# Goose Agent Security on Mac: Monitor Network Access (FireAI)

> Goose is an open-source AI agent from the Agentic AI Foundation with a desktop app, a CLI and MCP extensions. See what it can reach on a Mac and how FireAI watches its connections.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai

Goose is an open-source AI agent that is not limited to code: its repository describes it as built for code, workflows and everything in between. It runs as a desktop app and as a command-line tool, and it reaches outside tools through extensions. Those facts explain searches such as “goose ai agent security mac” and “goose agent network access”. This article sets out what the project documents, marks where the pages we could read were silent, and then explains how FireAI, an on-device firewall for macOS made by HisnLabs, watches the connections of an agent that you have installed as an app.

## What Goose is

goose is written in Rust and licensed under Apache 2.0. The repository, originally published by Block, states that the project is now maintained by the Agentic AI Foundation, which operates under the Linux Foundation. It is offered as a desktop app, a CLI and an API, and connects to extensions through the Model Context Protocol (MCP), an open standard for tool integration. The README lists compatibility with more than a dozen model providers, including Anthropic, OpenAI, Google, Ollama, OpenRouter, Azure and Bedrock [[1]](https://github.com/block/goose). Each extension is a tool the agent can call, and an extension may itself reach the network.

## How Goose runs on macOS

The installation guide gives two routes on macOS. The desktop app is a download for Apple Silicon or Intel, or `brew install --cask block-goose`. The CLI is installed with a download script or `brew install block-goose-cli`, and updates can come from Homebrew or `goose update`. The CLI and the desktop app share their configuration, including provider settings, model selection and extensions [[2]](https://goose-docs.ai/docs/getting-started/installation). The shared configuration file is `~/.config/goose/config.yaml` on macOS [[3]](https://goose-docs.ai/docs/guides/config-files).

## What it can access and how it is controlled

What Goose can touch is defined by the extensions you enable, since each MCP extension exposes its own tools, and by the permissions of your macOS account. The project’s documentation includes a section on permission modes. The page could not be read in full when this article was prepared, so this article does not describe the individual modes; read the guide in the goose documentation before relying on them.

## Where it connects

The configuration guide documents a telemetry setting, `GOOSE_TELEMETRY_ENABLED`, described as enabling anonymous usage data collection, with a default of false; it can be set in `config.yaml` or as an environment variable [[3]](https://goose-docs.ai/docs/guides/config-files). Beyond your chosen model provider and any extension, the pages read do not publish a list of domains.

> **Note:** This article reports what Goose’s own documentation says and what it leaves out. We list no domain, incident or vulnerability that the sources above do not state.

## Watching Goose with FireAI

FireAI is a firewall for macOS that runs on the Mac. Its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) feature recognises 19 AI agents, learns where each normally connects and flags what is new. FireAI’s Agent profile page lists Goose among the apps recognised by the app they run from, together with ChatGPT, Windsurf, Kiro, Trae and OpenClaw. The page does not say how a Goose process started from a terminal is matched, so this article makes no claim about the CLI beyond what FireAI shows you in its activity list.

- For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain, so api.anthropic.com becomes anthropic.com. Nothing is flagged during this period.
- After that, the first-ever destination outside the baseline is flagged for review in Suggestions, in the AI agents card and in Quick Review. Swipe left to block, or right for “It’s fine”.
- An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.
- FireAI uses metadata only, meaning host names and byte counts. It never reads the payload of a connection.

> Want a firewall that tells you when Goose reaches somewhere new? FireAI learns each agent’s normal destinations on your Mac. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Setting up FireAI for Goose

1. Install FireAI and use the agent as you normally do. The 3-day learning period starts on its own and flags nothing.
2. Open Suggestions and find the AI agents card. After the learning period, a flag for the agent appears there and in Quick Review.
3. Review each flag. Choose Block to create a rule for the process that connected, or “It’s fine” to add the destination to the agent’s baseline.
4. To keep the agent to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Your rules apply as in Home, and a connection to a destination outside the baseline is blocked instead of flagged once the agent has finished learning.
5. A blocked destination appears in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent reaches it right away. Keep blocked creates a block rule that holds in every mode.

An allow rule you wrote for a website, domain or address still wins, and DNS and your local network are never blocked. For an agent FireAI does not list, write a rule for its program by hand in [per-app rules](https://hisnlabs.com/en/docs/per-app-rules). The Agent profile mode needs FireAI 1.0.3 or later, and recognition of Goose needs 1.0.4.

## Limits

- FireAI sees which destinations Goose or its child processes reach, not which MCP extension asked for the connection.
- Goose is recognised by the app it runs from, which means it is labelled, not verified: only Claude Code, Claude and Cursor are checked against their developer’s signature.
- FireAI does not stop prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- FireAI cannot see prompts, the contents of MCP tools, file access or skills. TLS hides the payload, and FireAI is not inside the agent.
- Child processes that exit very quickly may be missed, and they are matched by path, not by signature.
- During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked.
- In the Agent profile mode, a connection made to a bare IP address with no host name is matched by its address, so a new address for a service the agent normally uses is blocked until you allow it.

## Other agents

The same approach applies to every agent FireAI recognises. See the other guides: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [the Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [the ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai), [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai), [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any other AI agent running on python or node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). The full feature description is on the [Agent profile documentation page](https://hisnlabs.com/en/docs/agent-profile), published by HisnLabs.

> See every connection your Mac makes — and decide which ones go through. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## How FireAI and HisnLabs fit in

FireAI learns where Goose normally connects on your Mac and flags a first-ever destination or an upload spike, without reading your data.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [goose: project repository and README (GitHub)](https://github.com/block/goose)
- [goose documentation: installation](https://goose-docs.ai/docs/getting-started/installation)
- [goose documentation: configuration files](https://goose-docs.ai/docs/guides/config-files)
- [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)
- [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules)
