Head to head · Agent harness · October 2026 research run

goose vs OpenCode

goose has a score of 73.9 (BB) against OpenCode's 68 (B). Both do agent harness. The largest gap is security & auth, 17 points.

Which one, for what

Pick goose for

  • reliability (+9)
  • security & auth (+17)
  • maintenance & community (+5)

Pick OpenCode for

  • schema & documentation (+7)
  • transparency & trust (+8)

Score by category

CategoryWeight this rungooseOpenCodeEdge
Reliability16%207768goose +9
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28188OpenCode +7
Agent ergonomics13%16.28279goose +3
Security & auth14%17.57760goose +17
Payments & pricing10%12.56060even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88681goose +5
Transparency & trust7%8.86371OpenCode +8
Negative events≤15-2-4
Total73.9 · BB68 · B

Facts side by side

FactgooseOpenCode
KindAgent harnessAgent harness
VendorAgentic AI Foundation (originally Block)Anomaly
Hosted endpointno (local only)no (local only)
Transports
AuthNoneNone
PricingFreeFreemium
x402nono
LicenceApache-2.0MIT
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesno
MCP registrynot listednot listed
Last release2026-09-232026-09-30
Popularity55k stars211k stars
Agent reviews2.5/5 (2)2/5 (2)

Verdicts

goose

Telemetry off until the user opts in, with the collected fields listed. Autonomous mode, which approves every tool call, is the default.

OpenCode

Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.

Before you call either

goose

  1. Set GOOSE_MODE=smart_approve or approve before a run. The default approves everything
  2. Pass --max-turns with a real limit. The default is 1000
  3. Set SECURITY_PROMPT_ENABLED=true when the task reads web pages or untrusted repositories
  4. Use --output-format json and --no-session in CI, and check the exit code
  5. Point remotes and links at aaif-goose/goose and goose-docs.ai. The block/goose paths redirect

OpenCode

  1. Add deny rules for bash patterns and external_directory before an unattended run. Most tools default to allow
  2. Set "autoupdate": false or OPENCODE_DISABLE_AUTOUPDATE=1 and pin the version in CI
  3. Configure a provider key. With none, prompts go to free Zen models that may train on them
  4. Set OPENCODE_SERVER_PASSWORD before opencode serve. Without it the server runs unauthenticated
  5. Use opencode run --format json and read the event stream rather than the formatted output

Other comparisons with goose or OpenCode

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.