Software Mirrors
ProductsBlogs
REA - Reverse Engineer Anything - rea-agents-6.3.0

REA - Reverse Engineer Anything - rea-agents-6.3.0

REA is an open-source reverse engineering toolkit that helps AI agents analyze applications, native binaries, JavaScript, and Electron apps. Use its CLI and MCP server to investigate software behavior, inspect code, and recreate features locally.
(4.7)

Developer

morluto

Category

Developer Tools

Operating System

All Platforms

Date Published

Sat Oct 10 2026

Review REA - Reverse Engineer Anything - rea-agents-6.3.0

REA, short for Reverse Engineer Anything, is an open-source toolkit that helps AI coding agents investigate how software works, even when its original source code is unavailable. Hosted on GitHub, the project connects agents to analysis tools for native binaries, JavaScript applications, Electron apps, and other software.

Rather than attempting to recover an application's exact original source code, REA collects evidence from decompilers, disassemblers, strings, symbols, function references, and other analysis techniques. An AI agent can use that evidence to explain a feature, document an implementation, or build a compatible alternative for another project.

REA provides a command-line interface (CLI), a Model Context Protocol (MCP) server, and guided workflows for compatible AI coding tools. It is particularly useful for developers who need to understand undocumented behavior, investigate legacy software, or reproduce a feature without access to its implementation.

Features

AI-Assisted Reverse Engineering

REA is designed to let developers investigate software by describing what they want to understand in natural language.

For example, you could ask an AI agent to investigate how an application's offline search works, trace the relevant functions, explain the evidence, and implement similar functionality in your own project.

REA supplies the investigation tools and findings, while the AI agent performs the reasoning and writes the new implementation. This division makes it easier to investigate unfamiliar software without manually navigating every analysis tool.

The workflow generally follows three stages: decompile or inspect the target, trace the relevant behavior through the available evidence, and recreate the desired functionality in a separate implementation.

Native Binary Analysis

REA connects AI agents to tools that inspect compiled native applications. Depending on the configured analysis provider, developers can examine functions, strings, symbols, assembly instructions, pseudocode, references, and call relationships.

These capabilities help investigate how a binary implements a particular feature or interacts with other components.

For native analysis, REA supports integration with Hopper and Ghidra. The project also documents IDA-related support in its broader development direction, although provider availability and individual capabilities depend on the installed version and platform.

Hopper is a separate product with its own licensing requirements. Ghidra must be installed independently and configured before REA can use it.

Importantly, decompilation produces an approximation of the original program logic, not the original source code with all its comments, names, and design decisions intact.

JavaScript and Electron Application Inspection

REA can analyze JavaScript applications and Electron packages without executing the target application.

It can inspect application directories and ASAR archives to identify modules, imports, dependencies, and relationships between components. This is useful for understanding how a desktop application's frontend communicates with its underlying services.

For example, developers can investigate how an Electron application handles authentication, storage, updates, or networking by examining the available code and tracing the relevant modules.

Static analysis is especially convenient because it does not require a native decompiler for supported JavaScript targets. It also reduces the risks associated with running unfamiliar applications during an initial investigation.

Command-Line Interface

REA provides a CLI for running analysis tasks directly from a terminal or through automation scripts.

Install the command-line package globally with npm:

npm install --global rea-agents

Then start the guided setup:

rea setup

To check the environment and configured analysis tools:

rea doctor --json

For a JavaScript application or Electron package, you can run an analysis directly:

npx -y rea-agents@latest analyze-javascript-application \
  /absolute/path/to/app --json

The JSON output makes it easier to process analysis results programmatically or pass structured findings to another tool.

Native binary analysis requires an appropriate provider to be installed and configured. The CLI therefore serves as a common entry point rather than replacing the underlying analysis engines.

MCP Integration for AI Coding Agents

One of REA's strongest features is its MCP server, which exposes analysis operations to compatible AI assistants.

The setup utility can configure supported clients, including Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, and Windsurf. Additional clients can connect through manual MCP configuration if they support local MCP servers.

After setup, an agent can call REA's tools to inspect a target, search for strings, examine functions, trace references, and collect evidence without requiring the user to execute each analysis command manually.

This integration is valuable for AI-assisted software development because it allows reverse engineering to become part of the same workflow used to modify and test code.

Guided Workflows and Evidence-Based Results

REA provides structured investigation workflows intended to guide an agent from an initial question toward a supported explanation.

Instead of returning only a conclusion, the tools can provide evidence and identify unresolved questions or limitations. Developers can then distinguish observed behavior from assumptions that require further testing.

The project also supports reusable analysis results and snapshots in relevant workflows, reducing the need to repeat expensive analysis operations unnecessarily.

This evidence-oriented approach is particularly useful when examining unfamiliar or poorly documented software, where an unsupported conclusion could lead to an incorrect implementation.

Local Analysis and Privacy

REA is designed to analyze target applications locally rather than uploading them to a hosted REA analysis service.

This is beneficial when investigating internal tools, proprietary software, or applications that cannot easily be shared with an external service.

However, the privacy boundary also depends on the AI agent and model provider being used. Analysis results returned to an agent may be sent to its configured model service, so developers should review that provider's data-handling policy before investigating confidential software.

Guided Installation and Diagnostics

REA includes a setup utility that configures the CLI, MCP server, and matching agent instructions. It can connect existing analysis tools and offer to install Hopper when needed.

The setup process presents proposed changes for review and approval and backs up existing agent configuration before applying changes.

Its diagnostic command checks dependencies, host compatibility, analysis tools, and agent configuration:

npx -y rea-agents@latest doctor

This helps developers identify missing dependencies or configuration problems before attempting a more involved investigation.

Performance and Compatibility

REA is distributed as a Node.js application and supports the command line and local MCP workflows. Its documented runtime requirements include Node.js 22.19 or newer in the 22.x line, Node.js 24.11 or newer in the 24.x line, or Node.js 26 and later.

Native analysis depends on the configured provider and supported host environment. The project documents support for macOS and selected Linux distributions, while Windows support varies by analysis provider and workflow.

Static JavaScript and Electron analysis has fewer dependencies because it does not require a native analysis engine. This makes it a convenient starting point for developers who want to try REA without installing a separate disassembler.

Actual analysis speed depends on the target application's size, the chosen provider, and the complexity of the behavior being investigated. Large native binaries may require more time and resources than a small JavaScript application.

REA is an analysis framework rather than a universal decompiler. Its capabilities depend on the tools available for the target platform, and the accuracy of conclusions depends on the evidence that can be recovered. It cannot guarantee recovery of original source code or perfectly reproduce every behavior of an application.

System Requirements

Ghidra integration has additional requirements, including a compatible Ghidra installation and Java Development Kit. Consult the current installation documentation for exact versions and platform-specific instructions.

Pros and Cons

Pros

Cons

Download REA - Reverse Engineer Anything - rea-agents-6.3.0 - Software Mirrors

REA - Reverse Engineer Anything - rea-agents-6.3.0 Source Code

REA - Reverse Engineer Anything - rea-agents-6.3.0 Source code (zip)

REA - Reverse Engineer Anything - rea-agents-6.3.0 Source code (tar.gz)

REA - Reverse Engineer Anything - rea-agents-6.3.0 Release Notes:

6.3.0 (2026-10-09)

⚠ BREAKING CHANGES

  • captures: Historical captures without current producer accounting or transaction identity, and web diffs missing accessibility or storage dimensions, are rejected. Preserve original captures and recapture with the current producer; update comparison consumers to include every dimension rather than synthesizing missing observations. See the process capture guide and browser scenario contract. (3283a45)

  • browser: JSON shape paths now contain typed property and array-element segments. WebMCP input_schema_shape is replaced by input_schema and input_schema_sha256, retaining declared examples and defaults.

  • process: Filesystem digest omission entries now require system_code; budget and changed-file omissions use null, and unavailable-file omissions preserve the operating-system error code.

  • contracts: Provider analysis outputs must explicitly supply metadata previously repaired with defaults; unsupported nullable facets must be reported as null.

  • javascript: Semantic graph facts now store evidence context IDs and locations. Graph and semantic trace results require an inline evidence_contexts table.

  • contracts: source-map URLs now live in target observations selected by declared_url_sha256, and doctor skill identity no longer emits installed_catalog_digest. Use the documented observation join and identity.skill.state instead.

  • javascript: remove the never-incremented truncated_scopes statistic from JavaScript application analysis results and schemas.

  • native: Objective-C attribute tokens now contain only name and value. Properties report nullable atomicity and readonly facts; class flags, ivar counts, and method requirement flags are nullable when unobserved.

Features

  • setup: register OMP during setup (#1301) (8b4c359)

  • javascript: record Electron integrity mismatches (7915ee5)

Bug Fixes

  • inspector: retain observations after capture failures (dea3498)

  • artifacts: bind ASAR interpretation to owned snapshots (d79317c)

  • artifacts: infer legacy Mach-O simulator platforms (5aa2002)

  • artifacts: preserve archive facts and Unicode path identity (5751f5c)

  • artifacts: reject incomplete inventoried extraction (5e8fb53)

  • artifacts: retain DMG ownership through uncertain attachment (a27794c)

  • artifacts: validate only active extraction entries (cfb12e4)

  • browser: follow only HTTP redirect statuses for source maps (82bbe74)

  • browser: preserve payload shapes and WebMCP declarations (4951a89)

  • browser: release attached viewport overrides without resizing the external page (f6cfbfc)

  • browser: retain attached scenario emulation until cleanup (a0523b3)

  • browser: retain malformed redirect diagnostics (617cd84)

  • browser: serialize attached scenarios through cleanup settlement (cfce91d)

  • ci: scope verification and reuse native runners (#1344) (d5cb8ae)

  • cli: avoid duplicate primary cleanup diagnostics (37fcea7)

  • cli: classify JSON input permission denials (08daf05)

  • cli: classify oversized JSON inputs (f7cf4c8)

  • cli: stream JSON inputs beyond the whole-document string limit (#1360) (6ce3288), closes #1331

  • cli: stream JSON results at the shared command boundary (810107a)

  • contracts: advertise NUL with a portable hex escape (3f59a84), closes #1329

  • contracts: require observed provider output metadata (a4ba8ae)

  • electron: preserve unrepresentable numeric option evidence (41a228c)

  • evidence: order canonical projections independently of locale (614fb76)

  • files: reject nonregular capture and JSON inputs (5f16124)

  • filesystem: reject unstable artifact targets (7829b1a)

  • ghidra: reject a native decompiler built for another host (#1280) (3728c82), closes #1192

  • ghidra: retain process ownership after failed launch rollback (07675f7)

  • ghidra: verify dense jump tables on an optimized fixture (#1374) (73a664b)

  • hopper: allow restart after verified owned-provider shutdown (1c12349)

  • hopper: probe interior navigation from multi-byte instructions (#1285) (bf934d5)

  • ida: compare admitted document paths consistently (890bb66)

  • javascript: avoid positive-zero evidence for signed zero (9055bd6)

  • javascript: decline source-map UNC references with an unusable host (#1372) (f504c2a)

  • javascript: distinguish prefix-only builtins from packages (2b4abbf)

  • javascript: honor module-sync package exports (#1361) (d0e6069)

  • javascript: parse declaration artifacts in ambient mode (4896adc)

  • javascript: preserve agreeing module provenance (db171be)

  • javascript: preserve capture-time guards and ordering (001851f)

  • javascript: preserve semantic evidence through satisfies (e995b19)

  • javascript: preserve uncertainty after references escape to calls (#1292) (355a292)

  • javascript: reject invalid package exports configurations (7a4f268)

  • javascript: resolve exported callables through lexical bindings (#1351) (a9f5dad)

  • javascript: resolve query-only HTML references to their document (55a46f7)

  • javascript: retain array identity after length mutations (4bcea1a)

  • javascript: retain conditional mutation ordering uncertainty (b8a8190)

  • javascript: retain distinct module provenance path components (2bd7de6)

  • javascript: retain unresolved value frontiers in provenance queries (3e19875)

  • javascript: store source map URLs once (ed8fcae)

  • json: preserve runtime limits across JSON file readers (#1350) (9c4a68b)

  • managed: bind graph facts to their source Evidence (cc7b5af)

  • mcp: admit composed analysis through result bookkeeping (e11f4d3)

  • mcp: advertise object roots for union input schemas (#1373) (39dabd0)

  • mcp: advertise primitive semantic literal seeds (f62b449)

  • mcp: preserve JavaScript workflow identity validation (#1366) (53ed942), closes #1364 #1065

  • mcp: retry failed shutdown resources and retain failure reasons (e64678e)

  • native: distinguish symbol definitions from metadata (70bad53)

  • native: preserve unknown Objective-C metadata (b112d44)

  • native: refuse to list architectures of non-Mach-O targets (#1325) (1b73b5a)

  • native: retain LLDB cleanup ownership through client close (7ad353f)

  • process: keep unobserved file contents unknown (#1358) (f91f279)

  • process: retain per-file digest open failures (415145d)

  • reference: report malformed UTF-8 before import parsing (f166a2a)

  • report malformed application evidence as input errors (218c131)

  • retain completed observations when later analysis steps fail (35f121f)

  • setup: install the skill for Claude Code (b4a1919)

  • setup: recognize supported Nobara hosts (f0dc233)

  • skill: pin packaged commands to the shipping package version (2793672)

  • skill: pin packaged commands to the shipping package version (#1346) (f39e71c)

  • snapshot: preserve complete investigation revision histories (#1354) (1c0cc8a)

  • targets: cancel resolution before provider admission (f3c4a33)

  • update: preserve disabled client registrations (abf5e24)

Performance Improvements

  • javascript: index version relationships once per comparison (#1347) (b1e85ad)

  • javascript: validate the version change graph once (#1370) (037709a)

  • json: encode streamed JSON iteratively (#1322) (56598be)

Code Refactoring

  • use canonical implementations and types directly (765e809)

  • artifacts: remove unused root classifier (5291bca)

  • artifacts: test inventory changes at materialization boundary (750fb65)

  • browser: open scenario sessions without a factory wrapper (d1983a4)

  • catalog: import CLI metadata from its owner (8c96baa)

  • consolidate boundary semantics and prune redundant tests (392f1f3)

  • javascript: normalize erased expression syntax once (b628bba)

  • javascript: parse runtime evidence into one verified owner (006b295)

  • javascript: remove obsolete scope truncation statistic (449d570)

  • javascript: share Babel child traversal (0f10499)

  • javascript: share semantic evidence at fact construction (e3bbb9a)

  • process: remove duplicate observation and trace entry points (070339a)

  • providers: use canonical artifact and managed identities (87f0051)

  • reference: simplify malformed UTF-8 handling (377df71)

  • remove obsolete source exclusions and identity wrapper (44c92f8)

  • remove single-use forwarding helpers (4144e45)

Documentation

  • keep license sections text-only (e10f1f0)

  • align translated README artwork and layout (ccfbe87)

  • add README artwork and refine closing sections (4b8e744)

  • add repository-local REA tool design skill (7738c1f)

  • celebrate 40,000 GitHub stars 🎉 (3edb217)

  • celebrate 40,000 GitHub stars 🎉 (5ecc98a)

  • consolidate agent guidance around ownership and boundaries (ba44222)

  • contracts: explain canonical URL and skill metadata ownership (e36afa1)

  • correct MCP error and capture import guidance (077d6c4)

  • correct README setup and runtime guidance (5b3715e)

  • explain CI scope and native runner reuse (#1348) (6c9161d)

  • prune repeated contributor and tool design instructions (5d79387)

  • remove retired architecture and migration artifacts (7a0c800)

Tests

  • share the client registration command to restore the jscpd gate (#1317) (5d16be2)

  • mcp: remove arbitrary schema inventory thresholds (24673aa)

  • android: allow provider readiness under load (961c3c3)

  • artifacts: verify extraction races with real filesystem changes (1ac8389)

  • browser: avoid duplicating source-map listener setup (9367dc1)

  • browser: report redirect status cases independently (5a61562)

  • cli: remove duplicate malformed JSON assertion (5d32e42)

  • exercise source test selection through Git and Vitest (25711ad)

  • filesystem: bound FIFO regressions at consumers (0bfb6e0)

  • ghidra: allow rollback tests to reach spawned process (d761d73)

  • javascript: share primitive expansion producer fixtures (c867bcd)

  • javascript: share semantic graph test facts (ac356c4)

  • javascript: verify distinct module origins through reconstruction (96b2b24)

  • json: remove assertions covered by CLI output consumers (a959a83)

  • managed: include shared dossier fixture in artifact inputs (66a20a2)

  • native: retain trace diagnostics when observed hits differ (048b798)

  • package: share validated native dossier fixtures (ca90109)

  • process: publish capture readiness atomically (74be526)

  • process: report cleanup details on cancellation failures (79d5b9a)

  • process: use owned CLI and workspace fixtures (4940a86)

  • share snapshot replay and managed graph fixtures (d83cbd2)

Continuous Integration

  • enforce architecture guards with portable checkout paths (ecc67ca)

How to Install

The recommended approach is to install REA through its guided setup utility.

First, ensure that a supported Node.js runtime and npm are installed. Then run:

npx rea-agents@latest setup

Choose the AI agents you want to configure, review the proposed changes, and approve them. Setup configures the MCP connection and installs the corresponding workflow instructions.

Restart the configured AI client after setup so it can load the new MCP server.

To use REA as a regular command-line application, install it globally:

npm install --global rea-agents

Then verify the installation:

rea doctor --json

For native binary analysis, configure Hopper or an existing Ghidra installation according to the official documentation. Static JavaScript and Electron analysis can be used without installing either tool.

To update an existing installation, follow the update instructions for the installation method you used. If you use the npx workflow, refresh the agent configuration with:

npx rea-agents@latest setup

Review the proposed changes and restart the relevant client when its MCP registration changes.

Final Verdict

REA is a compelling open-source toolkit for developers who want to combine reverse engineering with AI-assisted software development. Its biggest advantage is the way it connects analysis tools, structured evidence, and MCP-compatible agents into a single investigation workflow.

Support for native binaries, JavaScript applications, and Electron packages gives it a broad range of uses, from understanding undocumented features to investigating legacy software and building compatible implementations. The CLI and evidence-oriented results also make it useful beyond interactive AI sessions.

Its main limitation is that REA depends on external analysis engines for many native workflows, and its capabilities vary by operating system and provider. It also cannot recover original source code automatically or guarantee that an implementation recreated from analysis will behave identically to the original.

For developers working with unfamiliar applications, REA is worth exploring, particularly if they already use an MCP-compatible coding agent. It is best viewed as a bridge between reverse engineering tools and AI development workflows rather than a replacement for established disassemblers or the expertise required to interpret their results.

Comments on REA - Reverse Engineer Anything - rea-agents-6.3.0