Eta: a system-level Android AI agent that reaches past the sandbox
Android 系统级 AI Agent——越过沙盒,让模型访问底层API、屏幕、终端与你的数据
At a glance
- What is it?
- Eta is a third-party Android assistant that runs its own agent loop inside the app, calls Android APIs directly, and can borrow the power button or a vendor assistant as its entry point. It needs an API key you supply, Android 14 or newer, and in places Root or LSPosed.
- Who is it for?
- Eta suits Android 14+ users who already pay for a model API, want the phone's own entry points rewired to their chosen provider, and accept that Root, LSPosed and vendor ROM support decide how much of the device the agent can actually touch. It is the wrong tool if you want local inference, a fixed first-party assistant, or a guarantee that a vendor update will not break the hooks.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 1 day ago.
- What is it written in?
- Mainly Kotlin, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The gap Eta is aiming at: Android agents that cannot leave the app
A normal Android app lives inside a sandbox. It can draw its own screens and, with permission, read a few system services, but it cannot reach the directories, commands and vendor data that a desktop coding agent treats as ordinary. Eta is built for that gap. The README frames the motivation plainly: desktop agents have a shell, a file system and open tools, while on Android the useful data sits inside separate apps with no interface for an agent to call.
The target user is someone who already accepts that a phone assistant should be swappable. Eta requires a model API key of your own, a pattern the project calls BYOK. Built-in provider entries cover OpenAI, Anthropic, Alibaba Bailian, DeepSeek, Kimi, MiMo, MiniMax, StepFun, SiliconFlow and OpenRouter, and a custom service can be added. The project states that AI features need that key; there is no bundled inference.
That requirement shapes who this is for. If you want an assistant that works out of the box with no account and no billing, Eta is the wrong shape. If you already have a provider account and want the same model reachable from the power button, it is aimed at you.
Inside the Agent Runtime: one loop, two entry points
The architecture described in the README is a single agent loop shared by requests from the chat screen and from system assistant entries. The model chooses tools through Tool Calling; results return to the context; the model decides the next step. Tool calls are validated against JSON Schema and permissions are checked before execution. A separate Hook process only handles entry and result passing, which keeps the vendor-assistant takeover from owning the whole runtime.
The runtime also manages streaming events, steering, cancellation and an incremental transcript. An appended instruction enters the next turn after the current one finishes. Sessions and results are archived on the device. After an interruption the runtime tries to recover existing records, and the README is explicit that it does not automatically replay operations. That is a sensible boundary: replaying a shell command or a tap sequence after a crash is how agents cause damage.
Tools are grouped rather than monolithic. System API calls use Android APIs and Intents for alarms, media and volume. The GUI Agent combines the accessibility UI tree, control location and on-demand screenshots to tap, scroll and type, with an overlay showing state and offering stop or takeover. A built-in WebView browser can load JavaScript pages, read text, manipulate the DOM and take screenshots, and the user can open the same session to take over. Terminal access spans user and root shell, Alpine or Debian Linux, and file read and write. A single task can mix them: read a page, then script a file operation, or find an order clue in notifications and open the app to confirm.
Installing Eta and running a first task
Eta ships as an APK on GitHub Releases; the README does not describe an app store listing or a package manager route. Download the APK, install it, then open the model provider settings and enter your API key and model choice. The README notes that running tasks requires Tool Calling, and that understanding images also needs a model with image input.
The README's quick start gives four numbered steps, and they are the only setup instructions the project provides. There is no command to run, so the first real configuration happens inside the app.
1. 从 Releases 下载 APK,安装后在“模型提供商”中填写 API Key 并选择模型。执行任务需要 Tool Calling,理解图片还需模型支持图片输入。
2. 按任务需要配置工具开关与权限:GUI Agent 需要无障碍服务;通知、应用使用情况分别授权;位置工具需要“始终允许”。工具页可查看当前设备的可用能力。
3. 开始对话。需要 Linux 时,在“Linux 工具环境”中安装发行版、基础工具及所需开发工具;需要系统入口时,参见系统助手入口。Permissions are per-tool. The GUI Agent needs the accessibility service. Notifications and app usage are granted separately. The location tool needs Allow all the time. The tools page shows what the current device can actually do, which is worth checking before you assume a capability exists.
For Linux work, install the distribution and the base tools from the Linux tool environment screen, then add development tools as needed. The README lists Python, Node.js, SSH, APK analysis and Kimi Code as on-demand installs. Normal devices use PRoot; root devices can also choose chroot. The two backends install independently and do not migrate data between each other, and the README states that PRoot's simulated root does not grant Android system permissions. Authorized Android directories can be shared into Linux at /workspace/mounts/.
If you want to drive Eta from the power button, that path needs LSPosed and matching system support. The README documents long-press power button options for the default assistant, Gemini or Eta, and takeover of Xiao Bu or Super Xiao Ai so the vendor entry hands the request to Eta with your configured model.
Where Eta stops: Root, ROM support and the vendor wall
The README is unusually candid about boundaries. The app itself is not brand-locked and basic features need no Root, but Root and LSPosed expand system access and assistant entries, and what you get depends on authorization and ROM adaptation. Contacts, SMS and calendar retrieval still require Root. Photo album, calendar, SMS, recordings, health summaries and chat images are described as specialized retrieval that needs Root, with some sources additionally requiring the right ROM and app support.
That is the honest limitation of the whole approach. The project's own motivation section describes why: Doubao's phone assistant ran into ecosystem limits, with reports of WeChat problems and takeovers being withdrawn, plus human verification and screen-sharing objections elsewhere. Eta's answer is to stay a third-party app and let the user hold the keys, but it cannot force other apps to expose interfaces. Where a service keeps its data closed, the GUI Agent is the fallback, and GUI automation is slower and more fragile than an API call.
There is a second failure mode that has nothing to do with permissions. The README states that background execution is affected by Android and vendor process management, so a force stop or reboot means starting Eta manually. System and app updates may require the hooks to be adapted again. If your workflow assumes the agent is always resident, that assumption will break.
Data handling deserves the same attention. Task conversations, images and tool results go to the configured model service; a local runtime is not local inference. A custom HTTP address transmits the API key and request content in cleartext. Raw parameters and results from sensitive tools and MCP are not written to persistent sessions, though model replies are still saved. Notification history is kept for the last 7 days up to 1000 entries once authorized, and MCP tokens are stored encrypted. Backups include the API key, which matters if you share an export.
Eta against Tasker and vendor assistants
Tasker is the closest well-known comparison for Android automation, and the difference is in who decides the steps. Tasker runs profiles and tasks you author in advance: a trigger fires, a fixed action list executes. Eta puts a model in the middle and lets it choose tools at runtime through Tool Calling, which is why it can handle a request you did not anticipate. The cost is predictability. A Tasker task does the same thing every time; an Eta task depends on the model's decisions, and the runtime validates each call against JSON Schema and rechecks permissions before execution rather than guaranteeing a fixed path.
Vendor assistants are the other comparison, and here the README's argument is about model choice. A first-party assistant is tied to whatever model the vendor ships and to the vendor's service ecosystem. Eta keeps the familiar entry point, the power button or Xiao Bu, but routes the request to a provider you configure. The trade is support surface: Eta depends on LSPosed and ROM adaptation for those entries, while a vendor assistant is maintained by the party that controls the OS.
For terminal work, the relevant comparison is running a Linux environment directly. Eta bundles Alpine or Debian through PRoot, or chroot on root devices, and exposes it to the agent as a tool. That is a convenience layer over something you could set up separately, but the agent integration is the point: the same loop that reads a notification can run a script.
Licence, releases and what an upgrade costs you
The repository carries a LICENSE file at the top level, and the metadata classifies it as NOASSERTION, meaning GitHub could not match it to a known licence template. Read the file yourself before you redistribute anything or build on the code; this article is not legal advice and the licence text is the only authority.
Release cadence is visible and recent: v3.0.0 on 2026-08-31, v3.0.1 on 2026-09-05 and v3.0.2 on 2026-09-07, with the last push to the repository on 2026-09-07. Three releases inside eight days is a fast patch rhythm, and it tells you something practical: if you adopt Eta, expect to reinstall the APK rather than wait for a store update.
The upgrade cost is not only the APK. The README warns that system and app updates may require re-adapting the hooks, so the LSPosed and vendor-assistant features carry ongoing maintenance. Linux environments are a separate cost: Alpine and Debian install independently and data does not migrate between them, so switching backend means rebuilding the environment. Model configuration is portable through export and import, but the backup contains the API key, so treat the export file as a secret. If you rely on the terminal, budget for re-checking installed development tools after a major Eta release.
Editorial conclusion
Eta suits Android 14+ users who already pay for a model API, want the phone's own entry points rewired to their chosen provider, and accept that Root, LSPosed and vendor ROM support decide how much of the device the agent can actually touch. It is the wrong tool if you want local inference, a fixed first-party assistant, or a guarantee that a vendor update will not break the hooks. Before installing, read docs/ROOTLESS_SUPPORT.md to see which capabilities your exact device and ROM unlock, and check whether your model supports Tool Calling, since tasks depend on it.
Frequently asked questions
Does Eta require Root to work?
No. The README states that the app is not limited by phone brand and that basic features need no Root, covering chat, the browser, memory, Skills, MCP, the normal terminal and the private workspace. Root and LSPosed expand system access and assistant entries, and contacts, SMS and calendar retrieval still require Root.
Can I use Eta without my own model API key?
No. The README states that using Eta's AI features requires bringing your own API key, and the provider and model are your choice. Built-in provider entries include OpenAI, Anthropic, Alibaba Bailian, DeepSeek, Kimi, MiMo, MiniMax, StepFun, SiliconFlow and OpenRouter, and a custom service can be added.
Which Android versions does Eta support?
The README states that Android 14 and above is supported, which matches the minSdk 34 badge in the repository. Linux support depends on having a compatible 64-bit device.
Does Eta run the model on the phone?
No. The README states that the local runtime does not mean local inference: the conversations, images and tool results a task needs are sent to the configured model service. It also warns that a custom HTTP address transmits the API key and request content in cleartext.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/mangi-11-eta)