I put an AI coding agent inside an Android app. Here's everything that fought back. A developer built AndroPI, an open-source, MIT-licensed AI coding agent that runs entirely on an Android phone with no backend, wrapping the TypeScript coding agent pi in a Flutter UI. To get Node.js, git, ripgrep, ssh and a proot-based Debian userland running on-device, the binaries ship inside the APK renamed as lib*.so files, and the developer added DNS-over-HTTPS to bypass ISP DNS hijacking and a layer that sanitizes malformed tool-call arguments from models. Trimming the agent bundle from 16.6 MB to 8 MB cut the APK from 73 MB to 63 MB, and the developer had to drop the MANAGE_EXTERNAL_STORAGE permission after Google rejected it. I wanted to fix a bug from my phone. Not "review a PR" from my phone. Actually open a project, let an AI agent write the code, run it, see the result and ship it. Every tool I found was a chat app that talks to someone else's server. So I built the thing I wanted: AndroPI , an AI coding agent that runs on the phone itself. Open source, MIT, no backend. It works now. Getting there was a fight with Android the whole way. Take pi https://github.com/earendil-works/pi , an open source coding agent written in TypeScript. Put a Flutter UI in front of it. Done. The catch: pi needs Node.js. And git. And a shell, ripgrep, ssh, curl. On a phone. First wall. I dropped a Node binary into the app's data folder and tried to execute it. Permission denied. Since Android 10 you can't execute files from your app's writable storage. The only place an app can run native code from is its native library directory. And the packager only puts files there if they're named lib .so . So that's what I did. Node.js ships in the APK as libnode.so . Git is libgit.so . They aren't libraries. Android doesn't check. php package - {binary inside the Termux package: name inside the APK} BINARIES = { "nodejs-lts": {"bin/node": "libnode.so"}, "ripgrep": {"bin/rg": "librg.so"}, "git": {"bin/git": "libgit.so"}, "openssh": {"bin/ssh": "libssh cli.so"}, "proot": {"bin/proot": "libproot.so"}, } The binaries come from the Termux package repository. A script downloads the .deb files, pulls the binaries out, and rewrites their library names with lief , because a real dependency like libicuuc.so.78 also has to become libicuuc 78.so or the packager drops it. My favourite part: the container launcher is a shell script. It ships as libbox.so . The Flutter build complains every single time that it "failed to strip debug symbols" from it. Yeah. It's a shell script. An agent that can't apt install is half an agent. It'll want Python, or a newer Node, or some build tool I didn't bundle. So AndroPI runs a Debian or Alpine userland with proot . No root needed. The app pulls the official image straight from Docker Hub's registry API and unpacks the layers itself. The agent's shell runs inside that. apt install python3 on a phone, from a chat. That one felt good. My ISP hijacks DNS. The agent's web search kept failing. Turned out the provider was redirecting lookups for sites it doesn't like. I added DNS over HTTPS inside the Node host. Now the agent can search no matter what the network thinks. Models send garbage arguments. One model kept calling the read tool with offset: "None" . A Python-ism, as a string, into a number field. Validation failed, the run died. I added a small layer that cleans tool arguments before they're checked. The foreground service ate my notification. The app shows "Agent is working" while it runs, and "pi is done" when it finishes. The done notification never showed up. Both used notification ID 1. When the service stopped, Android removed ID 1. Took me an embarrassing while to see it, and I only caught it because I was recording a demo video. The first release APK was 73 MB. I assumed Flutter was the fat one. It wasn't. About 80% of the app is the runtime. Node alone is 15 MB compressed. ICU data, which Node needs for Intl , is another 15. My first idea was to bundle the agent into one minified file. That broke login. pi loads its OAuth flows through import paths it builds at runtime, and a bundler can't follow those. So I kept the package layout and did the boring thing instead: node modules Agent bundle: 16.6 MB down to 8 MB. APK: 73 down to 63. Then I added armv7 and x86 64 builds, since Termux has packages for both. Twice. First: "All files access". I had MANAGE EXTERNAL STORAGE so you could open a project in any folder on the phone. Google only allows that for file managers and a few other categories. A coding agent isn't on the list. Fair. The workspace already lived in app storage, so only one feature needed it. I split the build into two flavors: php < -- android/app/src/play/AndroidManifest.xml --