Goosy Docs
Documentation
Goosy reviews pull requests, scans your code for security issues, and runs API tests against your own endpoints — grounded in the actual code in your repo, not a generic ruleset.
Goosy connects to a GitHub, GitLab, or Bitbucket repository and gives you three things: automatic pull-request review with fixes, a security scanner that runs from a quick pattern pass up to full cross-file data-flow analysis, and an agentic testing module that writes and self-heals API tests against your own OpenAPI spec.
How Goosy is put together
Every scan and test run is grounded in your actual repository at a specific commit — Goosy clones the code, so findings and drift verdicts are backed by real diffs rather than guesses. A two-tier model split is used throughout: a fast, wide-net model drafts a result and a stronger model verifies or repairs it, which is why the deterministic parts of the product (a compiled test replay, for example) never call a model at all on the happy path.