REA: Reverse Engineer Anything with Agents

Hands reverse engineering to your coding agent, from app behavior down to native binaries.

Source repo
morluto/rea
Stars
★ 718
Last updated
today
License
MIT
Primary language
TypeScript

At a glance

How it runs
CLIMCP serverAgent plugin / skill
Works with
Universal · cross-platformCodex · Claude Code · Claude.ai
Cost
Free, no paid service needed
Setup effort
Medium · a few setup steps
You'll need
Node.js 22.19+ or 24.11+npmHopper Disassembler (separate license, demo mode supported)Ghidra 12.1.4 + 64-bit JDK 21 (optional, bring-your-own)macOS 12+ / Ubuntu 24.04+ / Fedora 41+ / 64-bit Arch Linux; Windows x64 for experimental Ghidra P0Shell / CLINetwork accessLocal filesystemMCP Server
Typical use
A product team sees a search or offline-caching feature in a shipped app with no source access and wants the agent to explain it, show evidence, and rebuild it for their own stack.
Not a fit if
  • Developers who only read source code and never touch binaries or runtime behavior
  • Teams that need deep native binary analysis on Windows (only a limited P0 boundary exists)
  • Users unwilling to install Hopper locally or supply their own Ghidra/JDK
Source review
72/100 · Some gaps

What does this agent do, and when should you use it?

REA is a reverse-engineering toolkit for coding agents, shipped as the npm package rea-agents with both a `rea` CLI and an MCP server that share one evidence contract and one investigation model. It wraps a deep-analysis provider — Hopper on macOS/Linux (demo mode supported) or a bring-your-own Ghidra 12.1.4 on Linux/macOS plus an experimental Windows x64 P0 — and exposes it through tools such as `open_binary`, `binary_overview`, `search_strings`, `find_xrefs_to_name`, `get_call_graph`, `procedure_pseudo_code`, and `batch_decompile`. Beyond native analysis it covers passive CDP website observation, attach-only Node/Electron V8 Inspector observation, JavaScript and source-map reconstruction, ASAR/package structure mapping, managed PE/CLI triage, and controlled process capture with comparison. Every successful call is recorded as deterministic Evidence with artifact and provider identity, confidence, authority, and limitations, exportable as bundles or reusable as snapshots. Analysis runs entirely on your local host — REA provides no hosted service and never uploads the target. It deliberately does not claim to recover original source code.

After setup, REA probes for local agents (Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin), writes MCP registrations additively and backup-first, and installs the matching routing skill. On each deep-analysis open it resolves a provider — request-level --provider/provider_id beats REA_ANALYSIS_PROVIDER, auto binds only a sole usable candidate and reports ambiguous otherwise, and runtime failure never triggers silent fallback. Commands like rea analyze, rea decompile, rea function, rea xrefs, and rea trace return the same Evidence envelopes as MCP; an MCP session can retain a live target and evidence ledger, and snapshot_path atomically imports a snapshot in open_binary or saves one in close_binary. Other surfaces include inspect-managed-artifact for PE/CLI metadata and CIL hashes, list-browser-targets/inspect-web-page for passive CDP capture, list-javascript-runtime-targets/observe-javascript-runtime for lifecycle metadata only, and capture-process/capture-browser-scenario for explicitly approved, per-call-granted behavioral capture.

  1. A product team sees a search or offline-caching feature in a shipped app with no source access and wants the agent to explain it, show evidence, and rebuild it for their own stack.
  2. A reverse engineer or security analyst needs to trace a suspicious string, symbol, or IPC channel all the way to the routine that implements it while keeping an auditable evidence chain.
  3. A developer handed an Electron app wants to statically reconstruct its ASAR modules, entrypoints, preload, and IPC graph without executing bootstrap code.
  4. Someone comparing two releases needs to find the first behavioral divergence across terminal output, filesystem, or protocol dimensions rather than eyeballing diffs.
  5. A maintainer of legacy .NET/CLI assemblies wants read-only metadata and P/Invoke boundary triage without loading the assembly or resolving CLR dependencies.
  6. A team that must reproduce analysis wants to freeze successful calls into snapshots or Evidence bundles and replay the same query without relaunching a provider.

How do you install or deploy this agent?

The recommended path is the reviewed setup wizard, which prints its full plan, exact paths, and external effects before a final confirmation that defaults to No:

npx --yes rea-agents@latest setup

To get a shell-visible rea command instead:

npm install --global rea-agents
rea setup
rea doctor

Setup configures Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, and Windsurf when detected; Devin is reported but left unchanged. Deep native analysis needs a provider: setup can install Hopper (official DMG to ~/Applications on macOS; pinned 6.4.2 package with checksum verification on Ubuntu 24.04+, Fedora 41+, Arch), while Ghidra is strictly bring-your-own:

export GHIDRA_INSTALL_DIR=/absolute/path/to/ghidra_12.1.4_PUBLIC
export JAVA_HOME=/absolute/path/to/jdk-21 # optional when java and javac resolve from PATH
rea doctor --json
rea providers --json

Requirements: macOS 12+, Ubuntu 24.04+/Fedora 41+/64-bit Arch Linux, with Windows x64 only for the experimental Ghidra P0; Node.js 22.19+ or 24.11+.

How do you use this agent?

After setup, restart any configured agent so it loads the aligned MCP registration and routing skill, then describe what you want investigated:

Reverse engineer the Notes app. Find how offline search works, explain it,
and build a version for my project using TypeScript and SQLite.

For a one-off terminal overview:

npx -y rea-agents@latest analyze /Applications/Notes.app
npx -y rea-agents@latest inspect /Applications/Notes.app
npx -y rea-agents@latest trace /Applications/Notes.app "offline"

Manual configuration for any client that supports local MCP servers:

{
  "mcpServers": {
    "rea": {
      "command": "npx",
      "args": ["-y", "[email protected]", "mcp"]
    }
  }
}

Reuse an approved result without relaunching a provider:

rea analyze /absolute/path/to/app --snapshot /absolute/path/to/analysis/app.json

Browser and runtime observation are off by default and need literal loopback endpoints plus approved origins:

export REA_BROWSER_OBSERVE_ENABLED=true
export REA_BROWSER_CDP_ENDPOINTS_JSON='["http://127.0.0.1:9222"]'
export REA_BROWSER_ALLOWED_ORIGINS_JSON='["http://127.0.0.1:3000"]'
rea inspect-web-page http://127.0.0.1:9222 TARGET_ID --approved --json

What are this agent's strengths and limitations?

Pros
  • One workflow and one evidence contract span the CLI and the MCP server, so the same capability can be a single terminal call or a session-held target with a live evidence ledger.
  • Providers are optional and explicitly bound: bring your own Ghidra 12.1.4 for a read-only path, or let setup install Hopper; switching requires an explicit selector and runtime failure never silently falls back.
  • Analysis stays local with no hosted service, and every dynamic surface — process capture, browser scenarios, JS runtime observation — is disabled by default and gated by per-call approval.
  • Coverage extends well past a single disassembler: passive CDP web observation, attach-only Node/Electron V8 Inspector observation, JavaScript/source-map reconstruction, and read-only managed PE/CLI triage.
  • Each successful call becomes deterministic Evidence carrying artifact and provider identity, confidence, and limitations, and can be exported, compared, or replayed from an immutable snapshot.
Limitations
  • Deep native analysis depends on external tooling: Hopper is separate licensed software (demo mode is vendor-limited), and Ghidra must be supplied at exactly 12.1.4 with a 64-bit full JDK 21 or doctor rejects it.
  • The platform boundary is real: full capability centers on macOS and Linux, while Windows offers only an experimental x64 Ghidra P0 that does not claim named-pipe DACL or hostile-local-user isolation.
  • The runtime is heavyweight — Node.js 22.19+ or 24.11+, and Linux demo automation additionally needs Xvfb, Python 3, libX11.so.6, and libXtst.so.6 — so first-time preparation is not trivial.
  • REA does not recover original source; decompiler text is explicitly a provider-specific observation, and treating it as source will mislead you.
  • Several advanced capabilities (browser scenarios, process capture, JS runtime observation, snapshots) require extra environment variables and per-call grants, so you pay an upfront cost in the permission model.

How does this agent compare with similar options?

Key facts side by side with the most closely related agents.

Agent Source review Form / cost Stars Updated Language Full support on
REA: Reverse Engineer Anything with Agents This agent 72 · Some gaps CLIFree ★ 718 today TypeScript Codex · Claude Code · Claude.ai
Auto RE Agent 61 · Some gaps CLIFree + model costs ★ 2k 24d ago Python Codex · Claude Code · OpenAI API · Claude API
Stock SDK 71 · Some gaps Library / SDKFree ★ 2k 1d ago TypeScript ChatGPT · Codex · Claude Code
Graphify – Turn Any Codebase into a Queryable Knowledge Graph 64 · Some gaps CLIFree ★ 124k 1d ago Python Codex · Claude Code

How does FollowAgents rate this agent?

FollowAgents source review · FARS-2.1
Some gaps
72/ 100 5-point scale 3.6 / 5
Trust 19/29
Reliability 9/14
Adaptability 16/18
Convention 14/18
Effectiveness 9/13
Verifiability 5/8
Why each dimension lost points
Trust19 / 29 · 3.3/5

Positive: README/SECURITY.md describe least-privilege design in detail (read-only Ghidra adapter, mode-0600 Unix socket, capability tokens, never invoking sudo, never installing Ghidra/Java without approval); setup defaults to No, is backup-first, supports dry-run, and leaves Devin untouched. Deducted: most controls are documentation assertions; no core implementation source was provided, only tests; opening an untrusted binary delegates parsing to the provider with the user's own permissions and SECURITY.md admits this is not a sandbox. Publisher is unverified; attribution rests only on the morluto copyright line in LICENSE.

Reliability9 / 14 · 3.2/5

Positive: doctor distinguishes unsupported hosts, missing dependencies, config drift; deps:check gates builds; all dependencies pinned; sharded CI with fail-closed steps. Deducted: runtime reliability claims rest on docs and test code and cannot be independently confirmed from this material; no vulnerability-audit evidence for the dependency set.

Adaptability16 / 18 · 4.4/5

Positive: audience (developers wanting to understand app features), dual terminal/agent paths, explicit capability boundaries (Windows P0 rejects DLLs/managed PEs, no original-source recovery, demo limits), OS and Node matrices, per-distro Linux notes. Deducted: trigger precision depends on skill routing whose content is not shown in this material.

Convention14 / 18 · 3.9/5

Positive: extremely thorough install notes (npx/global/curl distinctions, uninstall boundary, PATH hints), explicit and repeated known-limitations statements, full MIT LICENSE, multi-language README. Deducted: no CHANGELOG file in this material, only indirect Release Please signals; single unverified maintainer; no FAQ, examples concentrated in README.

Effectiveness9 / 13 · 3.5/5

Positive: structured JSON output, Evidence bundles, snapshot caching to avoid re-analysis, free Hopper demo path lowering cost. Deducted: output quality and marginal value are documented claims; no release history corroborates maturity; incremental benefit over direct Hopper/Ghidra use requires execution to confirm.

Verifiability5 / 8 · 3.1/5

Positive: verify:* script family, per-lane CI, and test code (rejecting spoofed providers, wrong-predicate Evidence) corroborate README claims; docs repeatedly separate facts from inference ('not original source', 'not a sandbox'). Deducted: the core src/ implementation is absent from this material, so key claims cannot be traced line-by-line to code.

Risks and how to mitigate them
  • Publisher is not verified by the curated registry; identity is unknown. Verify the repository-to-npm (rea-agents) correspondence yourself before use.
  • Reverse-engineering untrusted binaries delegates parsing to a local provider with your user's own permissions and is explicitly not a sandbox — analyze hostile samples in isolation or under a dedicated account.
  • Setup mutates MCP configuration across multiple agent clients; although additive and backup-first, run rea setup --dry-run to review the plan first.
  • Hopper installation is verified against the vendor-published SHA-1 checksum, which is a corruption check, not a signature; supply-chain risk is only partially mitigated by HTTPS origin restriction.
  • This is a static review (low confidence); no commands were executed. All behavioral claims come from documentation and test code and were not run-verified.
  • Windows x64 native analysis is an experimental P0 that explicitly excludes DLLs, managed PEs, and non-x86-64 images; do not use beyond that boundary.
  • Core src/ implementation and a CHANGELOG are absent from this material, so key security claims cannot be traced line-by-line.
Evidence confidence: Low Reviewed Oct 04, 2026 Reviewed revision 405732a7f55e
See the full review method →

FAQ

Is REA free? What about Hopper?
The rea-agents package itself is MIT-licensed and open source. Hopper is separate software with its own license; REA can run Hopper's free demo mode (on Linux it selects the offered demo mode inside a private Xvfb display), and a paid license is optional. The Ghidra route is entirely bring-your-own — REA never downloads or installs Ghidra or Java.
Does it upload my application anywhere?
No. REA ships no hosted analysis service; providers, passive observers, and process capture all run on your local host. Note that your agent or model provider has its own data policy, so review that separately.
Can REA recover the original source code?
No, and the README says so explicitly — no decompiler can guarantee the original source. REA hands the agent pseudocode, assembly, symbols, strings, metadata, and relationships it can use to explain behavior or build a compatible recreation, not the original project.
Does it work on Windows?
Only through a restricted path. Windows x64 gets an experimental Ghidra-only P0 boundary limited to approved native x86-64 PE applications; DLLs, managed PE files, non-x86-64 images, and non-PE formats are rejected, and automated rea setup plus Hopper installation remain unavailable on Windows.
Can I reproduce and diff analysis results?
Yes. Every successful call is recorded as deterministic Evidence, exportable as a bundle and canonically serializable via rea evidence-import/rea evidence-export, then compared with rea compare. You can also freeze calls into provider-neutral snapshots (--snapshot, or snapshot_path in MCP) that are reused only when the binary digest, kind, format, architecture, operation parameters, and provider build all match.
View on GitHub ↗ Install ↓

Compare agents like this one

The same FARS review applied across the shortlist this agent qualifies for.

Related agents