The Developer extension allows goose to automate developer-centric tasks such as file editing, shell command execution, and project setup. It also provides tools for [enhanced code editing](/docs/guides/enhanced-code-editing) and [codebase analysis](/docs/guides/codebase-analysis).
In this example, I'm going to have goose automate setting up my JavaScript developer environment with Express, Mongoose, Nodemon, Dotenv and initialize Git.
set up a new JavaScript project with Express, Mongoose, Nodemon, and Dotenv? Fetch the latest package versions, generate a README with those versions, and initialize Git
Shell commands executed by the `shell` tool inherit the environment of the running goose process. This typically includes:
- System variables like `PATH`, `HOME`, and `USER`
- Environment variables present in the process that launched goose (for example, your terminal's environment when you start goose from a shell)
- Session-specific variables injected by goose, such as `AGENT_SESSION_ID` for [session-isolated workflows](/docs/guides/environment-variables#using-session-ids-in-workflows)
This enables workflows that depend on environment configuration, such as authenticated CLI operations and build processes.
:::info
goose Desktop or launcher-based starts may use a different environment and may not load your shell startup files.
:::
:::warning Sensitive Information
Environment variables may contain sensitive values like API keys and tokens (e.g., `GITHUB_TOKEN`, `AWS_ACCESS_KEY_ID`).
By default, goose can run system commands with your user privileges and edit any accessible file **without your approval**. This is because goose runs in Autonomous permission mode by default and has access to the Developer extension's shell and file editing tools. While this configuration allows goose to work quickly and independently, there's potential for unexpected outcomes. Understanding the available access control features can help you configure goose to match your comfort level and specific needs.
:::tip
See the [Quick Setup Example](#quick-setup-example) below for some ways to configure more control over goose's behavior.
:::
### Developer Extension Tools
The Developer extension provides these tools:
| Tool | Description | Use Cases | Risk Level |
|------|-------------|-----------|------------|
| `shell` | Execute shell commands | Running tests, installing packages, git operations | ⚠️ High<br />Can run any system command with your user privileges |
| Autonomous<br />CLI: `auto` | No approval required | Best for experienced users in safe environments |
| Manual Approval<br />CLI: `approve` | Review every action | Recommended for sensitive work or when you want maximum control |
| Smart Approval<br />CLI: `smart_approve` | AI decides what needs review | Balanced approach |
| Chat Only<br />CLI: `chat` | Disable all tools | For maximum security and models that don't support tool-calling |
- **[Tool Permissions](/docs/guides/managing-tools/tool-permissions)** let you set `Always allow`, `Ask before`, and `Never allow` permissions for individual extension tools when in Manual Approval or Smart Approval modes
- **[.gooseignore files](/docs/guides/context-engineering/using-gooseignore)** restrict which files and directories goose can access (`.gitignore` files are fallback)
You can change goose permission modes during a session without restarting:
- **CLI**: Use the `/mode` command (e.g. `/mode approve`)
- **Desktop**: Use the <Tornado className="inline" size={16} /> mode selector button in the bottom menu
:::
#### Quick Setup Example
You might want more control over goose's operations when working with sensitive systems, exploring unfamiliar codebases, using untrusted models, or simply preferring to review actions before execution.
Here's an example configuration that enables oversight:
3.**Configure [tool permissions](/docs/guides/managing-tools/tool-permissions)** based on your needs
As you become more comfortable with goose's behavior, you can adjust these settings to reduce friction while maintaining appropriate safeguards for your environment.
:::info
Also see the [Security Guide](/docs/guides/security/) for information about using goose safely.