Developer tools#MCP#Reverse engineering

REA: reverse engineer anything with your coding agent

REA connects coding agents to Hopper, Ghidra and IDA through one MCP server: reverse engineer apps without source code, evidence attached to every finding.

Project facts

GitHub Ecosystem
Repositorygithub.com/morluto/rea
License
MIT
Language
TypeScript
Stars
82,583
Data checked
2026-10-11

Snapshot figures reflect the check date and may change over time.

You spot a feature you like in an app and want to know how it actually works — and you don’t have its source. REA (by morluto, MIT-licensed, written in TypeScript, created 2026-04-14, 82,583 stars as of 2026-10-11) connects your coding agent to Hopper, Ghidra and IDA through one MCP server, so Claude Code, Codex or Cursor can investigate an app’s behavior from a web page down to native binaries. It invents no new decompilation; its two real contributions are a unified tool interface agents can actually drive, and findings that ship with their evidence and limitations instead of the model’s guess.

REA launching its analysis bridge inside Hopper to inspect a native binary

Core features

  • One setup for mainstream agents: npx rea-agents setup registers the MCP server and installs matching workflow instructions for Claude Code, Codex, Cursor, Gemini CLI and Grok Build, backing up your existing configuration first. Used from a terminal, the same engine is the rea CLI with snapshots, result import/export and --json output for scripts.
  • Findings carry their evidence: native analysis returns pseudocode, assembly, symbols and call references, and every conclusion ships with its evidence and limitations. The site’s demo pins the Windows Calculator’s % behavior to a specific build — on Calculator 11.2508.4.0 x64, % after + takes a percentage of the first number (200 + 10% = 220), while after × it acts as 0.1.
  • Analysis stays local: targets are inspected on your machine and not uploaded. Your agent receives the tool results, and your model provider has its own data policy — the README’s FAQ says this plainly.
  • A wide target list: 15 target types from native binaries to firmware, each with its own engine requirements. The common ones:
TargetWhat you getNeeds
Native binariesPseudocode, assembly, symbols, call referencesHopper / Ghidra / IDA
JavaScript and Electron appsModules, imports, source maps, routes, IPCNode.js only
WebsitesPage structure, scripts, network observations, screenshotsA Chrome-family browser
.NET assembliesMetadata, CIL instructions, native dependenciesNone (static)
Android APKsManifest, classes, decompiled methods, referencesJADX + JDK
FirmwareRegions and extraction resultsBinwalk / Unblob
Network capturesRequests, responses, exposed payloads, source locationsA HAR file
Process behaviorTerminal interaction, exit status, filesystem observationsLinux or macOS

Adapted from the project README’s target table, checked 2026-10-11.

REA's investigation flow: the agent asks, REA inspects the target and returns evidence, the agent explains, implements and tests

Typical use cases

  • Security research and CTF: Ghidra covers 16-bit DOS programs, and EVM bytecode analysis, ELF layout diagnostics and recorded crash notes round out the usual security-research lanes.
  • Borrow a feature for your own project: the site’s first lesson traces how the Notes app exports CSV, then builds one for your project; the Chrome dinosaur game’s speed rule (start at 6, add 0.001 per update, capped at 13) was recovered and verified in a controlled check.
  • Game and software preservation: the community used REA to reconstruct DX-Ball’s 1996 sound-pan calculation — the rebuilt C passes 3,205 original-x86 cases and reproduces all 63 compiled function bytes — and recovered the PC-98 game TH04’s bullet-angle math as compilable C++.
  • Find out what’s running on your machine: who an Electron app talks to, why a process exits — static ASAR analysis, HAR captures and process observation cross-check each other.

The three official showcases: DX-Ball's sound-pan math, Notion's clipboard bridge and TH04's bullet ring

Quick start

You need Node.js 22.x (≥ 22.19), 24.x (≥ 24.11) or 26+, plus npm, then:

npx rea-agents setup

Pick your agents, approve the changes, restart, and ask (the README’s own example):

Understand how search works in the Notes app, show me the evidence, and build a
similar feature for my project.

Deep native analysis needs Hopper (setup can install it with your approval), Ghidra or IDA; JavaScript, Electron and .NET analysis need no engine at all.

Summary

Made for security researchers, reverse-engineering hobbyists, and developers who want to borrow an interaction detail from another product. If the plan is to clone a commercial app and resell it, look elsewhere — that is a legal problem, not a tooling one. MIT license, written in TypeScript. Three things to know:

  • The legal line is yours to hold: the README endorses lawful reverse-engineering research only, and software whose license forbids analysis is off-limits; cloning for resale is a different matter entirely. In the 734-point Hacker News thread (opened 2026-10-10), “fully automated luxury plagiarism” critics and game preservationists went at it — the former doubt AI-produced decompilations qualify as transformative fair use, the latter count the old games that are simply no longer sold anywhere.
  • The hype has froth in it: a demo tweet on October 4 pulled 314k views, and six days later the repo sat at #1 on GitHub Trending (the author confirmed it on 2026-10-10). Some of those 82k stars are trend tourism — the author’s own post asks “is an open source project good because it has stars, or does it have stars because it is good”. The README also carries a denial: no REA token exists, and coins using the name are scams.
  • No algorithmic breakthrough — the interface is the value: REA wraps existing engines behind an agent-usable interface and forces evidence into every result. Hacker News commenters also showed the no-REA route: Claude patching two long-standing bugs in the Windows Remote Desktop binary from symptoms alone, or reverse engineering the Insta360 app to add AMD GPU acceleration. The tool amplifies; it is not the ticket.

Releases move fast — 5.0.0 landed October 7 and 6.4.0 shipped October 11, which the author calls “much, much faster” — so run rea update before you start. In the same spirit, universal-modder turns coding agents into PC-game modders, and LCU splits a closed app’s computer control into MCP tools.