Goose should set the Content-Security-Policy header appropriately to mitigate the risk of unauthorised content being loaded in the browser. This is particularly useful for XSS prevention. The Expect-CT header also has support among some of the browsers.