← All agents

Goose

noneopen sourcecli

No OS-level isolation, it runs with your full privileges, gated only by approval prompts.

No OS-level isolation. This agent runs commands with your full user privileges. Its guardrails (approval prompts, allowlists) live inside your trust boundary, wrap it in a boundary you control.

Goose runs with your full user privileges and has no OS-level sandbox. Its per-tool permission records are configuration inside your trust boundary, gated by approval prompts, not an isolation boundary.

Sources