rea is a free, open source frameworks & platforms project written in TypeScript and released under MIT. It has 29,472 GitHub stars, 3,500 forks and 70 open issues, and was last pushed 3 hours ago. On this registry it ranks #20 of 111 tracked projects in Frameworks & Platforms, with 5 head-to-head comparisons available.

What is rea?

REA is an open-source MCP server and CLI that lets AI coding agents — and your terminal — reverse engineer native binaries, JavaScript and Electron apps, .NET assemblies, and websites, with evidence attached to every conclusion.

What it is

REA (Reverse Engineer Anything) is a TypeScript project distributed on npm as rea-agents, built around the Model Context Protocol (MCP) so that agent clients such as Claude Code, Codex, Cursor, Gemini CLI and Grok Build can call reverse-engineering tools directly. It lives in the Node.js ecosystem, requires Node.js 22.19 or newer, and ships both an agent-facing MCP server and a standalone rea command for use from a plain terminal. Analysis runs locally, and every conclusion carries the evidence and stated limitations behind it, so an agent's output can be checked rather than taken on faith.

The concrete problem it addresses is that investigating an app without its source code normally means moving between a disassembler, a JavaScript or Electron unpacker, a .NET inspector and a browser one at a time, then manually stitching findings together. REA replaces that fragmented, hand-driven loop with a single MCP interface covering native binaries, JavaScript and Electron apps, .NET assemblies and websites, plus a matching set of workflow instructions installed alongside the server so the agent knows how to use the tools. The stated aim is practical: see a feature you like, understand how it works down to the binary level, and build a version for your own project.

Key capabilities

  • Exposes one MCP server whose tools span native binaries, JavaScript and Electron applications, .NET assemblies and websites, with a generated MCP tool catalog documented in docs/mcp-contracts.md.
  • Provides a terminal command for JavaScript work, for example npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json, returning modules, imports, Electron boundaries and their evidence from an extracted app directory or ASAR.
  • Performs native analysis through an existing Hopper or Ghidra installation; npx rea-agents setup can optionally install Hopper with your approval.
  • Runs static JavaScript analysis that needs neither Hopper nor Ghidra, so no native engine is required for that path.
  • Installs itself into your agent with npx rea-agents setup, which adds the MCP server and matching workflow instructions, proposes the changes for review, and backs up existing configuration before writing.
  • Supports Claude Code, Codex, Cursor, Gemini CLI, Grok Build and other agents, with provider configuration and manual MCP registration covered in docs/installation.md.
  • Documents provider selection and snapshots for native commands in the CLI and Evidence guide (docs/cli.md).

Who uses it and how

  • A developer who sees a feature in an existing app asks their agent to investigate it without source access, show the evidence, and then build an equivalent feature for their own project.
  • Reverse engineers and CTF participants (reverse-engineering and ctf are project topics) who drive analysis through an agent conversation instead of a GUI alone.
  • Practitioners who already hold a Hopper or Ghidra licence and want those engines reachable from an agent rather than only from their desktop.
  • Terminal-oriented users on any platform, including Windows paths such as "D:/apps/example", who install rea-agents and rea globally with npm and run the commands directly.
  • Teams standardising on a particular agent, since setup installs both the server and the workflow instructions into the chosen client with backups.

Getting started

With Node.js and npm installed, run npx rea-agents setup, choose your agents, review the proposed changes, approve them, and restart the agent; for regular terminal use install globally with npm install --global rea-agents rea.

How it compares

REA is not a competitor to Ghidra or Hopper but an orchestration layer in front of them: native analysis reuses an existing Ghidra or Hopper installation rather than shipping its own disassembler, while static JavaScript analysis deliberately needs neither engine. In that sense it sits alongside those tools in this registry, adding an agent-facing MCP interface, evidence-carrying output and workflow instructions that neither provides on its own.

When to use it — and when not

Native analysis requires you to configure a provider first and to have Hopper or Ghidra available, so anyone unwilling to operate an LLM provider plus a native engine should expect friction on the binary side. The project carries 70 open issues, and readers should consult the MIT LICENSE and the repository itself for current status before depending on it in a workflow.

project readme (upstream, from github) — read inline

English · 简体中文 · 繁體中文 · 日本語 · 한국어 · Türkçe · Русский · Tiếng Việt · ไทย · Deutsch · Español · Français · Українська · Polski · Português (Brasil) · العربية · فارسی

REA: Reverse Engineer Anything

One MCP for reverse engineering across binaries, applications, and runtime behavior.

See a feature you like. Understand how it works, down to the binary level.

npm version CI MCP tool catalog Node.js 22+ skills.sh MIT license Discord

morluto%2Frea | Trendshift

Website · Guides · Showcases

Quick start · How REA works · What you can analyze · Showcases · FAQ · Documentation

npx rea-agents setup




Join the Reverse Engineering Community

Discord · Q&A · Show and Tell


See a feature in an app that you want in your own product? Ask your agent to investigate it with REA. It can inspect the app without its source code, explain how the feature works, show the evidence, and build a version for your project.

REA connects your agent to tools for inspecting native binaries, JavaScript and Electron apps, .NET assemblies, and websites. You can also use the same tools from your terminal. Analysis runs locally, and results include the evidence and limitations behind each conclusion.

Setup registers REA with your agent and installs matching workflow instructions. Native analysis can use an existing Hopper or Ghidra installation; setup can optionally install Hopper with approval. Static JavaScript analysis needs neither engine.

Visit the REA website for setup instructions, illustrated guides, and real case studies.

Quick start

Set up your agent

With Node.js and npm installed, run:

npx rea-agents setup

Choose your agents, review the proposed changes, and approve them. Setup adds REA's MCP server and matching workflow instructions, with backups of existing configuration. Restart your agent afterward.

Setup supports Claude Code, Codex, Cursor, Gemini CLI, Grok Build and other agents. See installation and setup for provider configuration and manual MCP registration.

Ask your agent

Understand how search works in the Notes app, show me the evidence, and build a
similar feature for my project.

Replace Notes with your target app and the feature you want to understand.

Use the terminal

Inspect an extracted JavaScript/Electron app directory or ASAR:

npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json

The result includes modules, imports, Electron boundaries and their evidence. Replace the path with your target, such as "D:/apps/example" on Windows.

To install the rea command for regular use:

npm install --global rea-agents
rea --help

For native analysis, configure a provider first. See the CLI and Evidence guide for native commands, provider selection, snapshots and scripting.

Update REA

REA changes quickly, and new releases include frequent bug fixes. Keep your installation up to date.

For an npm-installed CLI:

rea update

To refresh your agent registrations and skill, run the setup command printed by the update.

If you use npx, update your agent setup with:

npx rea-agents@latest setup

Review the setup changes and restart your agent. For one-off CLI commands, use npx rea-agents@latest followed by the command.

How REA works

Your agent calls REA through MCP to inspect the target and trace relevant code. REA returns findings with their evidence. The agent uses them to ask follow-up questions, explain the behavior, or write and test an implementation. CLI commands use the same workflows.

REA investigation flow: your agent asks about a local target, REA inspects and traces it using analysis tools, and the agent uses the returned code, references and unknowns to explain, implement and test.

Open the full-size figure.

What you can analyze

REA requires Node.js 22.x (>=22.19), 24.x (>=24.11), or 26+, plus npm. Additional tools and host support depend on the target:

Target What REA returns Requirements and guide
Native binaries Pseudocode, assembly, strings, symbols, calls and references Hopper, Ghidra or IDA; native analysis
Offline ELF layout Sections, segments, original symbols/relocations and static mitigation candidates Caller-supplied pwntools on Linux x64; binary diagnostics
EVM bytecode Dispatch selectors, byte offsets, inferred arguments and mutability Local raw/hex carrier; offline EVM guide
Recorded Linux crashes Raw notes, every recorded thread's registers/signals and optional mapping candidates Caller-supplied pwntools; optional GDB/pwndbg; recorded crashes
JavaScript / Electron Modules, imports, source maps, routes, IPC and native add-on relationships Node.js and npm; application analysis
Websites Page structure, scripts, network observations and requested screenshots A Chrome-family browser; browser analysis
Saved network captures Requests, responses, exposed payloads and source locations HAR; mitmdump on Linux for native mitmproxy captures; capture guide
.NET assemblies Metadata, CIL instructions, declared native dependencies and build comparisons Static inspection; managed-code guide
Android APKs Manifest declarations, classes, decompiled methods and references Headless JADX and a full JDK on Linux/macOS; Android guide
Firmware Regions, extraction results and native-analysis handoffs Binwalk / Unblob on Linux; firmware guide
Packages and resources File inventories, digests, plists, Apple bundle anatomy and extracted resources Artifact and JavaScript guide, Apple applications
Process behavior Terminal output, interactions, exit and filesystem observations, and run comparisons Linux/macOS with a native PTY; process capture

Static JavaScript and .NET inspection read the supplied files without running the application. Runtime capture runs or interacts with the selected target using your user permissions; each runtime guide describes its effects.

Native formats and host support vary by provider. See Hopper and Ghidra setup, the IDA guide, and experimental Windows Ghidra support. Ghidra also supports 16-bit DOS analysis. For large binaries, raise its startup deadline with REA_GHIDRA_STARTUP_TIMEOUT_MS. For provider selection, see the CLI guide. Check release availability for features added since the latest npm release.

Showcases

DX-Ball: reconstruct a sound-pan calculation

Follow a sound call into its position-to-pan helper, inspect the instructions, and turn incomplete pseudocode into C. The reconstruction passes 3,205 original-x86 cases and reproduces all 63 compiled function bytes.

Read the case study · Reconstruction repository

Notion: trace the Electron clipboard bridge

Find the renderer's clipboard API, follow it through preload and IPC into the main process, and inspect the rich clipboard format.

Read the case study

TH04: recover a DOS bullet-ring calculation

Inspect the original PC-98 game's 16-bit instructions, recover the fixed and aimed angle calculations, and compare the reconstructed C++ with the historical compiler output.

Read the case study · Reconstruction repository

If you've used REA on something interesting, we'd love to see it. Share your case in an issue or a pull request, including the target, your question, how REA helped, and what you found.

FAQ

Which agents can use REA?

Any agent that supports local MCP servers. Setup configures the supported agents; other clients can use manual MCP registration.

Do I need Hopper, Ghidra or IDA?

Deep native analysis uses one of them. Static JavaScript and .NET inspection work without a native analysis engine. Setup can install Hopper after approval; Ghidra and IDA use your existing installations. See provider setup.

Do I need to start Hopper first?

REA starts Hopper when an operation needs it. On macOS, a first-run dialog may ask you to choose demo mode or activate your license. See Hopper startup and troubleshooting.

What does installing the skill from skills.sh do?

The skill supplies investigation instructions for your agent. Use rea setup to register REA's MCP server and install the matching instructions, then restart your agent. See skill-only installation.

What code does REA return?

Native analysis returns pseudocode and assembly. JavaScript/Electron analysis recovers modules and their relationships. Your agent uses these findings to write and test an implementation; the showcases give worked examples.

Does REA upload my app?

REA analyzes targets locally. Your agent receives the tool results, and its model provider has its own data policy.

What should I do if I hit a bug?

Update first; a recent release may already fix it.

For an npm-installed CLI:

rea update

For agent setup through npx:

npx rea-agents@latest setup

If you're using an agent, complete the setup refresh and restart it. Retry the same task. If the problem persists, open an issue with your REA version, target type, steps to reproduce and error output.

Documentation

Start with the website's worked guides. For exact options, prerequisites and result contracts:

Report vulnerabilities through SECURITY.md.

Contributing

We'd love your help with REA! Open an issue to report a bug or suggest a feature, or send a pull request to improve the code or docs.

See CONTRIBUTING.md for development setup and checks, testing for verification lanes, and the architecture map for the project structure.

Project links

Website · npm · skills.sh · Issues · Security

Star history

🎉 20,000 GitHub stars — thank you!

Thanks to everyone using REA, reporting bugs, testing builds, and contributing fixes.

REA GitHub star history

Disclaimer

REA provides tools for lawful reverse-engineering research, analysis, and reconstruction. You are responsible for obtaining any required authorization and complying with applicable laws. The project does not endorse illegal or unauthorized use.

License

MIT

Frequently asked questions

Is rea free to use?

rea is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does rea do?

Reverse engineer anything with agents, from app behavior down to native binaries.

What is rea written in?

rea is primarily written in TypeScript. Its source is publicly available at https://github.com/morluto/rea, and it has 29,472 GitHub stars.