cd /news/ai-agents/i-put-an-ai-coding-agent-inside-an-a… · home › topics › ai-agents › article
[ARTICLE · art-143740] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

I put an AI coding agent inside an Android app. Here's everything that fought back.

A developer built AndroPI, an open-source, MIT-licensed AI coding agent that runs entirely on an Android phone with no backend, wrapping the TypeScript coding agent pi in a Flutter UI. To get Node.js, git, ripgrep, ssh and a proot-based Debian userland running on-device, the binaries ship inside the APK renamed as lib*.so files, and the developer added DNS-over-HTTPS to bypass ISP DNS hijacking and a layer that sanitizes malformed tool-call arguments from models. Trimming the agent bundle from 16.6 MB to 8 MB cut the APK from 73 MB to 63 MB, and the developer had to drop the MANAGE_EXTERNAL_STORAGE permission after Google rejected it.

by read4 min views5 publishedOct 2, 2026

I wanted to fix a bug from my phone. Not "review a PR" from my phone. Actually open a project, let an AI agent write the code, run it, see the result and ship it.

Every tool I found was a chat app that talks to someone else's server. So I built the thing I wanted: AndroPI, an AI coding agent that runs on the phone itself. Open source, MIT, no backend.

It works now. Getting there was a fight with Android the whole way.

Take pi, an open source coding agent written in TypeScript. Put a Flutter UI in front of it. Done.

The catch: pi needs Node.js. And git. And a shell, ripgrep, ssh, curl. On a phone.

First wall. I dropped a Node binary into the app's data folder and tried to execute it.

Permission denied.

Since Android 10 you can't execute files from your app's writable storage. The only place an app can run native code from is its native library directory. And the packager only puts files there if they're named lib*.so.

So that's what I did. Node.js ships in the APK as libnode.so. Git is libgit.so. They aren't libraries. Android doesn't check.

BINARIES = {
    "nodejs-lts": {"bin/node": "libnode.so"},
    "ripgrep": {"bin/rg": "librg.so"},
    "git": {"bin/git": "libgit.so"},
    "openssh": {"bin/ssh": "libssh_cli.so"},
    "proot": {"bin/proot": "libproot.so"},
}

The binaries come from the Termux package repository. A script downloads the .deb files, pulls the binaries out, and rewrites their library names with lief, because a real dependency like libicuuc.so.78 also has to become libicuuc_78.so or the packager drops it.

My favourite part: the container launcher is a shell script. It ships as libbox.so. The Flutter build complains every single time that it "failed to strip debug symbols" from it. Yeah. It's a shell script.

An agent that can't apt install is half an agent. It'll want Python, or a newer Node, or some build tool I didn't bundle.

So AndroPI runs a Debian (or Alpine) userland with proot. No root needed. The app pulls the official image straight from Docker Hub's registry API and unpacks the layers itself. The agent's shell runs inside that.

apt install python3 on a phone, from a chat. That one felt good.

My ISP hijacks DNS. The agent's web search kept failing. Turned out the provider was redirecting lookups for sites it doesn't like. I added DNS over HTTPS inside the Node host. Now the agent can search no matter what the network thinks.

Models send garbage arguments. One model kept calling the read tool with offset: "None". A Python-ism, as a string, into a number field. Validation failed, the run died. I added a small layer that cleans tool arguments before they're checked.

The foreground service ate my notification. The app shows "Agent is working" while it runs, and "pi is done" when it finishes. The done notification never showed up. Both used notification ID 1. When the service stopped, Android removed ID 1. Took me an embarrassing while to see it, and I only caught it because I was recording a demo video.

The first release APK was 73 MB. I assumed Flutter was the fat one. It wasn't.

About 80% of the app is the runtime. Node alone is 15 MB compressed. ICU data, which Node needs for Intl, is another 15.

My first idea was to bundle the agent into one minified file. That broke login. pi loads its OAuth flows through import() paths it builds at runtime, and a bundler can't follow those.

So I kept the package layout and did the boring thing instead:

node_modules Agent bundle: 16.6 MB down to 8 MB. APK: 73 down to 63. Then I added armv7 and x86_64 builds, since Termux has packages for both.

Twice.

First: "All files access". I had MANAGE_EXTERNAL_STORAGE so you could open a project in any folder on the phone. Google only allows that for file managers and a few other categories. A coding agent isn't on the list.

Fair. The workspace already lived in app storage, so only one feature needed it. I split the build into two flavors:

<!-- android/app/src/play/AndroidManifest.xml -->
<uses-permission
    android:name="android.permission.MANAGE_EXTERNAL_STORAGE"
    tools:node="remove"/>

The Play build drops the permission. Files come in through the system picker and go out through MediaStore or the share sheet. The GitHub build keeps the full version.

Second: the foreground service. Android 14 wants a type for every foreground service, and "runs an AI agent" isn't one of them. So it's specialUse, which means a written justification and a video showing the notification while the app is in the background. That's the video where I found the notification bug.

You bring the model: Claude, GPT, Gemini, OpenRouter. Your keys stay on your phone. There's no server of mine in the middle, because there is no server of mine.

If you've shipped something weird inside an APK, I want to hear how you got it past review. And if you find a bug, open an issue. I probably caused it.

── more in #ai-agents 4 stories · sorted by recency
── more on @andropi 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/i-put-an-ai-coding-a…] indexed:0 read:4min 2026-10-02 · —