Android Studio 现在能跑任意编码 Agent:拆解 Bring Your Own Agent 与 ACP
2026 年 9 月 24 日,Android 团队在 Android Studio Canary 中上线了 Bring Your Own Agent(BYOA)。去年 Android Studio 已经开放给「任意 AI 模型」,这一次它把选择权推进到了编码 Agent 本身:Claude Agent、Codex、Antigravity 都能直接接进来,而 IDE 负责给它们喂上下文、注入原生工具。本文讲清楚这背后的 Agent Client Protocol、它为什么让 Agent 更省钱也更准,以及当 Agent 变成可插拔件之后,你需要补上哪几道治理闸门。
一、这次到底发布了什么
BYOA 目前以预览形式随 Android Studio Canary 的 Rabbit 2 版本推出,首批支持三家常被开发者使用的 Agent:Anthropic 的 Claude Agent、OpenAI 的 Codex,以及 Google 的 Antigravity。接入方式有两种,登录你自己的套餐,或者填 API key;注册表在 Settings > Tools > AI > Agents,任何符合 ACP 的 Agent 都可以被加进去。官方给出的四大好处是:把完整项目图、构建配置与平台细节通过协议交给 Agent 以提升 token 效率;在多次会话提示词与 IDE 原生工具之间无缝切换;Agent 可替换(某个 Agent 额度用完或表现不佳就换另一个);以及把构建诊断、Jetpack Compose 预览、Android SDK 工具和模拟器控制注入给 Agent。换句话说,IDE 从「内置一个 AI」变成了「运行一个 AI 的宿主」。
// BYOA is a registry, not a hard-coded menu. Give Android Studio the
// command, the transport, and the identity of an ACP-compliant agent,
// and it shows up in the agent window like any other tool.
// Settings > Tools > AI > Agents (name: claude, codex, antigravity, ...)
{
"agents": [
{
"id": "claude",
"label": "Claude Agent",
"transport": "stdio",
"command": "claude-agent --acp",
"auth": "user-plan",
"trust": "workspace-write",
"pinVersion": ">=2,<3"
},
{
"id": "antigravity",
"label": "Google Antigravity",
"transport": "stdio",
"command": "antigravity --acp",
"auth": "google-account-or-api-key",
"trust": "workspace-write"
}
]
}BYOA 在 Android Studio Canary 中开始预览
二、ACP 才是真正重要的那层
很多人会把注意力放在「支持了哪几个 Agent」,但真正的架构决定是 Agent Client Protocol。它把 Agent 与编辑器之间的交互标准化:一次 initialize 握手之后,就是普通的请求/响应流,Agent 可以申请读文件、跑 Gradle 任务、再读构建诊断。示例 1 展示了这件事的工程含义——BYOA 本质是一个注册表,你声明命令、传输方式、身份与版本钉选,而不是改代码去适配某一家。示例 2 则把「能不能碰」写成了显式能力声明:文件系统能不能写、终端能不能开、原生工具注入给哪几项,全都是一份可审查的清单,而不是一个布尔开关。协议的价值就在这里——换 Agent 不该意味着换你的工作流,也不该意味着换你的安全模型。
// The interesting half of ACP is not "can I chat with a model", it is
// "what may this agent touch". Declare capabilities explicitly, then let
// the IDE decide what to inject. Native tool injection is a privilege,
// so keep it a named list rather than a boolean.
{
"protocolVersion": "1",
"clientCapabilities": {
"fs": { "readTextFile": true, "writeTextFile": false },
"terminal": false,
"toolInjection": ["buildDiagnostics", "composePreviews", "emulatorControl"],
"projectGraph": { "provide": true, "scope": "relevantOnly" }
},
"limits": {
"maxTurnsPerTask": 25,
"maxTokensPerSession": 400000
}
}三、项目图为什么让 Agent 更省也更准
上下文是编码 Agent 最贵的资源。Android Studio 的做法是把完整的项目图、构建配置和平台细节提供给 Agent,再由 Agent 过滤出相关文件——官方描述为「高效使用 token、降低延迟、答案更准」。这与业界共识一致:与其把整个代码库塞进上下文,不如把结构化的、可按需裁剪的项目视图交给模型。示例 3 用 initialize 的 workspace 字段把这一点代码化:我们传入项目根与项目图的指纹,Agent 据此定位,而不是靠模糊的文件名猜测。指纹还有一个副作用值得利用——它让「Agent 看到的是哪个版本」成为可记录的事实,这在排查「它为什么改错了文件」时非常关键。
// A session opens with an initialize handshake. Everything after it is a
// normal request/response stream, which is why the same agent binary can
// sit behind a CLI, a CI runner, or an IDE without a rewrite.
const session = await client.initialize({
clientName: "android-studio",
protocolVersion: "1",
workspace: { root: projectRoot, graphFingerprint: "sha256:9f2c..." }
});
// One prompt, and the agent can ask for a file, run a Gradle task,
// then read the build diagnostics we already declared it may receive.
const turn = await session.prompt({
role: "user",
content: "Migrate this screen to Compose and make the tests pass."
});
for await (const update of turn.stream) {
if (update.kind === "tool_call" && requiresApproval(update.name)) {
await session.requestPermission(update);
}
}ACP 是 Agent 与 IDE 之间的那份契约
四、原生工具注入与权限
BYOA 的杀手锏是原生工具注入:构建诊断、Compose 预览、Android SDK 工具、模拟器控制。这意味着 Agent 不只是「写代码」,它能在你的环境里执行、诊断、验证。官方同时强调了粒度化权限:日常任务可自主执行,风险较高的动作需要你的批准。示例 3 的循环里就体现了这一点——当流式输出里出现需要审批的工具调用时,先请求权限再继续。这符合一条被反复验证的原则:控制点应该加在「动作」上,而不是加在「Agent 的自述意图」上。一个在追求目标的 Agent,很容易把一次危险的写操作描述成例行重构,只有环境层的闸门才拦得住。
// The convenience of pluggable agents is also the risk: every new agent
// is new code with new credentials inside your build environment. Pin
// what is allowed, and fail the build when someone adds a rogue one.
const ALLOWED = new Map([
["claude", { min: "2.0.0", egress: ["api.anthropic.com"] }],
["codex", { min: "1.4.0", egress: ["api.openai.com"] }],
["antigravity", { min: "3.0.0", egress: ["*.googleapis.com"] }],
]);
export function auditAgents(config) {
const problems = [];
for (const a of config.agents) {
const rule = ALLOWED.get(a.id);
if (!rule) problems.push("unapproved agent: " + a.id);
else if (!satisfies(a.pinVersion, rule.min)) problems.push("too old: " + a.id);
else if (a.egress.some((h) => !rule.egress.includes(h)))
problems.push("egress outside allowlist: " + a.id);
}
return problems;
}五、可替换性带来的新风险
当你可以在同一天里把 Claude、Codex、Antigravity 轮流接进 IDE,方便是真的方便,风险也是真的:每一个新 Agent 都是运行在你构建环境里的新代码,自带凭据、自带网络出口、自带升级节奏。示例 4 把这件事做成了一道 CI 检查:允许哪些 Agent、最低版本是多少、允许访问哪些出口域名,不在白名单里就让构建失败。这不是对某一家的不信任,而是对「可插拔」这个设计本身的诚实反应。官方也明确说明企业版与个人版套餐都支持,具体取决于 Agent 提供方——这句话的背面就是:凭据和合规边界由你负责,不由 IDE 负责。
# What did the IDE agent actually do yesterday? If you cannot answer that
# from logs you own, "the agent edited my project" is a rumour, not a record.
# Log the turn, the tool, the files touched, and the diff hash.
def record(turn, tool, files, diff_hash, actor):
ledger.append({
"ts": time.time(),
"agent": actor["id"],
"version": actor["version"],
"turn": turn,
"tool": tool, # e.g. writeTextFile, gradle, emulatorControl
"files": files, # workspace-relative paths only
"diffHash": diff_hash, # reproduce the change, do not re-read it
"approvedBy": actor.get("approver"), # set only when a human gated it
})
# One reviewable line, instead of a mystery commit at 2am.
for row in ledger.tail(20):
print(row["agent"], row["tool"], ",".join(row["files"]), row["diffHash"][:12])换 Agent 不该意味着换工作流
六、给团队的落地清单
第一,先在 Canary 里小范围试用,把 BYOA 当作预览能力而非稳定依赖。第二,用注册表集中管理 Agent、钉选版本、钉选身份来源,别让每个人的 IDE 里跑着不同版本的 Agent。第三,把原生工具注入做成显式清单,遵循最小权限。第四,把高风险工具调用接到审批闸门上,并同时记录「请求」与「批准」。第五,记录每一步的溯源——哪个 Agent、哪个版本、哪一轮、动了哪些文件、diff 哈希是多少,示例 5 给出了日志字段,示例 6 则把限制放进容器而不是放进 Agent 的承诺里。第六,把网络出口按 Agent 收敛到白名单。做完这些,你就同时拿到了 BYOA 的收益和一个可解释的环境。
📌 常见问题 FAQ
什么是 Android Studio 的 Bring Your Own Agent?
BYOA 是 2026 年 9 月 24 日随 Android Studio Canary 预览推出的功能,允许开发者把自己选择的编码 Agent 直接接入 Android Studio,首批包括 Claude Agent、Codex 和 Google Antigravity。
BYOA 现在可以直接用于生产吗?
官方说明 BYOA 目前处于预览阶段,从 Android Studio Canary 的 Rabbit 2 版本开始推出,因此不建议把它当作稳定依赖直接用于生产工作流。
Agent Client Protocol 是做什么的?
ACP 是 Agent 与编辑器之间的标准协议:完成 initialize 握手后以请求/响应流交互,Agent 可申请读写文件、执行命令。Android Studio 通过 ACP 把项目图和平台信息交给 Agent。
BYOA 能带来什么实际收益?
官方列出四项:通过项目图提升 token 效率并降低延迟;在提示词与 IDE 原生工具间无缝切换;Agent 可随时替换;以及把构建诊断、Compose 预览、SDK 工具与模拟器控制注入给 Agent。
接入可插拔 Agent 时最该注意什么?
把 Agent 当作运行在构建环境里的第三方代码来治理:集中注册表并钉选版本、显式控制原生工具注入与文件写入权限、记录每一步溯源,并用白名单收敛网络出口。
🔧 推荐工具
📚 参考资料
- Android Developers Blog — Build your way: Use any AI agent of your choice in Android Studio (Sep 24, 2026)
- Agent Client Protocol — Introduction
- Android Studio — Preview release channel
- Android Studio — Use a remote model (background on opening up to any model)
- Android Developers Blog — Android Bench 2: long-horizon tasks (Sep 2026)