block/goose: The Headless IDE for the Agentic Era

How a fintech company built a Rust-native, local-first AI agent that safely executes shell commands without compromising the host machine.

8 min read • View on GitHub • More from block

A mechanical goose securely enclosed inside a heavy glass and steel observation chamber, manipulating tools through shielded hazard gauntlets. This represents Goose's Docker-sandboxed execution environment.
Goose isolates autonomous AI operations within a secure boundary, granting terminal access without exposing the host.
Key Takeaways

The Shell-Scripting Elephant in the Room

Giving an AI agent access to your terminal is terrifying. Most AI coding tools are either simple autocomplete plugins or cloud-dependent CLI wrappers that demand blind trust. Autonomous agents are notorious for hallucinating destructive commands. This creates a fundamental tension between utility and security.

Block, a financial technology company, approached this problem by treating the LLM as a hostile external dependency. Goose operates as a local-first coordinator that routes all generated actions through a strict permission boundary. Users can configure Goose to run its tool extensions inside Docker containers. This sandboxed architecture allows the agent to install packages, edit files, and run tests without ever gaining unmitigated access to the host machine.

a framework for new heights of invention and growth.

Dhanji Prasanna, Block CTO · AI Tool Analysis

The Rust-Powered Orchestrator

While the AI ecosystem is heavily dominated by Python, the core of Goose is built entirely in Rust. This choice provides memory safety, easy binary distribution, and the robust concurrent performance required to manage complex agentic loops.

The codebase relies heavily on the tokio async runtime to handle simultaneous tool executions. The orchestrator bridges the gap between user input and the agent core via the Agent Client Protocol (ACP). This provider abstraction ensures that Goose remains entirely LLM-agnostic, capable of routing requests to OpenAI, Anthropic, or local Ollama instances interchangeably.

An interactive SVG diagram illustrating the Secure Agent Loop. Three vertical columns: 'The Brain' (LLM)

Taming the LLM with Recipes and ASTs

A raw prompt is too chaotic for reliable software engineering. Goose solves this by implementing a deterministic workflow system called Recipes. Defined in YAML files, these recipes guide the agent through multi-step tasks by establishing strict constraints and allowed tools.

To prevent the agent from destroying file formatting during complex edits, Goose integrates tree-sitter. This provides the agent with an Abstract Syntax Tree (AST) understanding of the code. Instead of guessing line numbers or hallucinating syntax, the agent edits files with structural awareness.

A close-up of a vintage, rigidly structured paper punch card being fed into an intricate brass analytical engine. The output side of the engine is a chaotic, glowing web of fiber optic cables. This represents YAML recipes bringing structure to LLMs.
YAML recipes and tree-sitter parsing force the inherent chaos of large language models into predictable, structured outputs.
name: rigorous-code-review
description: Perform structural analysis before suggesting changes.
tasks:
  - step: Parse target file with tree-sitter
    tool: ast_parser
  - step: Identify logical execution block
    constraints: Do not modify imports or formatting.

The Sovereign Agent

Goose is fundamentally an open protocol bet. By building its extension system around the Model Context Protocol (MCP), Block ensures that the agent can connect to thousands of standard external tools out of the box.

This positions Goose as a distinct alternative to proprietary systems. It trades the frictionless onboarding of cloud-locked tools for absolute local control and data privacy.

FeatureBlock GooseClaude CodeGitHub Copilot
Execution EnvironmentSandboxed / LocalCloud CLIIDE Inline
Core ParadigmAutonomous AgentInteractive AssistantKeystroke Autocomplete
ExtensibilityOpen (MCP)ProprietaryClosed Ecosystem
Data PrivacyAbsolute ControlCloud DependentTelemetry Enabled