---
name: Goose (Block/AAIF) Audit 2026-05-11
description: 45k-Stars Multi-Provider-Agent-Framework. Verdict: Tool ignorieren, 3 Patterns klauen (YAML-Recipes, Self-Test-Recipe, Custom-Distros für MRR). Prompt-Injection-Scan clean
type: reference
originSessionId: 08a27d91-b2ef-411c-9b56-62842a3c506c
---
Goose-Audit (https://github.com/aaif-goose/goose, jetzt unter Linux Foundation AAIF seit 9.12.2025). Volldoku in `02-Wissen/goose-audit-2026-05-11.md`.

**Verdict:** Tool ignorieren, 3 Patterns adoptieren.

**Begründung Tool-Ignore:**
- Wechsel = 6+ Monate Rebuild für Multi-Provider-Support den Kais nicht braucht (Claude 4.7 Daily Driver)
- Governance anti-velocity (1-Wochen-Maintainer-Diskussionen)
- Rust + Electron + Hermit Build-Overhead disproportional für Single-User
- 45k Stars sind Hype-Signal, nicht Fit-Signal (Block + LF haben strategisches Interesse)

**3 adoptierbare Patterns:**
1. **YAML-Recipes** für Skills (statt freier Markdown) — passt zu KAR-63 Bounded-Autonomy-Tags-Frontmatter
2. **Self-Test-Recipe** (`goose-self-test.yaml`-Style, auto-erweitert bei jedem Feature-Add)
3. **Custom-Distros** (`CUSTOM_DISTROS.md`-Pattern) — direkt MRR-relevant für eine BMW-Edition von Aria (Beilage zum Kadi-v2-Vendor-Vertrag, Compliance-Branding). Pattern klauen, KAR-64 angelegt für nach BMW-Pilot.

**Prompt-Injection-Scan: CLEAN** (README, GOVERNANCE, AGENTS.md, SECURITY.md, .goosehints geprüft. SECURITY.md thematisiert sogar Injection-Risiken aktiv).

**Sicherheits-Auffälligkeiten falls je adoptiert:**
- `curl | bash`-Install ohne Hash-Pinning
- Community-Recipes "Security-Scan (if approved)" Gummi-Klausel
- `goosed` Default-Secret-Key `test` in Docs
- 70+ MCP-Extensions = identische Trust-Boundary wie Aria-MCP-Stack

**Aria-Vorteile gegenüber Goose (heute):**
- Persistenter Brain-Vault (Goose hat keinen dokumentierten)
- Auto-Approve-Loop + tmux-Pipeline (Goose default human-confirm)
- Skill-Auto-Curator + Sleep-Memory-Consolidation
- Solo-Founder-Velocity statt Maintainer-Voting

**Aria-Nachteile:**
- Claude-only (Goose 15+ Provider) — heute irrelevant, später Risk
- Kein Web-UI / OpenAPI-Server
- Keine Whitelabel-Distro-Infrastruktur (genau hier liegt MRR-Hebel)
