# I put an AI coding agent inside an Android app. Here's everything that fought back.

> Source: <https://dev.to/abdulm/i-put-an-ai-coding-agent-inside-an-android-app-heres-everything-that-fought-back-lpk>
> Published: 2026-10-02 08:24:51+00:00

I wanted to fix a bug from my phone. Not "review a PR" from my phone. Actually open a project, let an AI agent write the code, run it, see the result and ship it.

Every tool I found was a chat app that talks to someone else's server. So I built the thing I wanted: **AndroPI**, an AI coding agent that runs on the phone itself. Open source, MIT, no backend.

It works now. Getting there was a fight with Android the whole way.

Take [pi](https://github.com/earendil-works/pi), an open source coding agent written in TypeScript. Put a Flutter UI in front of it. Done.

The catch: pi needs Node.js. And git. And a shell, ripgrep, ssh, curl. On a phone.

First wall. I dropped a Node binary into the app's data folder and tried to execute it.

Permission denied.

Since Android 10 you can't execute files from your app's writable storage. The only place an app can run native code from is its native library directory. And the packager only puts files there if they're named `lib*.so`.

So that's what I did. Node.js ships in the APK as `libnode.so`. Git is `libgit.so`. They aren't libraries. Android doesn't check.

``` php
# package -> {binary inside the Termux package: name inside the APK}
BINARIES = {
    "nodejs-lts": {"bin/node": "libnode.so"},
    "ripgrep": {"bin/rg": "librg.so"},
    "git": {"bin/git": "libgit.so"},
    "openssh": {"bin/ssh": "libssh_cli.so"},
    "proot": {"bin/proot": "libproot.so"},
}
```

The binaries come from the Termux package repository. A script downloads the `.deb` files, pulls the binaries out, and rewrites their library names with `lief`, because a real dependency like `libicuuc.so.78` also has to become `libicuuc_78.so` or the packager drops it.

My favourite part: the container launcher is a shell script. It ships as `libbox.so`. The Flutter build complains every single time that it "failed to strip debug symbols" from it. Yeah. It's a shell script.

An agent that can't `apt install` is half an agent. It'll want Python, or a newer Node, or some build tool I didn't bundle.

So AndroPI runs a Debian (or Alpine) userland with `proot`. No root needed. The app pulls the official image straight from Docker Hub's registry API and unpacks the layers itself. The agent's shell runs inside that.

`apt install python3` on a phone, from a chat. That one felt good.

**My ISP hijacks DNS.** The agent's web search kept failing. Turned out the provider was redirecting lookups for sites it doesn't like. I added DNS over HTTPS inside the Node host. Now the agent can search no matter what the network thinks.

**Models send garbage arguments.** One model kept calling the read tool with `offset: "None"`. A Python-ism, as a string, into a number field. Validation failed, the run died. I added a small layer that cleans tool arguments before they're checked.

**The foreground service ate my notification.** The app shows "Agent is working" while it runs, and "pi is done" when it finishes. The done notification never showed up. Both used notification ID 1. When the service stopped, Android removed ID 1. Took me an embarrassing while to see it, and I only caught it because I was recording a demo video.

The first release APK was 73 MB. I assumed Flutter was the fat one. It wasn't.

About 80% of the app is the runtime. Node alone is 15 MB compressed. ICU data, which Node needs for `Intl`, is another 15.

My first idea was to bundle the agent into one minified file. That broke login. pi loads its OAuth flows through `import()` paths it builds at runtime, and a bundler can't follow those.

So I kept the package layout and did the boring thing instead:

`node_modules`
Agent bundle: 16.6 MB down to 8 MB. APK: 73 down to 63. Then I added armv7 and x86_64 builds, since Termux has packages for both.

Twice.

**First: "All files access".** I had `MANAGE_EXTERNAL_STORAGE` so you could open a project in any folder on the phone. Google only allows that for file managers and a few other categories. A coding agent isn't on the list.

Fair. The workspace already lived in app storage, so only one feature needed it. I split the build into two flavors:

``` php
<!-- android/app/src/play/AndroidManifest.xml -->
<uses-permission
    android:name="android.permission.MANAGE_EXTERNAL_STORAGE"
    tools:node="remove"/>
```

The Play build drops the permission. Files come in through the system picker and go out through MediaStore or the share sheet. The GitHub build keeps the full version.

**Second: the foreground service.** Android 14 wants a type for every foreground service, and "runs an AI agent" isn't one of them. So it's `specialUse`, which means a written justification and a video showing the notification while the app is in the background. That's the video where I found the notification bug.

You bring the model: Claude, GPT, Gemini, OpenRouter. Your keys stay on your phone. There's no server of mine in the middle, because there is no server of mine.

If you've shipped something weird inside an APK, I want to hear how you got it past review. And if you find a bug, open an issue. I probably caused it.
