Zafiro
1.5.0 · GitHub
More about this app
Bring-your-own-key AI agent that reads the screen and controls the device through Shizuku, without root.
中文 | English
What is Zafiro?
Zafiro is an open-source intelligent Agent running on Android devices, with BYOK support. It understands your screen, controls your device, and carries out operations across apps — with full support for Skills, MCP, and memory. It can also run Shell and Python 3 natively and wrap tools on its own to perform tasks such as web search and file downloads, or connect to a remote dev machine via SSH.
![]() |
![]() |
![]() |
![]() |
| Device Control | Research | Install Apps from the Web | Settings |
Important
Zafiro runs via Shizuku — no Root required; Root users get the full experience.
You can download a release from Releases, or choose to build from source.
Core Capabilities
Modern UI Design Language
- Material 3 Expressive & Apple Liquid Glass - a modern, polished interface
- Personalized Theming - multiple theme colors with dark mode and dynamic color extraction
- Multilingual Support - English, 中文, 日本語, Español
- Background Interaction - sleek floating ball and notification tray UI to follow and interact with the Agent in real time
Device Control
- Screen Interaction - open apps, pick music, order food — all done for you
- Fully Visible - an on-screen mouse shows every step the Agent takes
Agent System
- Out-of-the-Box - built-in support for OpenAI, Anthropic, Google Gemini, DeepSeek, OpenRouter, Kimi, Alibaba Bailian, SiliconFlow, and more
- Extend as Needed - full support for Skills and MCP, plus memory and a workspace — extend it your way
- Permission Management - with configurable rules, every command and piece of code is under your control
- Conversation Control - rewind, edit, and regenerate any turn at will; all conversation data stays strictly local, and models can be switched on the fly within the same session
Python Tools
- Run Code Directly - run Python 3 natively on the device
- Meta-Tooling - wrap your own Python tools; the Agent reuses and maintains the tools it creates
- Built-in Scenarios - web search, web page reading, and APK installation work out of the box
Remote Environments
- Termux - use Linux commands and tools on your Android device
- SSH - connect to a dev machine or server to execute remote tasks
- Claude Code - issue dev tasks from your phone, executed by a remote Coding Agent
Voice Assistant Takeover
Through the LSPosed framework, Zafiro can take over your system voice assistant — wake Breeno or XiaoAi, and the one actually answering is your own Agent. You can decide, based on keywords, which requests go to Zafiro and which pass through to the native assistant. After takeover, the assistant retains full Agent capabilities including device control.
Note
Taking over the system voice assistant requires Root + LSPosed, and currently supports: OPPO - Breeno
Voice takeover availability may be affected by phone model, system version, voice assistant version, and vendor system restrictions. When your device does not yet support system assistant takeover, you can still use Zafiro's chat interface with all Agent capabilities.
Demos
![]() |
![]() |
![]() |
Tech Stack
| Category | Technology |
|---|---|
| Language | Kotlin |
| UI Framework | Jetpack Compose |
| Design Language | Material Design 3 Expressive |
| Liquid Glass | Android Liquid Glass |
| Agent Runtime | Okia |
| Python Runtime | Chaquopy |
| System Takeover | LSPosed + Xposed API |
| Terminal / SSH | libterm |
| SVG Rendering | coil-resvg (resvg) |
| G2 Rounded Corners | Capsule |
Getting Started
Build from Source
./gradlew assembleDebug
Requirements
- Android Studio (or Android SDK + JDK 17)
- An Android 11 or above device
Release Signing
To build a Release version yourself, use your own signing key:
keytool -genkeypair -v -keystore my-release.jks \
-keyalg RSA -keysize 2048 -validity 10000 -alias my_key
./gradlew assembleRelease \
-PRELEASE_STORE_FILE=/absolute/path/to/my-release.jks \
-PRELEASE_STORE_PASSWORD=yourStorePassword \
-PRELEASE_KEY_ALIAS=my_key \
-PRELEASE_KEY_PASSWORD=yourKeyPassword
Project Structure
./
├── app/ # Main app: Compose UI, AgentRuntimeService, Xposed hooks
├── business/ # Core business layer (separation of contracts and implementations)
│ ├── api/ # Public business contract interfaces
│ ├── agent/ # Agent core logic, conversation orchestration & state flow
│ ├── notification/ # Resident notification, foreground service & channel management
│ ├── permission/ # Unified permission manager (Root / Shizuku auto-granting, tool approval)
│ └── application/ # Application management & lifecycle
├── agent-runtime/ # Agent runtime: LLM invocation, Tool/Skill/MCP execution, Python runtime
├── xsettings/ # Lightweight configuration module (depended on by modules as needed)
├── store/ # Store persistence, IPC bridge (XIpcBridge)
├── ui-kit/ # Shared Compose components, LiquidScreen shell, navigation
├── remote-view/ # Cross-process / floating RemoteView components
├── xposed-api/ # Xposed event types, shared constants (shared by main app and host process)
├── xposed-runtime/ # Xposed runtime, hook base classes
└── libs/
├── logging/ # Logging library
├── okia/ # Okia Agent runtime base library
└── libterm/ # Terminal library (multiple backends: libsu, shizuku, ssh, etc.)
Roadmap
- System voice assistant integration (non-Xposed takeover)
- File import / sharing from outside the app
- Built-in skills like Termux,
/skillhints, and cloud skill imports
Contributing
Pull requests are welcome!
- Fork this project
- Create a feature branch (
git checkout -b feat/your-feature) - Commit your changes (
git commit -m 'feat: add your feature', following Conventional Commits) - Push to the branch (
git push origin feat/your-feature) - Open a Pull Request
Community
- Telegram — discuss, ask questions, give feedback
- GitHub Issues — report bugs or request features
- Afdian — support the developer
When reporting an issue, please include as much detail as possible: phone model and Android version, system voice assistant and its version, Zafiro version, steps to reproduce, and screenshots or screen recordings.
License
MIT — see LICENSE.
Made with ✨️ by niki914
How Shizuku is used
Can run agent shell commands, tap and swipe, capture screenshots and grant permissions via `sh`, `input`, `screencap`, `settings`, `pm grant` and `appops set` through Shizuku.
This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.
How this app uses Shizuku
Zafiro uses Shizuku to give its on device AI agent a privileged shell that can operate the device.
- Run agent shell commands: the agent terminal tool can run the command from the agent request in a shell session hosted through Shizuku, returning stdout, stderr and exit code.
- Tap, swipe and press keys: screen operations perform taps, long presses, swipes and key presses with the
input tap,input swipeandinput keyeventshell commands through Shizuku when driving the screen by shell. - Capture screen images: the screenshot tool captures the full device screen with the
screencap -pshell command through Shizuku so the model can see the display. - Enable access and notifications: setup automation reads and writes secure settings with the
settings get secureandsettings put secureshell commands and grants overlay, storage and notification access with theappops setandpm grantshell commands through Shizuku.
Android APIs or commands used
shsettings get secure enabled_accessibility_servicessettings put secure enabled_accessibility_servicessettings put secure accessibility_enabledappops set SYSTEM_ALERT_WINDOW allowappops set MANAGE_EXTERNAL_STORAGE allowappops set POST_NOTIFICATION allowpm grant android.permission.POST_NOTIFICATIONSpm grant android.permission.READ_EXTERNAL_STORAGEpm grant android.permission.WRITE_EXTERNAL_STORAGEinput tapinput swipeinput keyeventscreencap -p
Notable details
Terminal defaults to an unprivileged identity and screen control prefers accessibility; Shizuku is used when the agent selects it or when privileged shell commands are needed, with a normal shell remaining for basic commands. Screenshot requires a privileged shell and fails when Shizuku is unavailable.
Changelog
What's new for version 1.5.0
- Added file attachments: you can now send any file in a conversation
- Fixed leftover UI issues on older Android versions
- Added a Max Tokens setting
- Fixed Google provider compatibility issues and improved overall stability
- 新增文件添加功能,现在你可以在对话中发送任何文件
- 修复遗留的低安卓版本上的 UI 体验问题
- 新增 Max Tokens 配置
- 修复 Google 提供商的兼容性问题,提升整体稳定性
Permissions
13 permissions requested






