates/goose/src/agents/agent.rs) that replaces the previous loop. This change introduces a structured state machine for managing turns, tool execution, and compaction, along with new security features including extension malware checks via OSV (extension\_malware\_check.rs) and environment variable sanitization (extension.rs). The new architecture also includes a FinalOutputTool for structured recipe responses (final\_output\_tool.rs), GenAI telemetry integration (gen\_ai\_telemetry.rs), and a large response handler (large\_response\_handler.rs) that spills oversized tool outputs to temporary files. Slash commands are now handled through a dedicated execute\_commands module, and the agent loop supports tool confirmation coordination, stop hooks, and session-scoped extension management.

crates/goose/src/agents · high confidence

Recipe template building and parameter resolution logic

The recipe building module now validates templates, resolves sub-recipe paths relative to the parent, and handles file-based parameter inputs. Users benefit from more robust recipe execution with proper path resolution and file content handling.

_crates/goose/src/recipe/build\recipe · high confidence

Redesigned extensions directory with search and detail views

The extensions directory has been revamped with a new browsing interface. Users can now search for extensions via a dedicated search input on the main index page, which displays results in separate sections for built-in and community extensions. Clicking an extension opens a new detail page that provides the specific installation command (local, remote, or streamable-http), lists required environment variables and request headers, and includes a link to the relevant documentation tutorial. The visual style has also been updated with a new color palette and typography.

documentation/src/pages/extensions · high confidence

Refactored ACP tool-call handling with chain tracking and enrichment

The ACP server's tool-call handling has been restructured into a modular system (chain, conversion, enrichment) to improve how tool interactions are processed and displayed. A new \ToolChainTracker\ now groups consecutive tool requests into chains, allowing the system to generate and send asynchronous summary updates for multi-step tool sequences. Additionally, tool call titles are now enriched asynchronously based on the agent's context, and the conversion logic has been updated to better format tool names and extract metadata, ensuring that shell approval titles and other UI elements reflect the actual tool arguments more accurately.

_crates/goose/src/acp/server/tool\calls · high confidence

Refactored local inference engine with native and emulated tool calling support

The local inference provider has been restructured to support both native and emulated tool calling. The new \inference\_engine.rs\ module handles core generation logic, including memory-aware context length estimation and stop-suffix trimming. For models with native tool-calling capabilities, \inference\_native\_tools.rs\ streams tool calls and reasoning content directly. For models without native support, \inference\_emulated\_tools.rs\ provides a fallback that parses shell commands and code blocks from the model's text output. The main module (\mod.rs\) now detects which mode to use based on the model's chat template capabilities and user settings.

crates/goose-local-inference/src/llamacpp · high confidence

Restructured configuration system with declarative providers and permission management

The configuration module has been reorganized into dedicated files to support a more structured and secure setup. \base.rs\ now handles core config loading, secret storage (keyring or file-based), and environment overrides. \declarative\_providers.rs\ introduces a new system for defining and managing custom providers via JSON files in a \custom\_providers\ directory, including ID generation and validation. \providers.rs\ manages the active provider and model selection within a structured \providers:\ YAML block, replacing legacy flat keys. \extensions.rs\ handles extension configuration, including enabling/disabling and timeout settings. \permission.rs\ implements a \PermissionManager\ for tool-level access control (AlwaysAllow, AskBefore, NeverAllow). \migrations.rs\ ensures backward compatibility by migrating legacy flat provider keys and platform extensions to the new structured format. \paths.rs\ standardizes config, data, and state directory paths, supporting XDG conventions and custom roots. \search\_path.rs\ manages executable search paths for extensions. \signup\_openrouter/\ adds HTML templates for the OpenRouter authentication flow. \tls.rs\ configures TLS settings for providers using client certificates and CA certs. \experiments.rs\ provides a manager for feature flags.

crates/goose/src/config · high confidence

Skills now support argument placeholders and configurable built-in skill enablement

The skills system now allows skills to define and consume arguments via placeholders (e.g., $1, $ARGUMENTS\[0\], $name) in their instructions, which are resolved when a skill is loaded. Additionally, users can now disable Goose's bundled built-in skills through the ACP server interface, giving more control over which skills are available in the agent's context.

crates/goose/src/skills · high confidence

Unrolled agent loop state machine

The agent's execution engine has been refactored into a new, unrolled state machine located in \crates/goose/src/agents/state\_machine\. This change introduces a modular pipeline of operations—such as compaction, tool calling, and slash command handling—that process conversation state in a defined order. For users, this provides a more structured and reliable agent loop, enabling features like automatic conversation compaction, explicit tool approval workflows, and robust handling of shell commands and skills within a unified execution model.

_crates/goose/src/agents/state\machine · high confidence

Fixes

Fix Windows MSVC linking issues

Resolves linking problems on Windows with MSVC by re-exporting the v8\_goose crate from the vendor/v8 library, ensuring the correct symbols are exposed for the build system.

vendor/v8 · medium confidence

Safe and bounded hint file loading with subdirectory support

The hint loading system now supports discovering hints in nested subdirectories and respects .gitignore patterns to filter files. To prevent resource exhaustion, the new file import mechanism enforces strict limits on recursion depth (3 levels), the number of reference operations (64), and total output size (1 MB). It also explicitly excludes Git metadata directories and handles Git pointer files safely, ensuring that hint expansion remains predictable and secure.

crates/goose/src/hints · high confidence

Test coverage

Added ACP test fixtures for session and provider integration testing; Added MCP replay test fixture for GitHub MCP Server; Added common ACP test suite for session and notification behavior; Added comprehensive tests for the Goose state machine agent lifecycle; Added tests for GGUF filename parsing and auxiliary file detection; Added tests for cache-safe request assembly and prefix invariance; Added tests for live session transport, Z.AI streaming, and proxy isolation; Added tests for tool operation functionality; Added unit tests for the desktop application root component; Expanded test coverage for ACP provider and server capabilities; Removal of CLI test suite and configuration; Snapshot tests added for system prompt generation across extension configurations.

Dependencies

Initial dependency lock and workspace configuration for Goose 1.52.0

This change introduces the initial \Cargo.lock\ file and establishes the root \Cargo.toml\ workspace configuration for Goose version 1.52.0. It defines the Rust workspace structure, sets the minimum supported Rust version (MSRV) to 1.94.1, and centralizes dependency versions for key libraries including \rmcp\ (3.2.0), \agent-client-protocol\ (2.2.0), and \llama-cpp-2\ (0.1.146). The configuration also includes specific build optimizations, such as disabling debug info for third-party dependencies in dev profiles to reduce build times and binary size.

(dependencies) · high confidence

Housekeeping

Added internal documentation for the removal of the experimental Tool Selection Strategy; Recap of the New York Community Meetup.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 44 → 54 (+10.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 76 → 74 (-1.7)
  • Architecture 55 → 71 (+15.7)
  • Maturity 66 → 75 (+9.1)
  • Readiness 33 → 56 (+23.5)
  • Security 46 → 56 (+10.8)
  • Domain Modelling 92 (new)
  • Event Sourcing 100 (new)
  • Accessibility 45 (new)

Resolved (119)

  • Change coupling: App.tsx ↔ SessionsView.tsx (ui/desktop/src/App.tsx)
  • Change coupling: App.tsx ↔ sessionLinks.ts (ui/desktop/src/App.tsx)
  • Change coupling: ExternalBackendSection.tsx ↔ main.ts (ui/desktop/src/components/settings/app/ExternalBackendSection.tsx)
  • Change coupling: ScheduleDetailView.tsx ↔ SchedulesView.tsx (ui/desktop/src/components/schedule/ScheduleDetailView.tsx)
  • Change coupling: SessionListView.tsx ↔ SessionsView.tsx (ui/desktop/src/components/sessions/SessionListView.tsx)
  • Change coupling: autoUpdater.ts ↔ githubUpdater.ts (ui/desktop/src/utils/autoUpdater.ts)
  • Change coupling: chatSessionController.ts ↔ BaseChat.tsx (ui/desktop/src/acp/chatSessionController.ts)
  • Change coupling: docusaurus.config.ts ↔ index.tsx (documentation/docusaurus.config.ts)
  • Change coupling: main.ts ↔ sessionLinks.ts (ui/desktop/src/main.ts)
  • Coverage not measured — test suite did not build
  • Critical CVE: [GHSA redacted] (ui/pnpm-lock.yaml)
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (documentation/package-lock.json)
  • High CVE: [GHSA redacted] (ui/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (ui/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (ui/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (documentation/package-lock.json)
  • High CVE: [GHSA redacted] (ui/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (ui/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (documentation/package-lock.json)
  • …and 99 more

New (1507)

  • (anonymous) (cognitive 62) (crates/goose-mcp/src/autovisualiser/templates/assets/mcp-app-bridge.js)
  • (anonymous) (cyclomatic 57) (crates/goose-mcp/src/autovisualiser/templates/assets/mcp-app-bridge.js)
  • AcpClientLoop::run (cognitive 78) (crates/goose/src/acp/provider.rs)
  • AcpClientLoop::run (cyclomatic 30) (crates/goose/src/acp/provider.rs)
  • AcpProvider::stream (cognitive 71) (crates/goose/src/acp/provider.rs)
  • AcpProvider::stream (cyclomatic 32) (crates/goose/src/acp/provider.rs)
  • AcpReadinessPanel.AcpReadinessPanel (cognitive 24) (ui/desktop/src/components/settings/providers/AcpReadinessPanel.tsx)
  • AcpReadinessPanel.AcpReadinessPanel (cyclomatic 32) (ui/desktop/src/components/settings/providers/AcpReadinessPanel.tsx)
  • Agent::categorize_tool_requests (cognitive 43) (crates/goose/src/agents/reply_parts.rs)
  • Agent::categorize_tool_requests (cyclomatic 19) (crates/goose/src/agents/reply_parts.rs)
  • Agent::handle_approval_tool_requests (cognitive 35) (crates/goose/src/agents/tool_execution.rs)
  • Agent::handle_prompt_command (cognitive 39) (crates/goose/src/agents/execute_commands.rs)
  • Agent::reply_impl (cognitive 35) (crates/goose/src/agents/agent.rs)
  • Agent::reply_impl (cyclomatic 29) (crates/goose/src/agents/agent.rs)
  • Agent::reply_internal (cognitive 463) (crates/goose/src/agents/agent.rs)
  • Agent::reply_internal (cyclomatic 134) (crates/goose/src/agents/agent.rs)
  • AgentManager::create_agent_locked (cognitive 19) (crates/goose/src/execution/manager.rs)
  • AlertBox.AlertBox (cognitive 26) (ui/desktop/src/components/alerts/AlertBox.tsx)
  • AlertBox.AlertBox (cyclomatic 23) (ui/desktop/src/components/alerts/AlertBox.tsx)
  • Ambiguous removal operations: remove_extension and remove_extension_by_key appear to perform the same logical operation (removing an extension) but accept different identifiers (name vs key). Without documentation, it is unclear if 'key' is distinct from 'name' or if they are synonyms, leading to potential misuse.
  • …and 1487 more

Changes since last survey

  • 300 commits — 151 feature/other, 149 fixes

By area

  • crates/goose — 110 commits
  • ui/desktop — 52 commits
  • .github/workflows — 26 commits
  • (root) — 22 commits
  • crates/goose-provider-types — 20 commits
  • crates/goose-providers — 15 commits
  • crates/goose-cli — 12 commits
  • crates/goose-sdk — 10 commits
  • documentation/docs — 8 commits
  • documentation/package-lock.json — 7 commits
  • crates/goose-local-inference — 3 commits
  • documentation/src — 3 commits
  • ui/goose-binary — 3 commits
  • crates/goose-context-management — 2 commits
  • .blox/workstation.yaml — 1 commit
  • .devcontainer/Dockerfile — 1 commit
  • .github/pull_request_template.md — 1 commit
  • crates/goose-agent — 1 commit
  • crates/goose-roaming — 1 commit
  • documentation/blog — 1 commit

Notable commits

  • fix: Fix MCP sampling for reasoning-first responses (#11092)
  • fix: Fix/gdk pypi direct publish (#11819)
  • fix: fix (desktop): fix chat input freeze after opening model picker (#11525)
  • fix: fix Databricks GLM-5.3 and Kimi K3 reasoning effort (#12079)
  • fix: fix context management dependency (#11768)
  • fix: fix flaky command_hooks_repair_path_when_enabled test (stdin EPIPE race) (#12209)
  • fix: fix gdk kotlin example (#11825)
  • fix: fix maven smoke test find/exec command syntax (#11821)
  • fix: fix(acp): allow 60 seconds for provider readiness (#12240)
  • fix: fix(acp): bind MCP app tools to extension owners (#11416)
  • fix: fix(acp): omit unsupported socket MCP servers (#11417)
  • fix: fix(acp): prevent duplicate schedules from overwriting recipes (#12434)
  • fix: fix(acp): restrict project updates to visible sessions (#11487)
  • fix: fix(acp): send session usage updates after each provider call (#12006)
  • fix: fix(acp): update package locations (#12386)
  • fix: fix(agents): auto-compact at tool boundaries in the unrolled agent loop (#12444)
  • fix: fix(agents): fail fast when a recipe's structured response can't reach an ACP-bridged provider (#11307)
  • fix: fix(agents): keep streamed thinking ahead of text and tool calls (#11837)
  • fix: fix(anthropic): preserved-thinking compliance for the provider layer (#11836)
  • fix: fix(apps): protect bundled cache identities (#11397)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

aaif-goose/goose was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 04ed836c8cde23e540cc77d256992e00be99298b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.